FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior GRC Analyst – Enterprise Cybersecurity
Rivian and Volkswagen Group Technologies. Own TISAX follow-on certifications, including subsequent waves and sites after initial TISAX AL3 assessments .
Posted 9/21/2026full-timePalo Alto • California • United StatesSenior💰 $117,200 - $161,150 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in governance, risk, and compliance (GRC) with a strong focus on ISO/IEC 27001, TISAX, and risk management processes. Proven ability to manage audits, maintain compliance documentation, and coordinate with diverse stakeholders across multiple entities.
Highest-signal resume keywords
ISO/IEC 27001 Certification ManagementTISAX Compliance ManagementGovernance, Risk, And Compliance (GRC)Risk Register ManagementAudit Coordination And Evidence Collection
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Governance, Risk, And Compliance (GRC)ISO/IEC 27001/27002TISAXNIST Cybersecurity FrameworkRisk Assessment And TreatmentCorrective-Action TrackingAudit CoordinationDocumentation ManagementProject TrackingEvidence Collection
Soft Skills
Excellent Written And Verbal CommunicationStrong Documentation SkillsOrganizational SkillsAbility To Manage Multiple Deadlines
Tools & Technologies
ServiceNow GRCOneTrustVantaDrataArcherAuditBoardZenGRCJiraConfluenceGoogle Workspace
Certifications & Qualifications
CISACRISCISO 27001 Lead ImplementerISO 27001 Lead AuditorCompTIA Security+
Industry Keywords
Automotive IndustryTISAX/VDA ISA AssessmentsUNECE R155/R156ISO/SAE 21434IATF 16949
Tech Stack
Tools & technologiesCyber SecurityServiceNow
About the role
Key responsibilities & impact- Own TISAX follow-on certifications, including subsequent waves and sites after initial TISAX AL3 assessments
- Manage evidence maintenance, internal self-assessments, corrective-action tracking, re-assessment readiness, and ongoing ISMS evidence infrastructure
- Drive achievement and ongoing maintenance of ISO/IEC 27001 certification
- Coordinate internal audits and maintain the Statement of Applicability and control evidence
- Manage annual surveillance and recertification activities
- Support ISO 9001 efforts related to infrastructure and IT
- Support CSMS compliance under UNECE R155 and software update management under UNECE R156 for enterprise/IT infrastructure
- Track and drive corrective and preventive actions (CAPA) to closure across all frameworks
- Operate the enterprise cybersecurity risk register from intake through assessment, treatment tracking, and reporting
- Execute risk management processes with Legal and follow documented standard operating procedures, including confidentiality classification steps
- Produce prioritized risk reporting for the Sr. Manager, Enterprise Cybersecurity and other stakeholders
- Coordinate internal control owners across IT, Legal, Facilities, Internal Audit, HR, and engineering teams
- Coordinate evidence collection with 15–30+ named control owners
- Manage certification bodies, external consultants, and vendors, tracking deliverables, due dates, and response SLAs
- Maintain audit-ready documentation and program tracking in Jira, Confluence, and Google Workspace
- Travel to company sites in Southern California, Northern California, Vancouver (BC), and Belgrade (Serbia) for on-site audits, physical security walkthroughs, evidence collection, and stakeholder coordination
Requirements
What you’ll need- 5 years of experience in governance, risk, and compliance (GRC), IT/information security compliance, IT audit, or a closely related function
- Bachelor's degree or equivalent practical experience
- Working knowledge of ISO/IEC 27001/27002, TISAX and the NIST Cybersecurity Framework, including risk assessment and treatment concepts and control mapping
- Hands-on experience supporting or coordinating audits and certifications: evidence collection, control validation, and corrective-action tracking
- Experience operating or maintaining a risk register and driving remediation items to closure with accountable owners
- Strong documentation, organization, and project-tracking skills
- Ability to manage multiple concurrent deadlines
- Excellent written and verbal communication; able to work with technical and non-technical stakeholders across a complex, multi-entity organization
- Ability and willingness to travel domestically and internationally up to a few weeks per quarter
- Professional certification such as CISA, CRISC, ISO 27001 Lead Implementer or Lead Auditor, or CompTIA Security+ (preferred)
- Hands-on experience with GRC/compliance tooling such as ServiceNow GRC, OneTrust, Vanta, Drata, Archer, AuditBoard, or ZenGRC (preferred)
- Automotive industry experience, especially TISAX/VDA ISA assessments, UNECE R155/R156, ISO/SAE 21434, or IATF 16949 (preferred)
- Experience coordinating external auditors, certification bodies, or consultancies and managing deliverables to SLAs (preferred)
- Proficiency with Jira, Confluence, and Google Workspace (preferred)
- Experience in a fast-paced, high-growth, or joint-venture/multi-entity environment (preferred)
- Valid passport and ability to travel internationally
Benefits
Comp & perks- Annual company performance bonus program; annual bonus target of 10%
- Equity in the form of Restricted Stock Units (RSUs)
- Health coverage
- Retirement savings
- Time off
- Family planning programs
- Travel support for company-site audits and stakeholder coordination