FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior GRC Analyst
Shift Technology. Develop, maintain, and assess Shift’s integrated security and privacy management framework .
Posted 9/22/2026full-timeRemote • Massachusetts • United States, CanadaSenior💰 $120,000 - $150,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in developing and maintaining security and privacy management frameworks, managing compliance with industry standards, and conducting risk assessments. Proficient in overseeing audit processes and implementing security policies while ensuring alignment with regulatory requirements.
Highest-signal resume keywords
GRC ManagementISO 27001 ComplianceRisk AssessmentCISA CertificationData Protection Impact Assessment
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security FrameworksPrivacy PoliciesAudit ManagementCompliance DocumentationSecurity Control EvaluationData Handling StandardsIncident Response PlanningRegulatory AnalysisRisk MitigationThird-Party Security Assurance
Soft Skills
Exceptional CommunicationStakeholder ManagementProject ManagementAnalytical Mindset
Tools & Technologies
GRC Management ToolsDrata
Certifications & Qualifications
CIPP/ECIPP/USCIPTCISACISMCRISCCISSP
Industry Keywords
Financial ServicesHealthcareGDPRHIPAASOC 2 Type IIHITRUSTNIST CSFEU AI ActISO 42001
About the role
Key responsibilities & impact- Develop, maintain, and assess Shift’s integrated security and privacy management framework
- Manage compliance with key industry standards
- Lead risk assessments
- Oversee the third-party security assurance program
- Support TrustOps efforts for customer collateral, questions, contract reviews, and due diligence
- Translate global information security expectations into actionable policies, standards, and procedures
- Promote security and compliance across the organization and act as a subject matter expert
- Support the security awareness program
- Develop and maintain privacy policies, data handling standards, and public-facing privacy notices
- Develop and maintain the security assurance plan and evaluate security controls
- Improve third-party information security assurance and continuous assessment processes
- Identify risk areas and facilitate security control evaluations and testing
- Review architectural designs and new initiatives for security alignment and risk mitigation
- Support and facilitate Data Protection Impact Assessments
- Manage and coordinate ISO 27001 and SOC 2 Type II internal and external audits
- Analyze and compile compliance documentation and evidence
- Coordinate remediation of audit findings and track them to closure
- Support responses to Data Subject Access Requests
- Communicate with third parties and suppliers to conduct risk assessments, review security posture, and manage issue remediation
- Report to the GRC Lead within the Information Security department
Requirements
What you’ll need- 7+ years of proven experience in a GRC, IT Audit, Security Assurance, or Information Security role
- Bachelor’s Degree in a relevant field or equivalent work experience
- Professional certifications such as CIPP/E, CIPP/US, CIPT, CISA, CISM, CRISC, or CISSP are highly desirable
- Direct experience in highly regulated industries, i.e. financial services or healthcare
- Direct experience managing or supporting formal audit and certification processes from start to finish
- Deep knowledge of security and privacy frameworks, including ISO 27001, ISO 27701, SOC 2 Type II, HITRUST, and NIST CSF
- Strong knowledge of global privacy and healthcare regulations, including GDPR and HIPAA
- Working knowledge of AI regulations, frameworks, and standards, including EU AI Act and ISO 42001
- Working knowledge of business continuity, disaster recovery, and incident response planning
- Hands-on experience with modern GRC management tools, preferably Drata
- Exceptional communication and presentation skills
- Strong stakeholder management skills
- Strong project management skills and ability to manage multiple audits and assessments simultaneously
- Analytical mindset and ability to balance regulatory requirements with business objectives
Benefits
Comp & perks- Flexible remote and hybrid working options
- Competitive Salary and a variable component tied to personal and company performance
- Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
- Generous PTO and paid holidays
- Mental health benefits
- 2 MAD Days per year (Make A Difference Days for paid volunteering)
- Additional benefits may be offered by country, based on your eligibility