FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in GRC and security compliance programs, with a strong focus on SOC 2, ISO 27001, NIST, and FedRAMP frameworks. Proficient in risk management, audit readiness, and leveraging technology for compliance automation and evidence collection.
Highest-signal resume keywords
GRC Program ManagementSOC 2 ComplianceISO 27001 FamiliarityRisk AssessmentTechnical Fluency
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
GRC Program ManagementRisk AssessmentControl ImplementationEvidence CollectionAudit ReadinessRemediation TrackingContinuous MonitoringControl MonitoringCompliance DocumentationVulnerability Tracking
Soft Skills
Strong Written CommunicationDetail-OrientedOrganizedAdaptability
Tools & Technologies
GRC SystemsAI AutomationCloud SecurityJiraGitHub
Certifications & Qualifications
Security+CISACRISCCISMCGRCISO 27001
Industry Keywords
NIST 800-53FedRAMPThird-Party Risk ManagementVendor Security AssessmentsSaaSCloud Security
Tech Stack
Tools & technologiesAWSCloudCyber Security
About the role
Key responsibilities & impact- Operate and improve Upwind's GRC and security compliance programs
- Support compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, documentation, remediation tracking, continuous monitoring, and audit readiness
- Coordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HR
- Translate compliance requirements into clear actions for technical and business teams
- Perform control assessments, gap analyses, and risk assessments, and recommend remediation
- Work with process owners to build sustainable, evidence-based remediation
- Track vulnerabilities, risks, audit findings, and POA&Ms through completion
- Handle customer security questionnaires, due diligence requests, and security documentation
- Support third-party risk management and vendor security assessments
- Write and maintain policies, standards, procedures, and control documentation
- Maintain GRC systems, evidence repositories, and risk registers
- Research new regulatory and customer requirements and determine their applicability
- Use AI and automation to accelerate research, documentation, evidence organization, and workflow with appropriate validation and data handling
- Raise gaps and issues early with proposed fixes
Requirements
What you’ll need- 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit
- Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks
- Experience supporting audits, assessments, security questionnaires, or evidence collection
- Strong written communication and documentation skills
- Technical fluency to work effectively with Engineering, IT, and Security
- Ability to turn audit findings into adoptable remediation plans
- Comfort working in a fast-moving environment where priorities shift
- Demonstrated use of technology to improve GRC work, including risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation
- Organized and detail-oriented
- Nice-to-have: FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities
- Nice-to-have: Experience working with external assessors on formal readiness or assessment activities
- Nice-to-have: Cloud security experience, particularly AWS or AWS GovCloud
- Nice-to-have: Background in SaaS, cloud security, or a high-growth technology company
- Nice-to-have: Experience with a global, distributed workforce across time zones
- Nice-to-have: Hands-on experience with cloud-based GRC, compliance automation, or AI-enabled workflow platforms
- Nice-to-have: Experience building GRC automations, integrations, or dashboards
- Nice-to-have: Familiarity with Jira, GitHub, or similar tools
- Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001 are nice to have
Benefits
Comp & perks- Full-time employment
- Remote work in the United States