GRC Analyst
Support SOC 2 and ISO 27001 readiness programs by drafting policies, mapping controls, and managing evidence workflows for SaaS clients.
Responsibilities
- Draft and maintain security policies aligned with SOC 2 and ISO 27001 requirements
- Map client controls to framework criteria and identify gaps
- Manage evidence collection pipelines using compliance platforms (Vanta, Drata, or Sprinto)
- Prepare audit-ready documentation packages for external auditors
- Conduct periodic control reviews and track remediation items
Requirements
- 2+ years in GRC, compliance consulting, or internal audit
- Working knowledge of SOC 2 Trust Services Criteria and ISO 27001 Annex A controls
- Experience with at least one compliance automation platform
- Strong technical writing and documentation skills
- Ability to manage multiple client engagements concurrently