Suggested rewrite: Led a cross-functional initiative that improved [business outcome] by [measurable result], demonstrating experience relevant to this role...
GRC Analyst
Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.
- Remote from
- USA
- Salary
- USD 134k–202k / yr
- Department
- Legal & Compliance
- Employment
- Full Time
- Experience
- Open level
- Published
- Apply before
- 30 Oct 2026
- Listing views
- 37
- Application actions
- 2
Make your next move.
Prepare your resume, explore your fit, and draft a cover letter for this opportunity.
The role, at a glance.
Vercel is seeking a GRC Analyst to maintain and improve its security, privacy, and compliance program in a cloud-centric environment. The role manages audit readiness, controls, evidence, remediation plans, and compliance frameworks including SOC 2, ISO 27001, HIPAA, and PCI DSS. It also partners with technical and go-to-market stakeholders to integrate controls into the SDLC, respond to security questionnaires, and improve customer-facing compliance documentation. The analyst will help mature GRC operations through process automation, reporting, training, and cross-functional accountability. Candidates need at least three years of relevant audit-lifecycle experience and strong project coordination and communication skills.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Pace & Pressure
4/5Autonomy Level
4/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I start by translating the audit scope into a clear control and evidence plan, assigning accountable owners and due dates. I validate evidence quality early, track gaps and remediation in a centralized system, hold regular stakeholder check-ins, and perform a pre-audit review to ensure artifacts demonstrate consistent operation of each control.
I would document the deficiency, assess its risk and root cause, and work with the control owner to define a practical remediation plan with milestones. I would track completion, collect validation evidence, communicate status to relevant stakeholders, and identify whether related controls or processes require broader corrective action.
I focus on making requirements actionable and proportionate to risk. This includes mapping policies and control objectives to existing engineering workflows, using tooling where possible for evidence collection, agreeing on ownership, and explaining how security practices support reliable delivery and customer trust rather than treating compliance as a separate process.
I would first identify reusable, approved answers and supporting materials from the security knowledge base. For new or high-risk questions, I would route targeted requests to the appropriate security, legal, privacy, or engineering owners, maintain clear status updates for the go-to-market team, and ensure all responses accurately reflect the company's implemented controls.
I would track metrics such as control operating effectiveness, evidence collection timeliness, audit findings by severity and aging, remediation completion rates, policy-training completion, questionnaire turnaround time, and the proportion of controls with automated evidence. These measures show both compliance health and operational efficiency over time.
About this role.
About Vercel:
Vercel is the agentic infrastructure company, freeing people and agents to ship what’s next. For more than a decade we’ve helped builders move from idea to production with speed, security, and exceptional developer experience.
Now we’re scaling our products for both agents and people to ship and run software, built in the open and trusted by OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.
About the role:
We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements.
You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)).
Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and we encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.
If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.
What you will do:
- Collaborate with internal teams to maintain an effective suite of internal controls and drive remediation efforts to completion with clear documentation of progress.
- Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
- Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
- Monitor and improve controls, processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting
- Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
- Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization.
About you:
- At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
- Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
- Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.
Bonus if you have:
- Strong experience with cloud infrastructure (e.g., Azure, AWS)
- Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.)
- Experience with frontend development and open source components
- Relevant industry certifications (i.e., CISM, CISSP, CCEP) are a plus, but not required
Compensation & Benefits:
- Competitive compensation package, including equity.
- Inclusive Healthcare Package.
- Learn and Grow – we provide mentorship and send you to events that help you build your network and skills.
- Flexible Time Off.
- We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Disclosures:
- Privacy: Please review our Job Applicant Privacy Policy for more information on how we handle your data.
- Equal Opportunity: Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don’t necessarily check every box on the job description.
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.
Apply now.
Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.
Continue on the employer website
Protect your personal information and never pay to secure an interview or job offer. .
