All remote jobs

GRC Analyst

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Remote from
USA
Salary
USD 134k–202k / yr
Employment
Full Time
Experience
Open level
Published
Apply before
30 Oct 2026
Listing views
87
Application actions
6
Application toolkit

Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

The role, at a glance.

Vercel is seeking a GRC Analyst to maintain and improve its security, privacy, and compliance program in a cloud-centric environment. The role manages audit readiness, controls, evidence, remediation plans, and compliance frameworks including SOC 2, ISO 27001, HIPAA, and PCI DSS. It also partners with technical and go-to-market stakeholders to integrate controls into the SDLC, respond to security questionnaires, and improve customer-facing compliance documentation. The analyst will help mature GRC operations through process automation, reporting, training, and cross-functional accountability. Candidates need at least three years of relevant audit-lifecycle experience and strong project coordination and communication skills.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

4/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

4/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a mid-level GRC role requiring practical ownership of multi-framework compliance, audit deliverables, internal controls, and remediation in a fast-growing cloud software company. The work demands sound judgment across technical, regulatory, operational, and customer-facing requirements.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive
$168,000
US market range$120k–$185k
AI insightThe disclosed San Francisco base-pay range is $134,000 to $202,000 USD yearly, with a midpoint of $168,000. This is a competitive range for a GRC Analyst with 3+ years of cloud-compliance and audit-lifecycle experience; the estimated broader US base-salary market range is approximately $120,000 to $185,000 yearly, varying by location, framework expertise, and technical depth.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
Describe your approach to preparing for a SOC 2 or ISO 27001 audit.

I start by translating the audit scope into a clear control and evidence plan, assigning accountable owners and due dates. I validate evidence quality early, track gaps and remediation in a centralized system, hold regular stakeholder check-ins, and perform a pre-audit review to ensure artifacts demonstrate consistent operation of each control.

How would you handle a control deficiency discovered during an audit-readiness review?

I would document the deficiency, assess its risk and root cause, and work with the control owner to define a practical remediation plan with milestones. I would track completion, collect validation evidence, communicate status to relevant stakeholders, and identify whether related controls or processes require broader corrective action.

How do you partner with engineering teams to embed compliance into the SDLC?

I focus on making requirements actionable and proportionate to risk. This includes mapping policies and control objectives to existing engineering workflows, using tooling where possible for evidence collection, agreeing on ownership, and explaining how security practices support reliable delivery and customer trust rather than treating compliance as a separate process.

How would you respond to a complex customer security questionnaire under a tight sales deadline?

I would first identify reusable, approved answers and supporting materials from the security knowledge base. For new or high-risk questions, I would route targeted requests to the appropriate security, legal, privacy, or engineering owners, maintain clear status updates for the go-to-market team, and ensure all responses accurately reflect the company's implemented controls.

What metrics would you use to measure GRC program maturity?

I would track metrics such as control operating effectiveness, evidence collection timeliness, audit findings by severity and aging, remediation completion rates, policy-training completion, questionnaire turnaround time, and the proportion of controls with automated evidence. These measures show both compliance health and operational efficiency over time.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.
Opportunity details

About this role.

About Vercel:

Vercel is the agentic infrastructure company, freeing people and agents to ship what’s next. For more than a decade we’ve helped builders move from idea to production with speed, security, and exceptional developer experience.

Now we’re scaling our products for both agents and people to ship and run software, built in the open and trusted by OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide.

About the role:

We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements.

You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)).

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and we encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

What you will do:

  • Collaborate with internal teams to maintain an effective suite of internal controls and drive remediation efforts to completion with clear documentation of progress.
  • Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
  • Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
  • Monitor and improve controls, processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting
  • Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
  • Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization.

About you:

  • At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
  • Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
  • Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.

Bonus if you have:

  • Strong experience with cloud infrastructure (e.g., Azure, AWS)
  • Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.)
  • Experience with frontend development and open source components
  • Relevant industry certifications (i.e., CISM, CISSP, CCEP) are a plus, but not required

Compensation & Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow – we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

Disclosures:

  • Privacy: Please review our Job Applicant Privacy Policy for more information on how we handle your data.
  • Equal Opportunity: Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don’t necessarily check every box on the job description.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. .

Log in to save
One quick step before you apply

Sign in to continue.

Sign in or create a free account to continue to the employer's application.

Applying is free. After signing in, return to this job and select Apply Now.
Add alert
Jobs Talent AI Tools Salaries
Menu