Talent.com
GRC Analyst

GRC Analyst

BambooHRDraper, UT, US
job_description.job_card.variable_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Job Description

Job Description

Please Note : This is a Utah-based hybrid position which will require some regular in-office days each week. Additionally, employment with BambooHR is contingent on passing both a background and credit check.

Essential Job Duties

The GRC Analyst is a key member of BambooHR's GRC team responsible for evaluating and supporting compliance initiatives covering information security, policy, risk management, data classification, vendor management, privacy, audit, and awareness. This position assists other members of the GRC team with implementing information security policies and documentation, assessing compliance with existing policies, and ensuring overall compliance with security-related requirements from customers. In addition, this position assists with performing security assessments and monitoring and tracking compliance status; developing and improving processes, procedures, standards, and guidance; providing guidance on security control implementation; and implementing process improvement and maturity initiatives. The position will also assist in evaluating risks and controls to support the company's NIST CSF, ISO 27001, ISO 27018, ISO 42001, SOC 1, SOC 2, HITRUST, FedRAMP, and other regulatory and compliance initiatives. Success in this role requires a good understanding of information security best practices, strong security knowledge, the ability to understand and communicate risk and controls, organization, planning, good communication, and writing skills.

You will :

  • Work with internal stakeholder teams to document the implementation of security compliance control implementations for technical, management, and operational requirements
  • Conduct gap analysis of current policies, procedures, and practices as they relate to established guidelines outlined by NIST, FISMA, HIPAA, and other regulatory standards
  • Conduct risk assessments of technology infrastructure and operational processes and controls for assigned areas
  • Embrace AI as an essential tool for improving GRC accuracy, efficiency, and proactive risk management
  • Use AI-powered platforms for continuous controls monitoring, predictive risk assessments, and identifying compliance gaps while incorporating responsible AI use into practices
  • Improve efficiency in evidence collection and analysis, allowing the team to begin shifting time toward higher-value GRC activities with AI support
  • Build and maintain the controls matrix, in alignment with multiple compliance frameworks, including SOC 1 & SOC 2, PCI DSS, NIST CSF, ISO 27001, ISO 27018, ISO42001, HITRUST, and HIPAA
  • Develop and maintain security documentation such as the System Security Plan, Privacy Impact Assessment, Configuration Management Plan, Contingency Plan, Contingency Plan Test Report, POA&M, annual FISMA assessment, and incident reports
  • Assist in delivering and maintaining information security training and awareness programs
  • Perform vendor management / security risk assessments and interface with vendors on occasion
  • Track efforts related to threat and vulnerability assessment processes to monitor and remediate vulnerabilities in a timely manner

What You Need to Get the Job Done

  • Bachelor's degree in Computer Science, Information Technology, or related field
  • Minimum of 1 year of experience in compliance, audit, and / or information security
  • CISSP, CISA, CCSA, or equivalent certification preferred
  • Familiarity with enterprise-level compliance tools such as Drata, Vanta, ServiceNow, Archer, IBM GRC or other industry equivalent software
  • Foundational understanding and eagerness to learn FedRAMP, NIST CSF, FISMA, NIST RMF, NIST FIPS 199, ISO 27001, ISO 27018, ISO 42001, SOC 1, SOC 2, HIPAA and HITRUST
  • Basic understanding of cloud based environments for production applications, including Amazon Web Services, Google Cloud, or other large-scale cloud deployments
  • Experience in the vulnerability assessment lifecycle from the point of identification to remediation
  • Interpersonal skills to work as a team member and as a liaison
  • Excellent verbal communication, presentation, organizational and planning skills, and great attitude and ability to learn new things quickly
  • AI at BambooHR : At BambooHR, we believe in leveraging cutting-edge technology to empower people and transform HR. We're actively integrating AI into our solutions and workflows to enhance efficiency and drive innovation. To that end, we're looking to our existing team members and future hires to share this forward-thinking mindset : individuals who are curious about AI's potential, eager to learn and adapt, and ready to explore how intelligent tools can elevate their work along with BambooHR's impact on setting people free to do great work. Join us in reimagining the future of HR!
  • What You'll Love About Us

  • A Great Company Culture that has been recognized by multiple organizations like Inc, and Salt Lake Tribune
  • Comprehensive health, life, and disability insurance
  • Generous leave policies that include 4 weeks of vacation, 12 company holidays, parental leave, and volunteer time off so you can enjoy quality of life
  • 401k plans with up to 6% company match
  • $2000 Paid-Paid Vacation bonus
  • EAP through Headspace
  • Check out all our benefits that benefit you
  • About Us

    At BambooHR, we're building something different : we're building a people intelligence platform that transforms HR and sets people free to do great work! We're a proven market leader driving innovation while building lasting success through thoughtful, sustainable growth. Here, you'll find a place that champions growth : both professional and personal, both individual and collective.

    We invest in potential, giving you the space to stretch your capabilities and turn good ideas into reality while providing the safety net of a supportive, values-driven culture. Our approach combines meaningful work with meaningful lives, offering competitive benefits, professional development, and the flexibility to thrive both in and outside the office.

    What sets us apart isn't just what we do, but how we do it : with openness, integrity, and a shared commitment to doing the right thing. Join us in creating HR software that makes work better for everyone, while we make work better for you.

    BambooHR is committed to the full inclusion of all qualified individuals and will ensure that persons with disabilities are provided reasonable accommodations throughout the hiring process. If you would like to request accommodations, please let your recruiter know.

    BambooHR is An Equal Opportunity Employer M / F / D / V

    Because our team members are trusted to handle sensitive information, we require all candidates that receive and accept employment offers to complete a background check before being hired.

    For information on California Privacy Policy, click here.

    Our process utilizes AI as an assistant to efficiently process and analyze candidate data. Recruiters and hiring managers maintain full oversight and accountability, ensuring that all final selection and rejection decisions are human-made and based solely on objective job qualifications. Please see our General Privacy Notice and California Privacy Notice for more details.

    serp_jobs.job_alerts.create_a_job

    Grc Analyst • Draper, UT, US

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    Air Systems Requirements Analyst (Senior), F-35 JPO FCAT (Future Capability) Directorate-(Hybri[...]

    Air Systems Requirements Analyst (Senior), F-35 JPO FCAT (Future Capability) Directorate-(Hybri[...]

    SercoSalt Lake City, UT, United States
    serp_jobs.job_card.full_time
    Serco is excited to continue our support to the F-35 Joint Strike Fighter (JSF) Program Office.This contract provides program management support in support of the full acquisition life-cycle of the...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Product Strategy Analyst

    Product Strategy Analyst

    CanopySouth Jordan, UT, US
    serp_jobs.job_card.full_time
    Canopy is a fast-growing SaaS company in South Jordan, Utah building simple, efficient software for accounting firms.We are looking to revolutionize the accounting space with modern, user-friendly ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Procurement Analyst

    Procurement Analyst

    Amerit ConsultingSalt Lake City, UT, United States
    serp_jobs.job_card.permanent
    Our client, US Fortune 250 company and a global medical technology corporation serving customers in Clinical Labs, Health care research & Pharmaceutical industry, seeks an accomplished.JOB TITLE : P...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Credit Analyst

    Credit Analyst

    TradeJobsWorkForce84045 Saratoga Springs, UT, US
    serp_jobs.job_card.full_time
    Conduct thorough analysis of financial statements and assessment of credit requests, including new requests, changed requests, refinancing and annual due diligence Provide recommendations tied to a...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Sr. Analytics Engineer

    Sr. Analytics Engineer

    Nature's Sunshine ProductsLehi, UT, US
    serp_jobs.job_card.full_time
    We are seeking a senior, experienced analytics engineer to join our team and take charge of designing, building, and optimizing a data warehouse as the single source of truth for all financial data...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Curb and Gutter / Site Work Superintendent

    Curb and Gutter / Site Work Superintendent

    Hughes General ContractorsNorth Salt Lake, UT, US
    serp_jobs.job_card.full_time
    Hughes General Contractors, Inc.We are known within the industry for our outstanding employee culture and a business model offering steady, year-round employment with amazing benefits and opportuni...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Regulatory Compliance Analyst - Testing

    Regulatory Compliance Analyst - Testing

    Celtic BankSalt Lake City, UT, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Celtic Bank’s Regulatory Compliance Analyst - Testing assists management in ensuring regulatory compliance at our Strategic Lending Partnerships (“SLP”) and the Bank. As a Compliance Analyst, your d...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Business Analyst

    Business Analyst

    KēSTA I.T.Midvale, UT, US
    serp_jobs.job_card.full_time +1
    Come Build, Disrupt and Thrive! .Business Analyst with UAT experience.Business Analyst, System Validation.We're looking for a highly skilled and analytical.This key role involves a n...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Financial Analyst - Year Round

    Financial Analyst - Year Round

    Deer Valley ResortCottonwood Heights, UT, United States
    serp_jobs.job_card.full_time
    Please note, this position is located at Deer Valley Resort in Park City, UT.Classic, consistent quality from a winning team!. Deer Valley Resort is nestled in the Wasatch Mountains of Utah, in the ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    Human Resources Coordinator

    Human Resources Coordinator

    Solve IT Strategies, Inc.Cottonwood Heights, UT, United States
    serp_jobs.job_card.full_time
    Work closely with Business Partners, Talent Acquisition, and Payroll to ensure a smooth and positive experience across the entire employee lifecycle — from hiring and onboarding to development and ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day
    • serp_jobs.job_card.promoted
    PayPal Fraud Analyst

    PayPal Fraud Analyst

    TradeJobsWorkforce84045 Saratoga Springs, UT, US
    serp_jobs.job_card.full_time
    Be part of our success story as a PayPal Fraud Analyst to review transactions and identify suspicious activity.Work with your team to maintain efficiency and high standards.Stay adaptable to changi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Target Digital Network Analyst (Utah)

    Target Digital Network Analyst (Utah)

    Prime Time Consulting, L.L.CBluffdale, Utah, United States, 84065
    serp_jobs.job_card.full_time
    Prime Time Consulting provides clients with expert intelligence analysis services.Our clients include defense contractors, industrial and service corporations, and departments and agencies of the U...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Workiva GRC Consulting Manager (Location flexible)

    Workiva GRC Consulting Manager (Location flexible)

    RSM US LLPSalt Lake City, UT, United States
    serp_jobs.job_card.full_time
    Workiva GRC Consulting Manager (Location flexible).Be among the first 25 applicants.Workiva GRC Consulting Manager (Location flexible). Get AI-powered advice on this job and more exclusive features....serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Senior Security GRC Analyst

    Senior Security GRC Analyst

    IBM ComputingSalt Lake City, UT, United States
    serp_jobs.job_card.full_time
    A career in IBM Software means you'll be part of a team that transforms our customers’ challenges into industry-leading solutions. We are an infinitely curious team, always seeking new possibilities...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    GRC Security compliance leader

    GRC Security compliance leader

    Avant Digital Inc.Salt Lake City, UT, United States
    serp_jobs.job_card.full_time
    GRC Security compliance leader.Job Title : GRC Security Compliance Leader.Duration : 12+ Months (Contract).Support implementing and managing Information -Security Management Systems by ISO27001 stand...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Center Clinical Director, Board Certified Behavioral Analyst (BCBA)

    Center Clinical Director, Board Certified Behavioral Analyst (BCBA)

    Fox Talent SolutionsLayton, UT, US
    serp_jobs.job_card.full_time
    Now Hiring : Center Clinical Director (BCBA) – Layton, Utah.An established and growing ABA organization is opening a brand-new therapy center in Layton, Utah and seeking a Center Clinical Director (...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Operations Analyst

    Operations Analyst

    TradeJobsWorkForce84045 Saratoga Springs, UT, US
    serp_jobs.job_card.full_time
    Operations Analyst Job Duties : Identifies project requirements by interviewing customers; analyzing ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    Sr. Analyst, 3PL Fulfillment

    Sr. Analyst, 3PL Fulfillment

    PuraPleasant Grove, UT, US
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Join Us at Pura—Reimagining Fragrance for the Future At Pura, we believe life is better when it smells good.Fragrance has the unique power to transform spaces, elevate moods, and create lasti...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Principal Consultant, GRC, Proactive Services (Unit 42) - Remote

    Principal Consultant, GRC, Proactive Services (Unit 42) - Remote

    Palo Alto NetworksSalt Lake City, UT, United States
    serp_jobs.filters.remote
    serp_jobs.job_card.full_time
    The Principal Consultant, Cyber Risk Management Advisory for Proactive Services is focused on leading our Governance, Risk, and Compliance team across a comprehensive portfolio of clients.The indiv...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    PACS Admin / Analyst

    PACS Admin / Analyst

    Kanak Elite Services IncSalt Lake City Utah, UT, United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Table" style="border : undefined"> Title : PACS Admin / Analyst ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days