Search jobs > Seattle, WA > Temporary > Governance risk and

Security Governance Risk and Compliance (GRC) Lead

Gusto
Seattle, WA
$144K a year
Full-time

About Gusto

Gusto is a modern, online people platform that helps small businesses take care of their teams. On top of full-service payroll, Gusto offers health insurance, 401(k)s, expert HR, and team management tools.

Today, Gusto offices in Denver, San Francisco, and New York serve more than 300,000 businesses nationwide.

Our mission is to create a world where work empowers a better life, and it starts right here at Gusto. That’s why we’re committed to building a collaborative and inclusive workplace, both physically and virtually.

Learn more about our .

Security Governance Risk and Compliance (GRC) Lead

San Francisco, Denver, NYC or Remote)

Gusto processes billions of dollars in payroll every month for small businesses and their employees. Our clients trust us with a huge amount of personally identifiable information (PII) and protected health information (PHI), including SSNs, EINs, salaries, home addresses, and more.

Our business is largely built on trust, as a result protecting our clients’ information is our top priority.

The Governance Risk and Compliance (GRC) team is responsible for ensuring that Gusto complies with all applicable laws, regulations and its own internal controls, manages its risks effectively, and maintains a high level of information security.

As a Lead GRC Analyst at Gusto, you will play a critical role in ensuring that our organization adheres to the highest standards of governance, risk management, and compliance, including managing of all the pre and post sales IT & Security support for Gusto Embedded.

Here’s what you’ll do day-to-day :

  • Develop, implement, and maintain a comprehensive strategy and supporting documentation that aligns with the business goals and objectives to help support all pre and post sales IT & Security support for Gusto embedded payroll.
  • Support pre-sales initiatives with large potential customers by aligning with the internal Sales team on who Gusto is targeting in order to perform initial compatibility due diligence, including reputational checks, public breach history, etc.
  • Support the continued refinement of tier-based security requirements, inclusive of internal service level objectives (SLOs).
  • Aligning to a chosen security framework with explicit guidelines for each type of partner Gusto would work with.
  • Creation of playbooks, driving agility and efficiency, improving Gusto’s embedded payroll service, including current controls and positioning IT & Security as a competitive advantage in our go-to-market strategy.
  • Develop project plans to capture key milestones, sign off and support throughout the pre (and post) sales process.
  • Understand, triage and respond to all partner due diligence requirements in a centralized, organized, and timely manner.

For areas with identified gaps, coordinate internal discussions for a path to remediation.

  • Facilitate negotiations with partners to ensure there is risk reduction for both parties, including ensuring any commitments from Gusto are specific, time-bound and achievable prior to insertion in a contract.
  • Ensure there is continued trust with our Embedded Partners by ensuring proactive communication of external security and IT exam or scan results and management of on-going Security or IT requirements inclusive of annual audits, attestations and other due diligence exercises.
  • Continuously monitor changes in compliance regulations, standards, and best practices, and adapt the company's GRC program accordingly.
  • Lead efforts to drive process improvement and enhance the effectiveness of the GRC function.

Here’s what we're looking for :

  • 8+ years of experience in the GRC, audit, compliance space assisting an organization in working towards SOX, SOC 1, SOC 2, ISO 27001, PCI and HIPAA.
  • Experience with ISO 27001, ISO 27002, NIST CSF and working knowledge of ISO 27005 and ISO 27018
  • Client-facing experience managing pre and post sales for IT & Security support
  • Relevant certifications (, CISA, CISSP, CRISC, CISM) preferred.
  • Excellent analytical, problem-solving, and project management skills.
  • Ability to work collaboratively with cross-functional teams and stakeholders, from control owners up to the executive level.
  • High attention to detail and a commitment to upholding the highest standards of data security and compliance.
  • Experience with response coordination tools like Loopio, RFPio, etc.

Our cash compensation amount for this role is targeted at $144,000 / yr to $180,000 / yr in Denver & most remote locations, and $174,000 / yr to $210,000 / yr for San Francisco & New York.

Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role).

The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale.

Note : The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.

When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required.

Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger.

If you share our values and our enthusiasm for small businesses, you will find a home at Gusto.

Gusto is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic.

Gusto considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gusto is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures.

If you require assistance in filling out a Gusto job application, please reach out to .

5 days ago
Related jobs
Promoted
Equiniti
Seattle, Washington

Working in close collaboration with the products/business line along with other complimenting Business Risk & Control teams, this group is responsible for governance and overall oversight of the control landscape and strategy for the Division (risk identification, risk assessment, risk measurement, ...

Promoted
Federal Reserve Bank of Cleveland
Seattle, Washington

Some preferred areas include vendor risk management, cybersecurity response and resilience, cloud security, data governance and security, endpoint and server technologies, intrusion detection and prevention systems, identify access management and access control, and threat vulnerability management. ...

Promoted
TikTok
Seattle, Washington

As the Category Lead in Governance & Experience team, you will be part of a team consisting of policy managers, investigation ops, and program managers to drive cross-functional collaboration in the design and management of projects to ensure balance between growth and sustainability of the plat...

Princess Cruises
Seattle, Washington

You’ll communicate governance-related technical information to team members and coordinate regular status reports to leadership on status and milestones, including, elevating risks in a timely and appropriate manner and facilitation of regular risk reviews and mitigation steps. You’ll act as an advo...

TikTok
Seattle, Washington

Having an in-depth knowledge of vertical / category products and mapping business strengths and customer needs to justify compliance, regulatory and operation investment to allow the selection to be sold and under what conditions/criteria- Monitor, analyze and own key performance indicators such as ...

Amazon.com Services LLC
Bellevue, Washington

The role involves self-driven, independent, and hands-on work in the areas of understanding stakeholder needs and expectations, legal research, stakeholder engagement, data analysis, investigation and root cause analysis, and risk management. Key responsibilities include defining, applying, and defe...

TikTok
Seattle, Washington

Having an in-depth knowledge of vertical / category products and mapping business strengths and customer needs to justify compliance, regulatory and operation investment to allow the selection to be sold and under what conditions/criteria- Monitor, analyze and own key performance indicators such as ...

Forrester Research, Inc.
Washington
Remote

The Security and Risk Analyst will deliver these insights and recommendations in written reports, presentations, tools and templates, video, inquiries, guidance sessions, and custom advisory for security and risk leaders across industries and geographies. Candidates for this role must understand how...

Mediabistro
Seattle, Washington

Establish a risk posture and mechanisms to rate risks within the consumer organization- Partner with related finance and business and technology teams to mitigate identified controls risks- Track control defects, partner with business teams to conduct deep dives on defects and offer near-term and lo...

Amazon.com Services LLC
Seattle, Washington

Our team offers the unique opportunity to work with leading industry security experts and engage across Amazon teams and leadership. As a Security Engineer in VMR Response, you will play a hands-on role in the proactive identification and remediation of security issues at Amazon. We are data-driven,...