What are the responsibilities and job description for the GRC Analyst position at Jobs via Dice?
Dice is the leading career destination for tech experts at every stage of their careers. Our client, WinMax Systems Corporation, is seeking the following. Apply via Dice today!
Title: GRC Analyst
Location: San Francisco, CA (4 days onsite)
Duration: 6 months
Key Responsibilities:
Title: GRC Analyst
Location: San Francisco, CA (4 days onsite)
Duration: 6 months
Key Responsibilities:
- Conduct technical vendor risk assessments (security, privacy, architecture, data handling) for new and existing third parties
- Review security documentation (SOC 2, ISO 27001, pentest reports, architecture diagrams, data flows) and identify risks
- Drive risk-based decisions — recommend approve / conditional approve / reject with clear rationale
- Track and manage vendor risk findings, remediation plans, and exceptions
- Partner with Legal/Procurement on security terms, DPAs, and contractual requirements
- Respond to internal GRC queries (security questionnaires, audits, customer due diligence)
- Experience in GRC / Vendor Risk / Security Risk roles
- Strong understanding of cloud/SaaS architectures and common security controls
- Familiarity with frameworks like SOC 2, ISO 27001, NIST, HIPAA, PCI
- Ability to balance risk vs. business enablement in a fast-paced environment
- Strong communication skills with both technical and non-technical stakeholders