×
Register Here to Apply for Jobs or Post Jobs. X

Senior GRC Analyst

Job in San Francisco, San Francisco County, California, 94199, USA
Listing for: Triwill Group
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 183000 - 205000 USD Yearly USD 183000.00 205000.00 YEAR
Job Description & How to Apply Below

About Gusto

At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k) s, and HR — so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.

All full-time employees receive competitive base pay, benefits, and equity (RSUs) — because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about our Total Rewards philosophy.

AI is a fundamental part of how work gets done  expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process.

About the Role

Gusto is seeking a Security, Governance, Risk & Compliance professional to join our team managing our security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC and related frameworks, while embedding security-minded practices throughout Gusto.

This is a cross-functional role with key touchpoints in every department.

Here’s what you’ll do day-to-day
  • Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies—particularly supporting SOC 2 and future framework adoption.
  • Own and manage trust management platforms including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it
  • Collaborate with Legal, Enterprise Applications, and Gusto counterparts to establish and maintain data governance policies (e.g., classification, retention, handling).
  • Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams.
  • Manage the third‑party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
  • Lead interactions with external auditors and regulatory bodies during compliance assessments (e.g., SOC 2 Type
    2) and oversee responses to client security assessments and due diligence requests.
  • Stay current on relevant compliance frameworks, laws, and regulations to ensure appropriate coverage and adaptability.
  • Partner cross‑functionally (e.g., Security, Legal, Engineering, Sales, IT) to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights.
Here’s what we’re looking for
  • 8+ years of experience in governance, risk, and compliance within SaaS, ideally in the HCM, payroll, or fintech sectors.
  • Bachelor’s degree in Business, Information Systems, or a related field.
  • Strong understanding of SaaS business models, with experience implementing controls and policies in fast-paced, product-driven environments.
  • Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams.
  • Familiarity with compliance tools and platforms such as Optro, Vanta, Drata, Viso Trust, or similar.
  • Demonstrated ability to translate complex GRC requirements into actionable, scalable processes.
  • Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders.
  • A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.
  • One or more relevant professional certifications:
    • CISA, CRISC, or GRCP preferred
    • CGEIT, CRMA, or PMI-RMP are a bonus

Our cash compensation amount for this role is targeted at $,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and…

Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary