Governance, Risk & Compliance; GRC) Analyst
Listed on 2026-09-04
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Why Join Ivo?
Every civilization runs on the same infrastructure: agreements between people who don't fully trust each other. Sumerians pressed them into clay. Romans carved them into stone. We bury them in 80-page PDFs.
The way those agreements are reviewed hasn't changed in four thousand years — a human reads the whole thing and tries not to miss anything. We're building the AI that finally changes that. Ivo is the contract intelligence platform of choice for companies like Uber, Meta, Canva, and IBM, and Intel. We recently raised our Series B and have grown 800% over the last 12 months.
TheOpportunity
Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in maintaining and enhancing Ivo's compliance programs, including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001.
The ideal candidate has experience supporting security audits, managing evidence collection, conducting risk assessments, maintaining policies and procedures, and partnering cross-functionally with engineering, IT, legal, HR, and business stakeholders.
This is a fully onsite role based out of Ivo's San Francisco headquarters to support close cross-functional collaboration with Security, Engineering, IT, and Operations teams.
What You'll DoSupport and coordinate Ivo's compliance programs including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001.
Assist with annual audits, surveillance audits, and customer security assessments.
Coordinate evidence collection and maintain audit readiness across teams.
Support and maintain Ivo's Vanta GRC platform and associated compliance workflows.
Monitor automated compliance evidence collection and control monitoring within Vanta.
Perform vendor and third-party risk assessments.
Support enterprise risk management and risk register maintenance.
Maintain and update security policies, standards, and procedures.
Support AI governance and responsible AI compliance initiatives.
3–5 years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Audit, or related field.
Hands-on experience supporting SOC 2 Type II, ISO 27001, CSA STAR, and in-depth knowledge of ISO/IEC 42001.
Experience administering or working extensively with Vanta or similar GRC/compliance automation platforms.
Experience managing and maintaining a customer-facing Trust Center, including security documentation, compliance artifacts, sub-processor disclosures, and customer assurance materials.
Strong understanding of information security principles and common security controls.
Experience with audits, evidence management, and customer security reviews.
Excellent written and verbal communication skills.
Experience working at a SaaS or AI company.
Familiarity with GDPR, CCPA, privacy regulations, and third-party risk management.
Knowledge of cloud environments such as GCP, AWS, or Azure.
Relevant certifications such as Security+, CISA, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor.
Would describe yourself as being relentlessly resourceful.
You have a strong internal sense of urgency. You have a bias towards doing things today, rather than tomorrow.
Experience working in a startup environment is preferred but not required.
Are excited about the adventure of building a company!
Competitive Compensation: Final offer details are determined based on experience, expertise, and overall fit.
Equity: Meaningful ownership in a company that's scaling fast
Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.
Health & Wellness: Comprehensive medical, dental, and vision plans to suit the needs of you and your family.
Flexible Spending & Insurance: Access to HSA and FSA accounts, plus life insurance coverage.
401(k) Program: Save for the future with our 401(k) program.
Commuter Benefits: We help make getting to and from the office easier and more convenient.
Unlimited PTO: So you can take the time you need to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).