Zip Logo

Zip

GRC Analyst

Posted 25 Days Ago
In-Office or Remote
2 Locations
95K-150K Annually
Junior
In-Office or Remote
2 Locations
95K-150K Annually
Junior
Support and drive GRC and compliance programs: perform access reviews, audits, and vendor risk assessments; manage security questionnaires; guide control owners; support SOC/ISO audits; develop and maintain security policies and standards.
The summary above was generated by AI
About Zip

Zip is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before.
The world’s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together they’ve saved over $8 billion and processed over $500 billion in spend. Zip’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA.
Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups.

Your Role

The Security & Compliance team at Zip is committed to providing a high level of security assurance to customers, aligning security goals with business objectives and customer requirements. As a GRC Analyst at Zip, you’ll be a key driver for ensuring the success of compliance programs at a fast-growing company. Your contributions will be pivotal to the overall growth and competitive edge of Zip’s GRC program. You’ll ensure we can securely and compliantly build new features, help design and scale the compliance programs that power our expansion. You’ll help maintain our existing SOC and ISO certifications while supporting new certifications, from AI products to entry into new markets like the EU and highly-regulated industries.

Responsibilities
  • Drive and perform periodic compliance-related activities, such as user access reviews, internal audits, and vendor risk assessments

  • Lead conversations and curate responses for customers’ security, compliance, and governance teams in due diligence and security questionnaires

  • Guide internal control owners and stakeholders to understand requirements, take accountability, and operationalize their controls.

  • Collaborate with internal stakeholders and external auditors to support third party audits including SOC 1, SOC 2, and ISO 27001

  • Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements

Required Qualifications
  • Bachelor’s degree in a related field

  • 2+ years of experience in GRC, information security consulting, cybersecurity risk, audits, or similar roles

  • Strong written and verbal communication skills with both technical and non-technical stakeholders

  • Familiarity with and participation in one or more of the following frameworks: SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP

  • Familiarity with information security fundamentals for cloud software systems

Preferred Qualifications
  • Professional certifications in information security are a plus but not required


The salary range for this role is $95,000 - $150,000. The salary for this position is determined based on a variety of job-related factors that may include location, relevant experience, education, or particular skills and expertise.

Perks & Benefits

At Zip, we’re committed to providing our employees with everything they need to do their best work.

  • 📈 Start-up equity

  • 🦷 100% health, vision & dental coverage options

  • 🍽️ Catered breakfast, lunch, & dinner

  • 🌴 Flexible PTO

  • 🏋️‍♀️ ClassPass membership

  • 🚍 Monthly commuter benefit

  • 🚠 Team building events & happy hours

  • 💻 Home office stipend

  • 🛜 Phone/internet reimbursement

  • 🍼 Paid parental leave

  • 🧑‍🧑‍🧒‍🧒 Fertility stipend

  • 💸 401k plan

  • 🤖 Unlimited AI token usage

We're looking to hire Zipsters and that means hiring people who take ownership, communicate openly, have an underdog mindset, and are excited to increase the pace of innovation for every business in the world. We encourage all candidates to apply even if your experience doesn't exactly match up to our job description. We are committed to building a diverse and inclusive workspace where everyone (regardless of age, religion, ethnicity, gender, sexual orientation, and more) feels like they belong. We look forward to hearing from you!


#BI-Remote
HQ

Zip San Francisco, California, USA Office

San Francisco, CA, United States, 94105

Similar Jobs

2 Days Ago
Remote
United States
110K-120K Annually
Senior level
110K-120K Annually
Senior level
Digital Media • Events • News + Entertainment
Manage third-party vendor risk, respond to security questionnaires, support SOC 1/2 audits, maintain compliance automation platforms, collect audit evidence, document policies and controls, track risk and remediation, and present risk findings to leadership.
Top Skills: AndromedaAWSAzureCaiqDrataIso/Iec 27001Nist 800-53Nist CsfSigSoc 1 Type 2Soc 2 Type 2
2 Days Ago
Remote
United States
110K-120K Annually
Senior level
110K-120K Annually
Senior level
Fintech • News + Entertainment • Software
Manage third-party vendor risk program, complete and respond to security questionnaires, support compliance automation (Drata/Andromeda), collect SOC 1/2 audit evidence, maintain security policies and controls, monitor audit readiness, advise stakeholders on remediation, and report risks to leadership.
Top Skills: AndromedaAWSAzureCaiqDrataIso/Iec 27001Nist 800-53Nist CsfSigSoc 1Soc 2
10 Days Ago
Remote
United States
Senior level
Senior level
Information Technology
Lead and manage GRC activities including internal/external audits, risk assessments, DR/BCP, third-party risk, and remediation. Develop and maintain policies, conduct BIAs, run tabletop exercises, mentor junior analysts, and collaborate with stakeholders to improve compliance posture and reporting across business and technology teams.
Top Skills: Business ContinuityCloud EnvironmentsColocationDisaster RecoveryGrc ToolsHipaaIso 27001NetworkingNist CsfPci-DssSoc1Soc2

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account