Jobs and Careers
DR

Senior GRC Analyst (Remote)

Drata
United States, United StatesRemotefull_timeVerifiedPosted 30 Jun 2025
💰 $168,700/yr($109,300/yr$168,700/yr)

About the role

At Drata, members of the GRC team have a rare opportunity to be Customer Zero—we actively use the same GRC platform that our customers rely on. This means your work as a Senior GRC Analyst will contribute directly to both the strength of Drata’s internal GRC program and the continuous evolution of our product. You'll provide hands-on feedback to our product and engineering teams based on real-world use, helping to refine user experience and functionality for thousands of customers. This isn’t just a GRC role – it’s a chance to help shape a category-defining solution while strengthening trust and security from the inside out.

Drata’s Senior GRC Analyst will support the execution of governance, risk, compliance, and trust-related initiatives to help ensure Drata remains aligned with key security frameworks, laws, and industry best practices. In this role, you’ll assist with internal control testing, evidence collection, audit readiness, and documentation across compliance programs such as SOC 1/2/3, ISO 27001/17/18, ISO 42001, HIPAA, and FedRAMP, among others. You’ll work closely with internal stakeholders and external assessors to support continuous improvement of controls and risk mitigation efforts. A strong understanding of security compliance programs and familiarity with frameworks such as GDPR, data privacy laws, and data security regulations is essential.

What you'll do:

  • Respond to customer due diligence requests (e.g., Trust Center inquiries, questionnaires, assessments, contract and addendum reviews) within defined SLAs.
  • Manage and respond to customer privacy-related inquiries, including Data Subject Access Requests (DSARs), ensuring timely resolution in line with regulatory timelines .
  • Conduct enterprise risk assessments, identify and track risks in Drata’s Risk Register, and ensure mitigation plans are developed, assigned, and progressed.
  • Review and assess new vendors for risk and compliance alignment; conduct periodic reviews of critical and high-impact vendors.
  • Act as an internal “Customer Zero” of the Drata and SafeBase platforms—testing, evaluating, and providing structured feedback to product and engineering teams.
  • Maintain ongoing compliance with Drata’s attestations and certifications, including SOC 1/2/3, HIPAA, ISO 27001/27017/27018, and applicable privacy laws such as GDPR and CCPA.
  • Support readiness and adoption of new or evolving frameworks, including FedRAMP, and ensure timely compliance with contractual and regulatory requirements.
  • Draft, maintain, and disseminate security and compliance policies, standards, and procedures aligned with frameworks, regulations, and business needs.
  • Provide training and awareness to staff on compliance responsibilities and enforce adherence through assessments and periodic reviews.
  • Monitor and resolve control testing alerts and findings from internal and external assessors in a timely manner.
  • Participate in roadmap planning and strategic product discussions to help shape compliance automation capabilities.
  • Collaborate with security and engineering teams to validate ongoing adherence to internal controls and external standards.
  • Assist with audit preparation and coordination, including evidence gathering and auditor communication.
  • Communicate the “why” behind compliance and security processes to cross-functional teams to drive shared understanding and alignment.
  • Develop clear, accessible documentation for configurations, policies, controls, and compliance processes to support both internal operations and external audits.
  • Stay current on security, compliance, and privacy trends; explore new tools and techniques to improve program effectiveness and automation.

By weaving together automation, innovation, and clear communication, you’ll play a pivotal role in shaping Drata’s future and redefining what it means to be secure and compliant in a modern, fast-paced world. Let’s revolutionize the industry—together!

What you’ll you bring:

  • You have 5-7 years of experience
  • You have a passion for developing solutions at the intersection of Compliance, Privacy and Security
  • You have a solid understanding of how things operate in a SaaS environment
  • You have a solid understanding of Risk Management and Vendor Management to lead discussions and manage risks and vendors.
  • You are knowledgeable in SOC 2 , ISO 27001, HIPAA, and an awareness of FedRAMP, NIST CSF, and others, and know how to audit internally, and facilitate external auditor assessments against these.
  • You like taking the road less traveled when it makes sense, you analyze problems and find better ways to meet the business need.
  • Black Hat, White Hat or Wizard Hat, we don’t care, we just want you to b

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Drata

View company profile →