Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Commerce

Security Governance Risk & Compliance Analyst I

Commerce

GRC Analyst supporting vendor risk assessments, controls, audits, and compliance reporting. Commerce empowers businesses through an open, AI-driven ecommerce ecosystem.

Posted 8/17/2026full-timeRemote • 🇺🇸 United StatesJuniorMid-Level💰 $49,729 - $73,130 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates a foundational understanding of GRC engineering, risk operations, and compliance frameworks, with hands-on familiarity in utilizing AI coding tools for cybersecurity applications. Proficient in documentation management, communication, and process improvement initiatives.

Highest-signal resume keywords
GRC EngineeringVendor Risk AssessmentSOC 2 ComplianceMicrosoft OfficeCybersecurity Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk OperationsCompliance FrameworksDocumentation ManagementInternal Control TestingEvidence CollectionProcess ImprovementMetrics PreparationTracking ToolsVendor Security QuestionnairesAudit Coordination
Soft Skills
Strong Communication SkillsAttention to DetailCross-Functional CollaborationWillingness to Learn
Tools & Technologies
Claude CodeGoogle WorkspaceSpreadsheets
Certifications & Qualifications
Security+CISA
Industry Keywords
ISO 27001PCI-DSSNISTRisk ManagementGRC

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Support third-party risk assessments by reviewing vendor security questionnaires, documentation, and due diligence materials
  • Maintain and update the vendor risk register and track remediation activities to closure
  • Assist with internal control testing and evidence collection for SOC 2, ISO 27001, PCI-DSS, and other compliance frameworks
  • Help coordinate audit requests and liaise with internal stakeholders to gather required documentation
  • Monitor policy and procedure documentation and flag items due for review or update
  • Assist in tracking risk exceptions and escalate items requiring senior review
  • Support reporting and metrics preparation for leadership and committee-level reviews
  • Contribute to process improvement initiatives as the program scales

Requirements

What you’ll need
  • 0–2 years of experience in GRC, risk operations, compliance, or a related function; internships count
  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Business, or a related field; equivalent work experience also considered
  • Genuine interest in GRC engineering and willingness to learn quickly in a fast-paced environment
  • Hands-on familiarity with Claude Code or similar AI coding tools, with ability to consider cybersecurity or GRC applications
  • Strong written and verbal communication skills for cross-functional and external vendor work
  • High attention to detail and comfort working with documentation, spreadsheets, and tracking tools
  • Proficiency in Microsoft Office or Google Workspace
  • Coursework or certification in cybersecurity or risk management is nice to have, including Security+ or CISA
  • Exposure to SOC 2, ISO 27001, NIST, or PCI-DSS is nice to have
  • Experience in an operations or process-driven role is nice to have

Benefits

Comp & perks
  • Variable compensation such as bonus or commission may be available where applicable
  • Equity may be available where applicable
  • Benefits in accordance with local policies
  • Inclusive and accessible hiring experience
  • Accommodation or adjustments during recruitment if needed