Senior GRC Analyst - Central or Eastern time, US or Canada
Shift Technology · Boston, MA, US
16 hours agoImpress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Senior GRC Analyst - Central or Eastern time, US or Canada role.
Rezi rewrites your resume against Shift Technology's job description. Free.

Tailor your resume to this Senior GRC Analyst - Central or Eastern time, US or Canada role.
Rezi rewrites your resume against Shift Technology's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Senior GRC Analyst - Central or Eastern time, US or Canada posting at Shift Technology — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Senior GRC Analyst - Central or Eastern time, US or Canada posting at Shift Technology — free, in seconds.
About the Role
As a Senior GRC Analyst, you will be a cornerstone of Shift’s security program, responsible for developing, maintaining, and assessing our integrated security and privacy management framework. This role is critical for ensuring that Shift meets its regulatory obligations and maintains the trust of our customers. As part of the Information Security department, this role reports to the GRC Lead.
Responsibilities
- Translate Shift’s global information security expectations into actionable policies, standards, and procedures.
- Promote a mind-set of security and compliance across the organization, transferring knowledge of standards and acting as a subject matter expert (SME).
- Contribute to the development and support of the security awareness program.
- Partner with the Data Protection Officer to develop and maintain privacy policies, data handling standards, and public-facing privacy notices in line with privacy laws and global regulations such as GDPR.
- Develop and maintain the security assurance plan, ensuring key controls are effectively designed and implemented.
- Improve the third-party information security assurance and continuous assessment process.
- Identify key risk areas in collaboration with engineering and business teams and facilitate security control evaluations and testing.
- Review architectural designs and new initiatives to ensure they align with security policies and effectively mitigate risk.
- Proactively identify potential information security GRC problem areas and execute plans to improve the overall assurance workflow.
- Support and facilitate Data Protection Impact Assessments (DPIAs) for new products and initiatives.
- Manage and coordinate internal and external audits for certifications such as ISO 27001 and SOC 2 Type II.
- Perform analysis and compile documentation and evidence to demonstrate the compliance level of systems, services, and controls.
- Work with internal teams to manage the remediation of audit findings and track them to closure.
- Support legal and stakeholder teams in responding to Data Subject Access Requests (DSARs).
- Develop, execute, and improve the third-party information security assurance and continuous assessment process.
- Communicate with third parties and suppliers to conduct risk assessments, review their security posture, and manage the remediation of identified issues.
Requirements
- 7+ years of proven experience in a GRC, IT Audit, Security Assurance, or Information Security role.
- Direct experience of delivery in highly regulated industries, i.e financial services, healthcare.
- Direct experience managing or supporting formal audit and certification processes from start to finish.
- Hands-on experience with modern GRC management tools, preferably Drata - connecting integrations, tuning automated evidence collection and monitoring tests, and building custom controls and frameworks.
- Exceptional communication and presentation skills, with the ability to translate complex compliance requirements into clear business guidance.
- Strong stakeholder management skills with the ability to influence and align teams without direct authority.
- Highly organized with strong project management skills, capable of managing multiple audits and assessments simultaneously.
- An analytical mindset with the ability to balance regulatory requirements with business objectives and priorities.
Skills
- ISO 27001
- ISO27701
- SOC 2 Type II
- HITRUST
- NIST CSF
- GDPR
- HIPAA
- EU AI Act
- ISO 42001
- Drata
Location
- Remote
- Hybrid
Work Type
- Full-time
- Remote
- Hybrid
Experience Level
- Senior
Education Level
- Bachelor’s Degree in a relevant field or equivalent work experience.
Salary/Compensations
- $120,000—$150,000 USD
Benefits
- Flexible remote and hybrid working options
- Competitive Salary and a variable component tied to personal and company performance
- Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth
- Generous PTO and paid holidays
- Mental health benefits
- 2 MAD Days per year (Make A Difference Days for paid volunteering)
About the Company
- Shift delivers AI agents that transform insurers' most critical work. By combining deep industry expertise and unmatched data resources, Shift provides proven results that have earned the trust of hundreds of the world's leading insurers. Our insurance-grade AI is accurate, explainable, and secure—empowering human experts to move with unmatched speed, total confidence, and a renewed focus on the people they serve.
- Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance.
- Learn more at www.shift-technology.com
Equal Opportunity
- At Shift we strive to be a diverse and inclusive workforce. We welcome applications from and hire people who will contribute to the diversity of our company, without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria. Shift Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email accommodation@shift-technology.com and we will work with you to meet your accessibility needs.
- Please be aware of scammers and only trust correspondence that comes from emails ending in "shift-technology.com". We will never do initial outreach to you via Whatsapp/Text/SMS, never ask for banking information or personal identification numbers (ex. Social Security Number) as part of our recruitment process.
- Shift Technology does not accept unsolicited CVs from recruiters or employment agencies in response to the Shift Technology Careers page or a Shift Technology social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Shift Technology.