GRC Analyst at Upwind Security | CA, US | Rezi

GRC Analyst at Upwind Security

GRC Analyst

Upwind Security · CA, US

Today

GRC Analyst

Upwind Security · CA, US

2 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this GRC Analyst role.

Rezi rewrites your resume against Upwind Security's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the GRC Analyst posting at Upwind Security — free, in seconds.

About the Role

Upwind is seeking a motivated and resourceful GRC Analyst to join our Security & Compliance team. This hands-on role involves supporting core GRC functions, including risk assessments, audits, policy governance, and compliance programs, while partnering with teams across the company to implement sustainable solutions. The ideal candidate will leverage modern cloud-based tools, automation, and AI to enhance GRC effectiveness and scalability.

Responsibilities

  • Operate and improve Upwind's GRC and security compliance programs
  • Support compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, documentation, remediation tracking, continuous monitoring, and audit readiness
  • Coordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HR
  • Translate compliance requirements into clear actions for technical and business teams
  • Perform control assessments, gap analyses, and risk assessments, and recommend remediation strategies
  • Work with process owners to build sustainable and evidence-based remediation plans
  • Track vulnerabilities, risks, audit findings, and POA&Ms through completion
  • Handle customer security questionnaires, due diligence requests, and security documentation
  • Support third-party risk management and vendor security assessments
  • Write and maintain policies, standards, procedures, and control documentation
  • Maintain GRC systems, evidence repositories, and risk registers
  • Research new regulatory and customer requirements and determine applicability
  • Utilize AI and automation to expedite research, documentation, evidence organization, and workflows, ensuring appropriate validation and data handling
  • Proactively identify and report gaps and issues with proposed solutions

Requirements

  • 3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit
  • Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks
  • Experience supporting audits, assessments, security questionnaires, or evidence collection
  • Strong written communication and documentation skills
  • Sufficient technical fluency to collaborate effectively with Engineering, IT, and Security teams
  • Ability to translate audit findings into actionable remediation plans that process owners will adopt
  • Comfort working in a fast-paced environment with shifting priorities
  • Demonstrated ability to drive assigned work to completion and proactively flag blockers
  • Curiosity to research unfamiliar requirements and ask pertinent questions
  • Demonstrated use of technology to improve GRC work (e.g., risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, workflow automation)
  • Organized and detail-oriented

Skills

  • NIST 800-53
  • SOC 2
  • ISO 27001
  • NIST CSF
  • Risk Assessments
  • Internal Audits
  • Policy Governance
  • Third-Party Risk Management
  • Customer Trust and Assurance
  • Compliance Programs
  • Cloud Security
  • AI-enabled Tools
  • Automation
  • Jira
  • GitHub

Location

  • Remote

Work Type

  • Full-time

Experience Level

  • Mid-level

Education Level

  • Relevant certifications such as Security+, CISA, CRISC, CISM, CGRC, ISO 27001, or similar.

About the Company

  • Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management.
  • Utilizes industry-leading efficiency and eBPF-powered sensors.
  • Offers agentless cloud posture discovery, real-time threat protection, and integrated API security.
  • One of the fastest-growing companies in cloud and AI security.
  • Building the GTM engine to match its growth.