
Senior GRC Analyst II
- Waterloo, ON
- Permanent
- Temps-plein
- Manage and continually improve the Carta Governance, Risk, and Compliance program, ensuring it is aligned with our security strategy and business objectives.
- Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements.
- Lead and coordinate internal and external security audits.
- Perform security assessments of vendors, third parties, and applications.
- Partner with cross functional teams to review initiatives that could impact compliance requirements
- Manage risk program activities including risk identification, tracking, and prioritization.
- Collaborate with engineering and product teams to assess risk posture and compliance status, and support remediation activities.
- A strong understanding and working knowledge of information security and compliance frameworks, such as SOC 1 and 2, ISO 27001, NIST CSF, GDPR, CCPA, FINRA, SOX and SEC cybersecurity requirements.
- Excellent judgment and the ability to make balanced decisions when working with complex situations.
- Proven understanding of public cloud infrastructure and services in AWS and GCP including knowledge of cloud-native security protection measures, tools, and techniques
- Proven ability to collaborate with cross-functional teams and affect change to accomplish goals.
- Excellent written and verbal communication skills, including the ability to effectively communicate business and cybersecurity risk.
- 5+ years of experience in developing and executing governance, risk and compliance functions.
- $193,800 - $228,000 in San Francisco, CA; Santa Clara, CA; New York City, NY
- $184,110 - $216,600 in Seattle, WA
- We are an equal opportunity employer and are committed to providing a positive interview experience for every candidate. If accommodations due to a disability or medical condition are needed, please connect with the talent partner via email.
- Carta uses E-Verify in the United States for employment authorization. See the
, , and . * Please note that all official communications from us will come from an @carta.com or @carta-external.com domain. Report any contact from unapproved domains to security@carta.com.