San Francisco, CA
14 days ago
Senior GRC Analyst
The Problems You'll Solve

At Carta, our employees set out on a mission to unlock the power of equity ownership for more people in more places. We believe that the problems we solve today unlock the opportunities of tomorrow.

As a Senior GRC Analyst,  you’ll work to assess regulatory requirements and accordingly establish and maintain  governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance metrics, and build and manage policies and standards.

Here are some problems we’d love for you to help us solve: 

Manage and continually improve the Carta Governance, Risk, and Compliance  program, ensuring it is aligned with our security strategy and business objectives. Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements. Lead and coordinate internal and external security audits. Perform security assessments of vendors, third parties, and applications. Partner with cross functional teams to review initiatives that could impact compliance requirements Manage risk program activities including risk identification, tracking, and prioritization. Collaborate with engineering and product teams to assess risk posture and compliance status, and support remediation activities. The Team You'll Work With

You will be part of a security-minded team that believes in progress over perfection and where security culture and mindset is key. Our team is rethinking how GRC activities can be accomplished in innovative ways. We do not focus on building processes, but instead how to solve business problems while minimizing and managing risk exposure for Carta.

About You

We are looking for candidates who have:

A strong understanding and working knowledge of information security and compliance frameworks, such as SOC 1  and 2, ISO 27001, NIST CSF, GDPR, CCPA, FINRA, SOX and SEC cybersecurity requirements. Excellent judgment and the ability to make balanced  decisions when working with complex situations. Proven understanding of public cloud infrastructure and services in AWS and GCP including knowledge of cloud-native security protection measures, tools, and techniques Proven  ability to collaborate with cross-functional teams and affect change to accomplish goals. Excellent written and verbal communication skills, including the ability to effectively communicate business and cybersecurity risk. 5+ years of experience in developing  and executing governance, risk and compliance functions. Salary

Carta’s compensation package includes a market competitive salary, equity for all full time roles, exceptional benefits, and, for applicable roles, commissions plans. Our minimum cash compensation (salary + commission if applicable) range for this role is:

$148,750 - $175,000 in San Francisco, CA; Santa Clara, CA; New York City, NY $141,313 - $166,250 in Seattle, WA

Final offers may vary from the amount listed based on geography, candidate experience and expertise, and other factors.

Confirm your E-mail: Send Email