Skip to main content
Back to Jobs

GRC Analyst

Drive compliance activities like user access reviews and vendor risk assessments

As a GRC Analyst at Zip, you will drive and perform periodic compliance-related activities such as user access reviews, internal audits, and vendor risk assessments. You will lead conversations and curate responses for customers’ security, compliance, and governance teams in due diligence and security questionnaires. You will guide internal control owners and stakeholders to understand requirements, take accountability, and operationalize thei...

Why This Role?

Help maintain existing SOC and ISO certifications while supporting new certifications for AI products and EU market entry

Key Responsibilities

  • Drive and perform periodic compliance-related activities such as user access reviews, internal audits, and vendor risk assessments
  • Lead conversations and curate responses for customers’ security, compliance, and governance teams in due diligence and security questionnair
  • Guide internal control owners and stakeholders to understand requirements, take accountability, and operationalize their controls
  • Collaborate with internal stakeholders and external auditors to support third party audits including SOC 1, SOC 2, and ISO 27001
  • Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory req

Requirements

  • Bachelor’s degree in a related field
  • 2+ years of experience in GRC, compliance, or a related field

Required Skills

compliancesecurityauditrisk-assessmentcommunicationrisk assessmentaudit supportpolicy developmentstakeholder communicationsecurity frameworks

Indonesia Context

Working Hours Overlap:
Flexible — work your own hours
See remote (USD) vs local pay →

Keywords

GRC AnalystcomplianceSOC 2ISO 27001vendor risksecurity questionnaires
View Original Description from Ashby Job Boards

Original description from Ashby Job Boards

ABOUT ZIP Zip is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before. The world’s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together they’ve saved over $8 billion and processed over $500 billion in spend. Zip’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA. Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups. YOUR ROLE The Security & Compliance team at Zip is committed to providing a high level of security assurance to customers, aligning security goals with business objectives and customer requirements. As a GRC Analyst at Zip, you’ll be a key driver for ensuring the success of compliance programs at a fast-growing company. Your contributions will be pivotal to the overall growth and competitive edge of Zip’s GRC program. You’ll ensure we can securely and compliantly build new features, help design and scale the compliance programs that power our expansion. You’ll help maintain our existing SOC and ISO certifications while supporting new certifications, from AI products to entry into new markets like the EU and highly-regulated industries. RESPONSIBILITIES - Drive and perform periodic compliance-related activities, such as user access reviews, internal audits, and vendor risk assessments - Lead conversations and curate responses for customers’ security, compliance, and governance teams in due diligence and security questionnaires - Guide internal control owners and stakeholders to understand requirements, take accountability, and operationalize their controls. - Collaborate with internal stakeholders and external auditors to support third party audits including SOC 1, SOC 2, and ISO 27001 - Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements REQUIRED QUALIFICATIONS - Bachelor’s degree in a related field - 2+ years of experience in GRC, information security consulting, cybersecurity risk, audits, or similar roles - Strong written and verbal communication skills with both technical and non-technical stakeholders - Familiarity with and participation in one or more of the following frameworks: SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP - Familiarity with information security fundamentals for cloud software systems PREFERRED QUALIFICATIONS - Professional certifications in information security are a plus but not required The salary range for this role is $95,000 - $150,000. The salary for this position is determined based on a variety of job-related factors that may include location, relevant experience, education, or particular skills and expertise. PERKS & BENEFITS At Zip, we’re committed to providing our employees with everything they need to do their best work. - 📈 Start-up equity - 🦷 100% health, vision & dental coverage options - 🍽️ Catered breakfast, lunch, & dinner - 🌴 Flexible PTO - 🏋️‍♀️ ClassPass membership - 🚍 Monthly commuter benefit - 🚠 Team building events & happy hours - 💻 Home office stipend - 🛜 Phone/internet reimbursement - 🍼 Paid parental leave - 🧑‍🧑‍🧒‍🧒 Fertility stipend - 💸 401k plan - 🤖 Unlimited AI token usage We're looking to hire Zipsters and that means hiring people who take ownership, communicate openly, have an underdog mindset, and are excited to increase the pace of innovation for every business in the world. We encourage all candidates to apply even if your experience doesn't exactly match up to our job description. We are committed to building a diverse and inclusive workspace where everyone (regardless of age, religion, ethnicity, gender, sexual orientation, and more) feels like they belong. We look forward to hearing from you!

Salary Context

Similar Data & Analytics roles on LokerDollar pay around $115k/yr (range $26.292k–999.999k/yr, n=71 active listings).

Hiring at Zip

Zip has 46 other active roles on LokerDollar and has been hiring here since Jul 23, 2026 — across Data & Analytics, Engineering, Marketing.

View all Zip openings →

Openness not stated by employer — check the listing

Company
Zip
Source
Ashby Job Boards
Salary
Job Type
full time
Location
Remote
Seniority
mid
PostedFresh
Jul 23, 2026

Share this job

Help a friend find their next remote role.

Frequently asked questions

Is GRC Analyst at Zip a remote job?
This role is based in Remote. See the listing for remote/onsite details.
What is the salary for GRC Analyst at Zip?
The listed pay range for this role is $7.917k–12.5k/mo.
What type of employment is GRC Analyst at Zip?
This is a full time position.
How do I apply?
Click the "Apply" button on this page to go to the official application at Zip.

Explore related

Market data & reports

Salary & skill-demand research built from our own listings data.

From the blog