GRC Senior Analyst

Reposted 7 Days Ago
Be an Early Applicant
Tel Aviv, ISR
In-Office
Mid level
Productivity • Software • Cybersecurity
The Role
The GRC Senior Analyst will enhance the organization's GRC strategy, ensure compliance with security frameworks, conduct risk assessments, and manage audit findings. They'll collaborate across departments and maintain GRC documentation and tools.
Summary Generated by Built In
Description

Upwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. Unlike traditional tools, Upwind uses runtime data proactively for risk prioritization and posture insights, ensuring teams focus on what truly matters. With industry-leading efficiency and eBPF-powered sensors, Upwind delivers comprehensive capabilities, including agentless cloud posture discovery, real-time threat protection, and integrated API security. From misconfigurations to malware defense, Upwind ensures end-to-end, cost-effective cloud infrastructure protection. At Upwind, you’ll have the opportunity to think creatively, explore new ideas, and use your skills to make a meaningful impact on our growth.

Upwind Security is seeking a highly motivated GRC (Governance, Risk, and Compliance) Analyst to join our growing Security & Compliance team. In this role, you will be responsible for supporting the implementation, operation, and continuous improvement of our GRC framework. You will help ensure our organization’s policies, procedures, and controls align with regulatory requirements and industry best practices.

Responsibilities 

  • Support the execution and enhancement of the organization’s GRC strategy, including policy governance, risk assessments, compliance monitoring, and audit support.
  • Assist in maintaining compliance with security frameworks and standards such as ISO 27001, SOC 2, NIST, and GDPR.
  • Conduct periodic risk assessments and control gap analyses across departments.
  • Track remediation of audit findings, risks, and control deficiencies, and validate completion of corrective actions.
  • Support third-party risk management activities including vendor due diligence and ongoing assessments.
  • Help maintain the GRC tool and ensure timely updates of risk registers, controls, and evidence repositories.
  • Collaborate cross-functionally with IT, Legal, Engineering, and other business units to promote a culture of security and compliance.
  • Assist in the creation and maintenance of documentation such as policies, standards, and procedures.
  • Prepare reports and dashboards for management review.
  • Stay updated on emerging regulations, standards, and security trends.
Requirements
  • Bachelor’s degree in Information Security, Risk Management, Computer Science, or a related field.
  • 4-6 years of experience in GRC, cybersecurity, risk management, or a compliance-focused role.
  • Familiarity with common regulatory and compliance frameworks (e.g., ISO 27001, SOC 2, HIPAA, PCI-DSS, NIST CSF).
  • Experience working with GRC platforms such as Vanta, Drata, OneTrust, or similar tools is a plus.
  • Excellent communication, documentation, and stakeholder engagement skills.
  • Strong attention to detail and organizational skills.
  • Relevant certifications (e.g., CISA, CISM, CRISC, ISO 27001 LA, or similar) are a plus.

Skills Required

  • Bachelor's degree in Information Security, Risk Management, Computer Science, or a related field
  • 4-6 years of experience in GRC, cybersecurity, risk management, or compliance-focused role
  • Familiarity with regulatory and compliance frameworks
  • Experience with GRC platforms
  • Excellent communication and documentation skills
  • Strong attention to detail and organizational skills
  • Relevant certifications (e.g., CISA, CISM, CRISC, ISO 27001 LA)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, California
243 Employees
Year Founded: 2022

What We Do

Upwind Cloud Security Platform bridges intelligence from runtime to build-time, eliminating friction & boosting the productivity of your developers, security engineers, and DevOps. Upwind delivers comprehensive cloud security, precisely when and where it’s most critical.

Similar Jobs

monday.com Logo monday.com

Devops Engineer

Artificial Intelligence • Productivity • Sales • Software
Hybrid
Tel Aviv, ISR
3049 Employees

monday.com Logo monday.com

Team Lead

Artificial Intelligence • Productivity • Sales • Software
Hybrid
Tel Aviv, ISR
3049 Employees

Rubrik Logo Rubrik

Senior Back-end Engineer

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
In-Office
Tel Aviv, ISR
3000 Employees

HiBob Logo HiBob

Finops Lead

HR Tech • Information Technology • Professional Services • Sales • Software
Remote or Hybrid
Israel
1350 Employees

Similar Companies Hiring

Fairly Even Thumbnail
Hardware • Other • Robotics • Sales • Software • Hospitality
New York, NY
30 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York City, NY
100 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account