Gusto
Gusto simplifies HR, payroll & benefits for modern businesses.
Seattle, WA, USA
Hybrid

Security Governance Risk and Compliance (GRC) Lead

Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Employer Provided Salary: 144,000-220,000 Annually
Salary data is provided by the employer. Please note this is not a guarantee of compensation.

About Gusto
Gusto is a modern, online people platform that helps small businesses take care of their teams. On top of full-service payroll, Gusto offers health insurance, 401(k)s, expert HR, and team management tools. Today, Gusto offices in Denver, San Francisco, and New York serve more than 300,000 businesses nationwide.
Our mission is to create a world where work empowers a better life, and it starts right here at Gusto. That's why we're committed to building a collaborative and inclusive workplace, both physically and virtually. Learn more about our Total Rewards philosophy .
Security Governance Risk and Compliance (GRC) Lead
(San Francisco, Denver, NYC or Remote)
Gusto processes billions of dollars in payroll every month for small businesses and their employees. Our clients trust us with a huge amount of personally identifiable information (PII) and protected health information (PHI), including SSNs, EINs, salaries, home addresses, and more. Our business is largely built on trust, as a result protecting our clients' information is our top priority.
The Governance Risk and Compliance (GRC) team is responsible for ensuring that Gusto complies with all applicable laws, regulations and its own internal controls, manages its risks effectively, and maintains a high level of information security. As a Lead GRC Analyst at Gusto, you will play a critical role in ensuring that our organization adheres to the highest standards of governance, risk management, and compliance, including managing of all the pre and post sales IT & Security support for Gusto Embedded.
Here's what you'll do day-to-day:

  • Develop, implement, and maintain a comprehensive strategy and supporting documentation that aligns with the business goals and objectives to help support all pre and post sales IT & Security support for Gusto embedded payroll.
  • Support pre-sales initiatives with large potential customers by aligning with the internal Sales team on who Gusto is targeting in order to perform initial compatibility due diligence, including reputational checks, public breach history, etc.
  • Support the continued refinement of tier-based security requirements, inclusive of internal service level objectives (SLOs).
  • Aligning to a chosen security framework with explicit guidelines for each type of partner Gusto would work with.
  • Creation of playbooks, driving agility and efficiency, improving Gusto's embedded payroll service, including current controls and positioning IT & Security as a competitive advantage in our go-to-market strategy.
  • Develop project plans to capture key milestones, sign off and support throughout the pre (and post) sales process.
  • Understand, triage and respond to all partner due diligence requirements in a centralized, organized, and timely manner. For areas with identified gaps, coordinate internal discussions for a path to remediation.
  • Facilitate negotiations with partners to ensure there is risk reduction for both parties, including ensuring any commitments from Gusto are specific, time-bound and achievable prior to insertion in a contract.
  • Ensure there is continued trust with our Embedded Partners by ensuring proactive communication of external security and IT exam or scan results and management of on-going Security or IT requirements inclusive of annual audits, attestations and other due diligence exercises.
  • Continuously monitor changes in compliance regulations, standards, and best practices, and adapt the company's GRC program accordingly.
  • Lead efforts to drive process improvement and enhance the effectiveness of the GRC function.


Here's what we're looking for:

  • 8+ years of experience in the GRC, audit, compliance space assisting an organization in working towards SOX, SOC 1, SOC 2, ISO 27001, PCI and HIPAA.
  • Experience with ISO 27001, ISO 27002, NIST CSF and working knowledge of ISO 27005 and ISO 27018
  • Client-facing experience managing pre and post sales for IT & Security support
  • Relevant certifications (e.g., CISA, CISSP, CRISC, CISM) preferred.
  • Excellent analytical, problem-solving, and project management skills.
  • Ability to work collaboratively with cross-functional teams and stakeholders, from control owners up to the executive level.
  • High attention to detail and a commitment to upholding the highest standards of data security and compliance.
  • Experience with response coordination tools like Loopio, RFPio, etc.


Our cash compensation amount for this role is targeted at $144,000/yr to $180,000/yr in Denver & most remote locations, and $174,000/yr to $210,000/yr for San Francisco & New York. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.
Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale.
Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.
When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required.
Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at Gusto.
Gusto is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Gusto considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gusto is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you require assistance in filling out a Gusto job application, please reach out to [email protected].

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are Gusto Perks + Benefits

Gusto Benefits Overview

Taking care of our people is just as important as taking care of our customers. We offer competitive total compensation packages with an emphasis on equity, along with many other great benefits, some of which are included below!

Medical, dental, and vision: comprehensive medical, dental, and vision benefits, plus a variety of mental health resources.

Time off
Gusties are encouraged to take the time off they need to continue doing great work.

Inclusive healthcare
Fertility benefits, parental leave, pregnancy termination, caregiving, gender-affirming surgery, hormone treatments, transgender-inclusive services, and more.

Free meals and refreshments
If you work at one of our offices, enjoy food, drinks, and snacks— on us. Conversation and community is an added bonus!

Sabbaticals
Celebrate 5 or 10 years at Gusto and take a month off to recharge.

Stipends
Take advantage of monthly internet, phone, and wellness stipends. Enjoy commuter or remote work stipends, along with and cash for your Gusto anniversaries!

Culture
Open office floor plan
Employee resource groups
Quarterly engagement surveys
Hybrid work model
Diversity
Dedicated diversity and inclusion staff
Diversity employee resource groups
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Mental health benefits
Transgender health care benefits
Financial & Retirement
401(K)
Company equity
Child Care & Parental Leave
Generous parental leave
Family medical leave
Adoption Assistance
Fertility benefits
Gusto provides a benefit designed to support your unique parenthood journey. The benefit is not health insurance, but rather provides resources to make family forming more accessible to everyone.
Vacation + Time Off
Generous PTO
Sabbatical
Paid holidays
Paid sick days
Bereavement leave benefits
Office Perks
Commuter benefits
Free daily meals
If you work at one of our offices, enjoy food, drinks, and snacks— on us.
Free snacks and drinks
Fitness stipend
Home-office stipend for remote employees
Professional Development
Lunch and learns
Promote from within

More Jobs at Gusto

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about GustoFind similar jobs like this