Senior GRC Analyst- Policies and Controls

Sorry, this job was removed at 10:19 p.m. (CST) on Wednesday, Aug 06, 2025
Greenwood Village, CO
In-Office
Cloud • Information Technology • Productivity • Security • Sharing Economy • Software • Infrastructure as a Service (IaaS)
Wherever you are in your cloud journey, Pax8 helps you bring your business to the next level.
The Role
Pax8 is the leading cloud-based technology marketplace, simplifying the cloud journey for our partners by integrating technology, business intelligence and proactive service to deliver an unparalleled experience. Serving thousands of partners through the indirect sales channel, our mission is to build the technology marketplace of the future. We are a fast-growing, dynamic and  high-energy startup organization, allowing you to make a meaningful impact on the business. Culture is important to us, and at Pax8, it’s business, and it IS personal. We are passionate, creative and humorously offbeat. We work hard, keep it fun, and expect the best. 
 
We Elev8 each other. We Advoc8 for our partners. We Innov8 continuously. We Celebr8 life.

No matter who you are, Pax8 is a place you can call home. We know there’s no such thing as a “perfect" candidate, so we don’t look for the right "fit" – instead, we look for the add. We encourage you to apply for a role at Pax8 even if you don’t meet 100% of the bullet points. We believe in cultivating an environment with a diversity of perspectives, in hopes that we can all thrive in an inclusive environment. 

We are only as great as our people. And we have great people all over the world. No matter where you live and work, you’re a part of the Pax8 team. This means embracing hybrid- and remote-work whenever possible.  

Position Summary:

We are seeking a detail-oriented and proactive Senior Technology Governance, Risk, and Compliance (GRC) Analyst to join our growing organization. In this role, you will play a critical part in safeguarding our cloud-based platforms by identifying and managing technology risks, supporting compliance initiatives, and ensuring the effectiveness of security controls. You will collaborate cross-functionally with teams across engineering, security, technology services, legal, and customer success to maintain our compliance posture, support audits, and drive continuous improvement in our GRC program.

The ideal candidate has a strong understanding of cloud-native technologies, SaaS delivery models, and regulatory frameworks such as SOC 2, ISO 27001, and GDPR. This role requires a mix of analytical rigor, technical acumen, and business judgment to help scale and mature our risk and compliance functions in a dynamic, fast-paced environment.

Essential Responsibilities:

  • Proven experience in Governance, Risk, and Compliance (GRC), with a focus on security policies, standards, and control implementation.
  • In-depth knowledge of one or more major security frameworks: ISO 27001, SOC 2, or NIST (800-53, 800-171, or CSF).
  • Proven experience drafting, maintaining, and rolling out security policies, standards, and procedures across a medium to large enterprise.
  • Strong understanding of technical security controls, such as access management, encryption, vulnerability management, and endpoint protection.
  • Ability to collaborate with engineering, security, and business teams to develop, train, and align technical controls with compliance and risk management requirements.
  • Familiarity with GRC platforms or tools (e.g., LogicGate, OneTrust or similar).
  • Excellent written and verbal communication skills, including the ability to simplify complex regulatory concepts for technical and non-technical audiences.
  • Demonstrated ability to work independently, manage multiple priorities, and deliver high-quality work on time.
  • Perform control assessments to ensure alignment with internal policies, regulatory requirements, and industry standards (e.g., ISO 27001, NIST, SOC 2).
  • Maintain and update the GRC framework, ensuring it supports strategic business objectives and regulatory compliance for a cloud-native environment and DevSecOps practices.
  • Coordinate and support internal and external IT audits, including evidence collection, walkthroughs, and remediation tracking.
  • Facilitate and monitor the completion of risk treatment plans, working with business units to implement mitigation strategies.
  • Lead or support the incident response process, including documentation, root cause analysis, and post-incident reviews. Includes required on-call Incident Commander rotation (approximately 1 out of 6 weeks).
  • Track and report compliance metrics, risk trends, and audit findings to key stakeholders and leadership.
  • Monitor and interpret emerging regulations and industry best practices, recommending changes to the GRC program as needed.

Ideal Skills, Experience, and Competencies:

  • 3-5 years in a technology GRC role.
  • Technical background with a focus on SaaS and multi-tenant cloud platforms highly preferred.
  • Proven experience in running assessments and/or audits with demonstratable track record of driving improvements.
  • Relevant certifications preferred (e.g., CISSP, CISA, CRISC, or ISO 27001 Lead Implementer/Auditor).

Required Behaviors:

  • Compassionate Candour—We aim to assist others with candid, actionable feedback.
  • Seek to Understand—Be open, curious and committed to learning.
  • We Before Me—Actively collaborate and seek out diverse perspectives to ensure a win for Team Pax8.
  • Do What You Say—Take ownership and honor your commitments; prioritize and deliver.
  • Light Up Learning—Be brave and try new ideas; be vulnerable and share your failures so everyone can learn from our mistakes.
  • Driven by Passion—Connects personal passion to Pax8 mission, resilient in face of adversity and uncertainty in pursuit of mission.

Required Education & Certifications:

  • B.A./B.S. in a related field or equivalent work experience.
Compensation:
  • Qualified candidates can expect a compensation range of $95,000/yr to $115,000/yr depending on experience.

Application Deadline: 08/15/2025

#LI-Remote #LI-AG1 

*** Colorado law requires an estimated closing date for job postings. Please don't be discouraged from applying if you see this date has passed ***
 
At Pax8 we believe that your Total Rewards should include a benefits package that shows how much we value our greatest assets. All FTE Pax8 people enjoy the following benefits:
  • Non-Commissioned Bonus Plans or Variable Commission
  • 401(k) plan with employer match
  • Medical, Dental & Vision Insurance
  • Employee Assistance Program
  • Employer Paid Short & Long Term Disability, Life and AD&D Insurance
  • Flexible, Open Vacation
  • Paid Sick Time Off
  • Extended Leave for Life events
  • RTD Eco Pass (For local Colorado Employees)
  • Career Development Programs
  • Stock Option Eligibility
  • Employee-led Resource Groups

Please take a moment to review our Proprietary Rights and Non-Competition Agreement —this document outlines important information about your rights and responsibilities if you join our team.

 Pax8 is an EEOC Employer.
Equal Opportunities
Pax8 is an equal opportunities employer and welcome individuals who are in possession of the appropriate requirements to work within the country the role is based in. Offered individuals will be asked to undertake identity, security compliance and reference checks. Your privacy is important to us. Your data will be held in accordance with Data Privacy best practices and processed only in accordance with our recruiting processes.
Job Applicant Privacy Notice
 

Similar Jobs

SoFi Logo SoFi

Business Analyst

Fintech • Mobile • Software • Financial Services
Easy Apply
Remote or Hybrid
United States
4500 Employees

Silverfort Logo Silverfort

Senior Manager of Corporate Communications

Information Technology • Sales • Security • Cybersecurity • Automation
Remote or Hybrid
United States
507 Employees

Sierra Space Logo Sierra Space

Software Test Engineer

Aerospace • Hardware • Information Technology • Robotics • Defense • Utilities
In-Office
Centennial, CO, USA
1600 Employees
87-119 Hourly

Sierra Space Logo Sierra Space

Software Test Engineer

Aerospace • Hardware • Information Technology • Robotics • Defense • Utilities
In-Office
Centennial, CO, USA
1600 Employees
61-84 Hourly
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Greenwood Village, CO
1,600 Employees
Year Founded: 2012

What We Do

Buy, sell, and manage cloud solutions with the marketplace that fuels your business.

Our born-in-the-cloud platform modernizes the channel’s cloud journey with consolidated billing, automated provisioning, and industry-leading PSA integrations. And our technology is backed by responsive support, educational offerings, and the resources you need to grow your cloud business.

Pax8 has displaced legacy distribution by connecting the channel ecosystem to our award-winning cloud marketplace. If you want to be successful with the cloud, you want to work with Pax8.

Why Work With Us

At Pax8, we tackle complex challenges, work hard, make time to celebrate, & give back. Being a part of the Pax8 team means being passionate about the quality of your work, caring about the people you serve, & capitalizing on opportunities to improve. It means having each other’s backs, never stopping until a problem's solved & having fun.

Gallery

Gallery

Similar Companies Hiring

Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees
Milestone Systems Thumbnail
Software • Security • Other • Big Data Analytics • Artificial Intelligence • Analytics
Lake Oswego, OR
1500 Employees
Fairly Even Thumbnail
Software • Sales • Robotics • Other • Hospitality • Hardware
New York, NY

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account