Senior GRC Analyst

Reposted 21 Days Ago
Hiring Remotely in U.S.
Remote
130K-160K Annually
Senior level
HR Tech • Payments • Software • Financial Services
Mission: Helping companies reimagine the world of benefits and how they are delivered to employees.
The Role
The Senior GRC Analyst will manage governance, risk, compliance, and audit readiness programs, ensuring security policies and compliance frameworks are adhered to, while collaborating with various teams across the company.
Summary Generated by Built In
About Us

At Benepass we're making benefits easy. We believe people are the most important asset to any company. Traditional one-size-fits-all benefits packages no longer cut it in today's hybrid and remote-first environment. With Benepass, companies can tailor their benefits to the unique needs of their workforce.

Through our easy-to-use and highly customizable fintech platform, People teams can implement, administer, and track the benefits that meet employees where they are. Employers design their benefits and perks plan by setting a contribution amount and eligible spend categories. Every employee has their own individual definition of wellness and needs different things to help them be their most productive, fulfilled self.

Our Mission

Helping companies reimagine how companies take care of their people.

Our Investors

We are backed by leading investors, including Centana Growth Partners, Portage Ventures, Threshold Ventures, Gradient Ventures, Workday Ventures, and Clocktower Technology Ventures. To date, the company has raised approximately $75 million in equity capital.

Articles
  • Founder Story - Jaclyn Chen

  • Benepass Raises $40M Series B

Candidate Resources
  • Benepass | Candidate Resource Page

  • Benepass Listed on Inc. Magazine's Best Workplaces of 2023

Team & Role

As a Senior GRC Analyst at Benepass, you will help operate and mature the governance, risk, compliance, audit readiness, and customer assurance programs that support our business, customers, and employees. You will work across security policies, internal controls, audit evidence, risk tracking, security questionnaires, and compliance operations.

Reporting to the Head of Infosec & GRC, you will be a key individual contributor on a lean security team. You will partner closely with Security, Engineering, IT, People, Legal, Finance, Sales, Customer Success, and Product to make our security and compliance programs clear, practical, and reliable.

You are detail-oriented, organized, and pragmatic. You know how to bring structure to ambiguity, communicate clearly with technical and non-technical stakeholders, and balance compliance rigor with the speed of a growing startup.

Role Location & Travel

This remote role is based in the United States or Canada. You will be expected to attend company-wide on-site events three to four times per year, as well as occasional on-site office travel as necessary.

What You'll Do
  • Governance & Policy: Maintain and improve information security policies, standards, procedures, control documentation, and related governance materials.

  • Control Mapping: Help map policies and controls to frameworks such as SOC 2, ISO 27001/27002, HITRUST, NIST CSF 2.0, and other customer, regulatory, or security requirements.

  • Policy Operations: Support policy exceptions, risk acceptances, remediation tracking, control owner follow-ups, and recurring governance workflows.

  • Compliance & Audit Readiness: Support SOC 2, ISO 27001, and HITRUST readiness, audit preparation, evidence collection, auditor coordination, and audit response management.

  • Control Testing: Maintain recurring evidence-gathering and control testing workflows, helping ensure controls operate consistently across the business.

  • Findings & Remediation: Track audit findings, control gaps, remediation plans, owners, due dates, and closure evidence.

  • Risk Management: Support risk assessments, control gap assessments, internal reviews, and maintenance of the risk register.

  • Business Communication: Translate technical and security risks into clear business language, including mitigations, ownership, timelines, and residual risk.

  • Customer Assurance: Own or support customer security questionnaires, RFP security sections, due diligence requests, and trust or compliance documentation.

  • Response Libraries: Maintain reusable questionnaire content, approved responses, compliance artifacts, and customer-facing assurance materials.

  • Security Awareness: Support employee security awareness programs and create clear internal guidance for policies, controls, and compliance responsibilities.

  • Vendor Risk: Support vendor security reviews, third-party risk assessments, remediation tracking, risk acceptance documentation, and vendor compliance evidence.

  • Tooling & Process Improvement: Use GRC platforms such as Vanta, Drata, Thoropass, Secureframe, or similar tools to improve evidence collection, control monitoring, task tracking, reporting, and repeatable compliance operations.

What We're Looking For
  • 5+ years of experience in GRC, information security compliance, IT audit, risk management, security assurance, or a closely related field.

  • Hands-on experience supporting SOC 2 audits and readiness activities.

  • Working knowledge of ISO 27001/27002, HITRUST, NIST CSF, or similar security and compliance frameworks.

  • Experience maintaining security policies, controls, control narratives, evidence repositories, and audit documentation.

  • Experience supporting internal or external audits, including evidence collection, auditor coordination, control owner follow-up, and remediation tracking.

  • Strong written communication skills, with the ability to produce clear policies, questionnaire responses, process documentation, and stakeholder updates.

  • Excellent attention to detail and project management discipline.

  • Experience responding to customer security questionnaires, RFP security sections, or due diligence requests.

  • Familiarity with GRC, compliance automation, or audit management tools.

  • Experience in SaaS, fintech, benefits, healthcare, or other regulated environments.

  • Comfort working in a startup or fast-moving environment where processes need to be mature enough to scale without creating unnecessary friction.

  • Ability to work with both technical and non-technical teams and communicate security and compliance expectations clearly.

Nice-to-Haves
  • Certifications such as CISA, CISM, CRISC, HITRUST CCSFP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or Security+.

  • Experience supporting HITRUST readiness or validated assessments.

  • Experience with vendor risk management or third-party security assessments.

  • Experience supporting HIPAA, PCI DSS, GDPR, or other privacy and security frameworks.

  • Experience at a startup or high-growth technology company.

  • Familiarity with customer trust centers, security assurance portals, or reusable security response libraries.

Compensation

$130,000-160,000 + Equity

Range(s) is subject to change. Benepass takes a number of factors into account when determining individual starting pay, including market comparables, interview performance, peer compensation, and years of experience.What We Offer
  • 95% coverage of medical, dental, and vision

  • Fantastic benefits (of course 😃), including:

    • $250 WFH setup (one time)

    • $500/year Learning & Development Benefit

    • $150/month cell phone + internet

    • $100/month Wellness

    • $100/month Co-working and Commuter Benefit

  • We offer several team onsites a year

  • Flexible PTO

At Benepass, we are working towards reimagining how companies take care of their people. We are committed to creating an inclusive environment for all our employees and are seeking to build a team that reflects the diversity of the people we hope to serve with our revolutionary products. Benepass is proud to be an equal-opportunity employer.

Skills Required

  • 5+ years of experience in GRC, information security compliance, IT audit, or risk management
  • Hands-on experience supporting SOC 2 audits and readiness activities
  • Working knowledge of ISO 27001/27002, HITRUST, NIST CSF
  • Experience maintaining security policies, controls, and audit documentation
  • Strong written communication skills
  • Experience responding to customer security questionnaires or due diligence requests

Benepass Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Benepass and has not been reviewed or approved by Benepass.

  • Fair & Transparent Compensation — Pay is considered competitive for engineering and senior IC roles, and the company highlights pay transparency practices. Overall compensation satisfaction is characterized as strong, though experiences can vary by function and level.
  • Flexible Benefits — Benefits are portrayed as highly configurable, consolidating LSAs and pre‑tax accounts into a single card/app with employer‑defined categories. A single wallet and global-friendly design aim to simplify spending and increase on‑card success.
  • Healthcare Strength — Health coverage is described as comprehensive, including medical contributions, full dental and vision, and access to services such as OneMedical, Teladoc, and Talkspace. These elements can materially enhance perceived total compensation.

Benepass Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
38 Employees
Year Founded: 2019

What We Do

Benepass is a platform to flexibly distribute benefits and non-salary compensation globally. Through our easy-to-use and highly customizable fintech platform, People teams can implement, administer, and track the modern benefits that their employees are looking for. Employers design their benefits and perks plan by setting a contribution amount and eligible spending categories. Every employee has their own individual definition of wellness and needs different things to help them be their most productive, fulfilled selves. Our card-first technology gives employees a physical and virtual VISA card with all their benefits from their employer coded on the card including: - Pre-Tax Benefits: Public Transit, Parking, Health FSA, Dependent Care FSA, HSA - Perks Programs: Wellness (Physical and Mental), Food, Family and Childcare benefits, Work from Home, Professional Development, LSA, and custom programs for your company! Today we’re the vendor of choice for 100+ clients representing 100,000+ employees in more than 30 countries.

Why Work With Us

We're a group of smart low ego hard-working professionals. We believe that we hire the best and give a high degree of ownership to be creative and execute. Being a part of a 37-person company you get the chance to directly shape how we build our culture, product, and trajectory of the company in a green field space. We practice what we preach!

Gallery

Gallery

Similar Jobs

In-Office or Remote
7 Locations
1992 Employees
106K-222K Annually

Bamboo Health Logo Bamboo Health

Sr. GRC Analyst

Big Data • Healthtech
Remote
United States
460 Employees

Benepass Logo Benepass

Senior GRC Analyst

Fintech • HR Tech • Software • Financial Services
Remote
U.S.
200 Employees
130K-160K Annually
Remote
USA
280 Employees
95K-105K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account