Obsidian Security Logo

Obsidian Security

GRC Analyst

Job Posted 25 Days Ago Posted 25 Days Ago
Newport Beach, CA
110K-175K Annually
Mid level
Newport Beach, CA
110K-175K Annually
Mid level
The GRC Analyst will manage governance, risk, compliance, conduct audits, assess third-party vendors, and enhance security operations.
The summary above was generated by AI

Obsidian Security was founded in 2017 to solve the unaddressed blindspot of SaaS Security. SaaS applications provide the tools employees need to succeed and hold the business’ most critical information. If those tools become unavailable or that data is jeopardized, there is a detrimental impact on the organization. 

Obsidian proudly offers the industry's most comprehensive and powerful SaaS defense solution. We are committed to solving the challenge of SaaS Security for our customers as efficiently and effectively as possible.

We’re a passionate team optimizing for impact by solving some of the biggest challenges in cybersecurity today. We listen closely to our customers, iterate quickly, and (over) deliver to delight them. Working at Obsidian means contributing to an industry-leading cybersecurity product in an environment where customer satisfaction, privacy, and data ethics are paramount.

Obsidian Security is looking for a GRC Analyst to join our IT team.  This Analyst will have a broad scope, including:

Governance & Policy Management

  • Maintain and update the Master Controls Register with mappings to frameworks (e.g., SOC 2, ISO 27001, ISO 27701, ISO 42001, GDPR, NIST).
  • Track control ownership, implementation status, and evidence requirements across the organization.
  • Assist in drafting, updating, and version-controlling security and compliance policies, standards, and procedures.
  • Ensure policy reviews and approvals occur on schedule; coordinate with document owners and stakeholders.

Risk Management

  • Support ongoing risk assessments and periodic risk reviews across business units.
  • Document risk findings, mitigation plans, owners, and timelines in the Risk Register.
  • Conduct third-party risk assessments for vendors, platforms, and SaaS tools.
  • Collaborate with internal teams to analyze new risks introduced by product changes or infrastructure updates.
  • Track risk mitigation action items and follow-up on deadlines.

Compliance and Audit Support

  • Coordinate readiness activities for internal and external audits (SOC 2, ISO, etc.).
  • Prepare and organize audit artifacts and walkthrough documentation.
  • Work with control owners to collect, review, and validate audit evidence.
  • Track open audit findings and corrective action plans; assist with resolution follow-ups.
  • Support ongoing compliance readiness posture through internal reviews and testing.

Third-Party Risk & Vendor Management

  • Maintain the vendor inventory and classify vendors based on risk levels.
  • Issue and track security questionnaires or due diligence assessments.
  • Monitor vendor compliance with contractual and regulatory requirements.
  • Coordinate vendor documentation reviews (e.g., SOC 2 reports, pen test results, certifications).

Controls Testing & Security Operations Support

  • Assist in the design and implementation of new security controls aligned to frameworks.
  • Conduct control effectiveness testing and control gap analysis.
  • Partner with engineering, DevOps, and security teams to understand and verify technical control implementations (e.g., logging, access controls, encryption).
  • Track remediation activities related to failed controls or known security issues.

Pay Transparancy

Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location, as well as the knowledge, skills and experience of the candidate. In addition to a competitive base salary, this position is eligible for equity awards and may be eligible for incentive compensation based on factors such as experience, skills, and location.

At Obsidian, we are proud to be an equal-opportunity employer. We value diversity and hire for talent, passion, and compassion. In compliance with federal law, all persons hired will be required to submit satisfactory proof of identity and legal authorization.  If you have a need that requires accommodation, please contact accommodations@obsidiansecurity.com

Information collected and processed as part of any job applications you choose to submit is subject to Obsidian’s Applicant Privacy Policy.

Base Salary Range

$110,000$175,000 USD

Employee Benefits:

Our competitive benefits packages are designed to support our employees' well-being, both at work and at home.  Our US based employees enjoy:

  • Competitive compensation with equity and 401k
  • Comprehensive healthcare with dental and vision coverage
  • Flexible paid time off and paid holiday time off 
  • 12 weeks of new parent or family leave
  • Personal and professional development resources

For more details on our US benefits, or for information on our international benefits, please see here.

Top Skills

Gdpr
Iso 27001
Iso 27701
Nist
SaaS
Soc 2

Similar Jobs

3 Days Ago
Remote
Hybrid
Los Angeles, CA, USA
103K-129K Annually
Mid level
103K-129K Annually
Mid level
Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
The GRC Analyst will support Information Security Governance, Risk Management, and Compliance workflows, manage compliance projects, and maintain standards and policies.
Top Skills: CasbCobitCsaDlpFedrampIds/IpsIso 27001Iso 27017Iso 27018Iso 27701Microsoft Office SuiteNist 800-53PciSIEMSoc 1Soc 2
24 Days Ago
Easy Apply
Hybrid
Long Beach, CA, USA
Easy Apply
120K-154K Annually
Senior level
120K-154K Annually
Senior level
3D Printing • Aerospace • Hardware • Robotics • Software • Manufacturing
Manage compliance with industry standards, conduct risk assessments, and integrate security principles across functions while ensuring organizational compliance.
Top Skills: CmmcHipaaHitrustIso 27001Nist 800-171Nist 800-53Pci Dss
6 Days Ago
Hybrid
3 Locations
Mid level
Mid level
Fintech • Software
As a GRC Analyst at Carta, you will establish governance and risk frameworks, develop security compliance programs, perform security assessments, and collaborate with cross-functional teams to ensure data privacy and compliance. You will drive risk management practices and review contracts with a focus on information security.

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account