The GRC Analyst is responsible for the operational execution of OneRail's governance, risk, and compliance program. This role owns the day-to-day work that keeps OneRail's ISO 27001:2022 ISMS, SOC 2 Type II attestation, and regulatory compliance programs running — including risk register maintenance, vendor security assessments, policy management, evidence collection, corrective action tracking, and security awareness delivery. The GRC Analyst works closely with the CISO and across every team in the organization to collect evidence, manage findings, and ensure that compliance obligations are met continuously — not just during audit windows. This is a highly cross-functional role that requires both strong process discipline and the ability to build trusted relationships with stakeholders in Engineering, HR, Legal, Finance, and Operations.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
No Education Listed
Number of Employees
1-10 employees