Hiring.Camp

GRC (Governance, Risk, and Compliance) Analyst

Yipitdatajobs

·

Today

Location
US Remote · New York, NY, United States
Workplace
Remote
Department
Engineering Operations - Security
Source
Greenhouse

Description

About Us:

YipitData is the leading market research and analytics firm for the disruptive economy and most recently raised $475M from The Carlyle Group at a valuation of over $1B. Every day, our proprietary technology analyzes billions of alternative data points to uncover actionable insights across sectors like software, AI, cloud, e-commerce, ridesharing, and payments.

Our data and research teams transform raw data into strategic intelligence, delivering accurate, timely, and deeply contextualized analysis that our customers—ranging from the world’s top investment funds to Fortune 500 companies—depend on to drive high-stakes decisions. From sourcing and licensing novel datasets to rigorous analysis and expert narrative framing, our teams ensure clients get not just data, but clarity and confidence.

We operate globally with offices in the US, APAC, and India. Our award-winning, people-centric culture—recognized by Inc. as a Best Workplace for three consecutive years—emphasizes transparency, ownership, and continuous mastery.

What It’s Like to Work at YipitData:

YipitData isn’t a place for coasting—it’s a launchpad for ambitious, impact-driven professionals.

From day one, you’ll take the lead on meaningful work, accelerate your growth, and gain exposure that shapes careers.

Why Top Talent Chooses YipitData:

  • Ownership That Matters: You’ll lead high-impact projects with real business outcomes
  • Rapid Growth: We compress years of learning into months
  • Merit Over Titles: Trust and responsibility are earned through execution, not tenure
  • Velocity with Purpose: We move fast, support each other, and aim high—always with purpose and intention

If your ambition is matched by your work ethic—and you're hungry for a place where growth, impact, and ownership are the norm—YipitData might be the opportunity you’ve been waiting for.

About The Role:

YipitData is looking for a GRC Analyst who likes asking good questions, finding the gaps others miss, and turning complicated requirements into work people can actually complete.

You will help us answer some important questions: Are our security controls working the way we say they are? Can we prove it? Where are we taking on risk? What needs to change as our products, technology, and use of AI continue to grow?

Your work will span audits, risk assessments, control testing, vendor reviews, customer questionnaires, policies, and compliance programs. You will partner with teams across Security, IT, Engineering, Legal, Finance, and People to understand how the business operates, identify where improvements are needed, and keep the work moving through completion.

This is not a role where success means uploading documents to an audit platform. We want someone who is curious enough to understand the evidence, thoughtful enough to challenge it when it does not make sense, and organized enough to make sure nothing important gets lost in the follow-up.

This is a remote-friendly opportunity that can sit in NYC (where our headquarters is located), one of our office hubs, or anywhere else in the US. However, depending upon where the remote work is performed, income could be subject to New York State tax withholding. 

The work hours are flexible on this team, but most employees work East Coast hours.

As a GRC Analyst You Will:

  • Take ownership of GRC workstreams and drive them from the initial request through evidence collection, testing, remediation, and completion
  • Help keep YipitData audit-ready throughout the year
  • Test security controls and determine whether they are actually working, rather than simply confirming that a document exists
  • Conduct risk assessments, identify meaningful gaps, and help teams develop remediation plans that are realistic and effective
  • Map controls across SOC 2 and other frameworks so one strong control can satisfy multiple requirements
  • Coordinate recurring work such as access reviews, control testing, policy reviews, risk updates, and audit evidence requests
  • Review vendors and help determine whether their security practices meet YipitData’s expectations
  • Support customer security questionnaires by finding the right information, validating it, and making sure our answers are accurate and consistent
  • Translate compliance requirements into clear actions for teams that do not live and breathe GRC
  • Draft and maintain policies, standards, control narratives, risk records, metrics, and other program documentation
  • Track findings and remediation commitments, follow up with owners, and keep issues from quietly sitting open forever
  • Look for ways to simplify and automate repetitive GRC work so the program can scale with the business
  • Help us think through governance for emerging technologies, including AI products, agents, and new ways of handling data

You Are Likely To Succeed If:

  • You can operate in an environment that is constantly changing: where not every process is perfect or every answer is immediately available
  • You have experience in security, compliance, risk, audit, privacy, vendor risk, or another field that taught you how to evaluate whether expectations are being met
  • You understand that evidence is only useful if it actually proves the control
  • You can connect a policy or framework requirement to what people and systems are doing in the real world
  • You are familiar with SOC 2, NIST CSF,  or similar security and compliance frameworks
  • You are a strong writer who can make complicated requirements clear for those not familiar with security frameworks
  • You notice inconsistencies, missing information, and answers that do not quite add up
  • You are comfortable asking follow-up questions and respectfully pushing back when something needs a closer look
  • You can keep multiple workstreams organized, meet deadlines, and follow through
  • You communicate well with both technical and non-technical teams and can explain why a requirement matters
  • You take ownership, use good judgment, and know when to work independently versus when to escalate
  • You are interested in figuring out how traditional governance needs to evolve for AI and other emerging technologies

What We Offer:

Our compensation package includes comprehensive benefits, perks, and a competitive salary: 

  • We care about your personal life, and we mean it. We offer flexible work hours, flexible vacation, a generous 401K match, parental leave, team events, wellness budget, learning reimbursement, and more!
  • Your growth at YipitData is determined by the impact that you are making, not by tenure, unnecessary facetime, or office politics. Everyone at YipitData is empowered to learn, self-improve, and master their skills in an environment focused on ownership, respect, and trust. See more on our high-impact, high-opportunity work environment above.
  • The annual base salary range for this position is anticipated to be $102,500 / year. Final compensation may be determined by a number of factors, including, but not limited to, the applicant’s experience, knowledge, skills, abilities, and internal team benchmarks.
  • The compensation package also includes equity.

This role may be performed fully remotely within the United States. Please note that our US headquarters are located in NYC. If the remote work is performed outside of these offices, income may be subject to New York State tax withholding.

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender, gender identity or expression, or veteran status. We are proud to be an equal opportunity employer.

Job Applicant Privacy Notice

Skills

SOCComplianceSOC 2

Similar Jobs

30

Sr Project Manager, GRC (Governance Risk and Compliance)

Coterie · Remote (United States) · Hybrid, Remote

1 week ago

GRC (Governance, Risk, and Compliance) Engineer

MISO Default · Carmel, IN

2 weeks ago

Customer Success Manager - GRC (Governance, Risk, and Compliance)

Workiva · Remote - IL, United States of America +2 · Remote

1 month ago

GRC (Governance, Risk, and Compliance) Analyst

Yipitdata · US Remote +1 · Remote

10 months ago

Associate - Assurance - GRC (Governance, Risk, and Compliance) Centralized team

Pwc · Jakarta - Gd. WTC 3, Indonesia

1+ year ago

Associate 2 - Assurance - Risk Assurance - GRC (Governance, Risk and Compliance)

Pwc · Jakarta - Gd. WTC 3, Indonesia

1+ year ago

Governance, Risk & Compliance (GRC) Analyst

Chaosindustries · El Segundo, California, United States +1 · Remote, Onsite

Yesterday

Experienced Associate - Governance, Risk & Compliance (GRC) Enablement Solutions

Pwc · Kuala Lumpur Office, Malaysia

3 days ago

Senior Associate - Governance, Risk & Compliance (GRC) Enablement Solutions

Pwc · Kuala Lumpur Office, Malaysia

3 days ago

Governance, Risk & Compliance (GRC) Lead, Federal

Peregrinetechnologies · Washington, D.C. +1

1 week ago

Governance, Risk & Compliance (GRC) Consultant

Cat · Irving, Texas, United States of America

1 week ago

Senior Consultant — Governance, Risk & Compliance (GRC)

Lostar · Istanbul & Sakarya, Turkey · Remote, Hybrid

4 weeks ago

Information Security Intern – Governance, Risk & Compliance (GRC)

Cc · LONDON BOND STREET HOUSE, United Kingdom

1 month ago

Manager, Cybersecurity Governance, Risk & Compliance (GRC)

Conagrabrands · 11 Omaha NE, United States of America

1 month ago

Security Governance Risk & Compliance (GRC) Analyst

Virtru · Washington, DC - Remote · Remote

1 month ago

Manager and Senior Manager: Governance, Risk, & Compliance (GRC)

Whoop · Boston, MA · Onsite

1 month ago

Governance, Risk & Compliance (GRC) Manager

Riverside Re · Beavercreek, OH, US

1 month ago

Information Security Analyst 5, Governance, Risk & Compliance (GRC)

SanDisk · Batu Kawan, Penang, Malaysia

1 month ago

Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri · Saint Louis, MO

1 month ago

Security Governance, Risk & Compliance (GRC) Analyst

Delivery Hero · Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia · Hybrid

2 months ago

Governance, Risk & Compliance (GRC) Manager

Northwoodspace · Torrance, CA

2 months ago

Cybersecurity Governance, Risk & Compliance (GRC) Specialist

Ithr 360 Consulting Fze · Dubai · Remote, Hybrid, Onsite

2 months ago

IT Governance Risk & Compliance (GRC) Analyst

Trustmark · Ridgeland, MS, US +1 · Remote

2 months ago

Governance, Risk & Compliance (GRC) Lead

Glen Dimplex Europe Holdings Ltd · Cloghran, Dublin, Ireland

4 months ago

Senior Consultant - IT Governance, Risk & Compliance (GRC)

Infinitive Inc · Ashburn, VA

5 months ago

Governance, Risk & Compliance (GRC) Expert (m/w/d)

Positivethinkingcompanytech · Deutschland · Hybrid

5 months ago

Governance, Risk & Compliance (GRC) Expert (m/w/d)

Positivethinkingcompanytech · Deutschland · Hybrid

5 months ago

Associate 2 - Risk Assurance - Governance, Risk, Compliance (GRC) - FY26

Pwc · Jakarta - Gd. WTC 3, Indonesia

5 months ago

Cyber Governance, Risk & Compliance (GRC) – Senior Associate

Pwc · Singapore - Marina One

6 months ago

Senior Associate - Governance, Risk & Compliance (GRC) Enablement Solutions

Pwc · Kuala Lumpur Office, Malaysia

8 months ago