- Workplace
- Remote
- Type
- Full-time
Description
About UpwindUpwind is a next-generation Cloud Security Platform that leverages runtime context to identify and prioritize critical risks, providing precise insights and efficient cloud security management. With industry-leading efficiency and eBPF-powered sensors, Upwind delivers comprehensive capabilities including agentless cloud posture discovery, real-time threat protection, and integrated API security. We are one of the fastest-growing companies in cloud and AI security, and we're building the GTM engine to match.The OpportunityWe are looking for a motivated and resourceful GRC Analyst to join our growing Security & Compliance team.This is a hands-on role for someone who enjoys solving problems, takes ownership of their work, and is comfortable operating in a fast-paced environment where processes are continuously evolving and improving. We are looking for someone who is curious, willing to dig into unfamiliar topics, and comfortable finding practical ways to solve compliance and security challenges.The GRC Analyst will support our core GRC functions - including risk assessments, internal audits, policy governance, third-party risk, customer trust and assurance, and compliance programs - while also serving as a practical partner to teams across the company. This role should be able to move beyond identifying a gap or requirement and help teams understand what good remediation looks like and how to build sustainable processes to address it. We also want someone who is comfortable using modern cloud-based security, compliance, automation, and AI-enabled tools to make GRC work more effective and scalable.We also value people who have experience in using AI and automation to make GRC work smarter and more scalable, while applying appropriate judgment and validation to the output.What You'll DoOperate and improve Upwind's GRC and security compliance programsSupport compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, documentation, remediation tracking, continuous monitoring, and audit readinessCoordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HRTranslate compliance requirements into clear actions for technical and business teamsPerform control assessments, gap analyses, and risk assessments, and recommend how to fix what you findWork with process owners to build remediation that holds up over time and can be evidencedTrack vulnerabilities, risks, audit findings, and POA&Ms through completionHandle customer security questionnaires, due diligence requests, and security documentationSupport third-party risk management and vendor security assessmentsWrite and maintain policies, standards, procedures, and control documentationMaintain GRC systems, evidence repositories, and risk registersResearch new regulatory and customer requirements and determine how they apply to usUse AI and automation to speed up research, documentation, evidence organization, and workflow, with appropriate validation and data handlingRaise gaps and issues early, with a proposed fix