About Us

At ControlSage, we help fast-growing companies turn compliance from a bottleneck into a competitive advantage. Our managed compliance platform combines AI-powered automation with hands-on expert guidance to help startups and scaleups achieve and maintain SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, and other critical certifications without slowing down engineering.

Our team includes security engineers, compliance experts, and former auditors who care about solving real problems for real businesses. Whether you're mapping controls, closing an audit, or building a governance program from scratch, your work here directly determines whether our customers can close their next enterprise deal.

The Role

We're looking for a GRC Analyst to join our growing Security and Compliance function. You'll be the backbone of compliance work at the intersection of Engineering, Legal, and Product. This role builds and maintains compliance programs as part of our security team. Our goal is simple: earn and keep the trust of our customers. The right person translates security and risk into terms that the business and product teams can act on.

Key Responsibilities

Own and manage compliance programs across SOC 2, ISO 27001, GDPR, HIPAA, and FedRAMP

Coordinate audit activities end-to-end: evidence collection, documentation, auditor responses, and remediation tracking

Leverage AI and other tools to deliver metrics that stakeholders can consume and understand

Conduct vendor and third-party risk assessments; manage due diligence for new and existing partners

Build and maintain compliance policies, procedures, and supporting documentation

Translate regulatory and contractual requirements into actionable controls and processes

Monitor the evolving regulatory landscape (especially AI-specific regulations) and flag relevant obligations

Support Privacy-by-Design reviews for new product features and data practices

Track open compliance items and proactively drive them to closure across stakeholders

Requirements

3-5 years of experience in GRC, Information Security compliance, or a related field

Hands-on experience with SOC 2 or ISO 27001 audits, including evidence collection and gap assessments

Familiarity with privacy regulations: GDPR, CCPA, and ideally emerging AI regulatory frameworks (EU AI Act, etc.)

Experience managing vendor risk assessments and third-party due diligence processes

Strong written and verbal communication skills — you can explain compliance to engineers and legal concepts to product managers

Highly organized, able to manage multiple workstreams and deadlines without dropping the ball

Comfortable working independently in a fast-paced environment with limited process overhead

Willingness and curiosity to use modern AI tools to build simpler, faster ways to track and report data.

Preferred Qualifications

Experience at a fast-growing SaaS, AI, or search company

Bachelor’s degree or equivalent in Information Systems, Accounting, Business or related field

CISA, CISM, or CRISC certification

Salary Band

$90,000 - $140,000 USD. Our salary bands are structured based on a combination of geographic tiers and internal leveling. Compensation is determined by multiple factors assessed during the interview process, with the final offer reflecting these considerations.

Company Perks

Hubs in San Francisco and Texas offering regular in-person gatherings and co-working sessions

Flexible PTO with U.S. holidays observed and a week shutdown in December to rest and recharge*

Equity plan ( Launchin soon)

$500 work-from-home stipend to be used within a year of your start date*

$1,200 per year Health and Wellness Allowance to support your personal goals*

The chance to collaborate with a team at the forefront of compliance and AI-powered governance

*Certain perks and benefits are limited to full-time employees only.

ControlSage participates in E-Verify. We will provide the Social Security Administration (SSA) and, if necessary, the Department of Homeland Security (DHS) with information from each new employee's Form I-9 to confirm work authorization. We are also an inclusive, equitable, and accessible workplace. Please let us know if you require accommodation for any portion of the recruitment and hiring process.
Beware of recruiting scams: ControlSage will only contact you through official @controlsage.com email addresses and will never ask for payment or sensitive personal information during the hiring process.

Apply for this role

Applying for: GRC Analyst

PDF or Word, up to 5MB. Your resume is saved directly to our Drive folder.