New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
Gusto

Senior GRC Analyst

Gusto
Apply →
hybrid senior full-time $183,000-205,000 San Francisco, CA

First indexed 28 Aug 2026

Description

Gusto is seeking a Security, Governance, Risk & Compliance professional to join our team managing security governance, risk and compliance initiatives.

This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC and related frameworks, while embedding security-minded practices throughout Gusto.

Responsibilities:

  • Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies,particularly supporting SOC 2 and future framework adoption.
  • Own and manage trust management platforms including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it.
  • Collaborate with Legal, Enterprise Applications, and Gusto counterparts to establish and maintain data governance policies.
  • Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams.
  • Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
  • Lead interactions with external auditors and regulatory bodies during compliance assessments and oversee responses to client security assessments and due diligence requests.
  • Stay current on relevant compliance frameworks, laws, and regulations to ensure appropriate coverage and adaptability.
  • Partner cross-functionally to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights.

Requirements:

  • 8+ years of experience in governance, risk, and compliance within SaaS, ideally in the HCM, payroll, or fintech sectors.
  • Bachelor’s degree in Business, Information Systems, or a related field.
  • Strong understanding of SaaS business models, with experience implementing controls and policies in fast-paced, product-driven environments.
  • Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams.
  • Familiarity with compliance tools and platforms such as Optro, Vanta, Drata, Viso Trust, or similar.
  • Demonstrated ability to translate complex GRC requirements into actionable, scalable processes.
  • Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders.
  • A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.
  • One or more relevant professional certifications: CISA, CRISC, or GRCP preferred.

Benefits:

  • Competitive base pay
  • Benefits
  • Equity (RSUs)
  • Physical office spaces in Denver, San Francisco, and New York City
  • Hybrid work arrangement (approximately 2-3 days per week in the office)
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting: https://job-boards.greenhouse.io/gusto/jobs/8082139