Governance, Risk, and Compliance Intern
NotionUSAInternship4w ago$50 - $54
Job description
About the role
Notion is on the lookout for an enthusiastic intern to join its Governance, Risk, and Compliance (GRC) team. This position is crucial for ensuring the integrity and security of Notion's expanding platform. As an intern, you will collaborate with various teams to design and implement effective information security strategies that focus on governance, risk management, and compliance. Your contributions will play a vital role in maintaining user trust and enhancing the overall functionality of Notion's offerings.
Key facts
What you'll do
- Collaborate with the GRC team to enhance existing security compliance frameworks, sales enablement tools, training programs, and governance initiatives.
- Develop automated solutions for collecting compliance evidence by designing custom connectors that streamline processes.
- Participate in delivering security awareness training sessions to educate staff on best practices and compliance requirements.
- Refine on-call procedures to better address the growing demands of the business, utilizing custom AI agents and automation techniques.
- Work alongside various departments to uphold essential certifications such as SOC2 Type II, ISO 27001, and HIPAA, ensuring compliance with industry standards.
- Assist in conducting risk assessments and audits to identify potential vulnerabilities and recommend actionable improvements.
- Contribute to the documentation of policies and procedures related to governance, risk, and compliance to ensure clarity and accessibility for all team members.
- Engage in cross-functional projects that promote a culture of security awareness and compliance throughout the organization.
- Analyze and report on compliance metrics to provide insights into the effectiveness of current GRC initiatives.
- Stay updated on industry trends and regulatory changes to ensure that Notion remains compliant with evolving standards.
- Support the development of training materials and resources that empower employees to understand their roles in maintaining security and compliance.
- Participate in team meetings and brainstorming sessions to foster a collaborative environment and share innovative ideas.
Requirements
- Currently enrolled in a Bachelor's or Master's degree program in fields such as Computer Science, Information Technology, Management Information Systems, Cybersecurity, or a related discipline.
- Previous internship experience in a relevant field is preferred.
- Familiarity with AI agents and AI-driven coding tools is advantageous.
- Proficiency in Python programming and experience with making REST API calls.
- Demonstrated ability to work independently on tasks that require coordination with multiple teams across different time zones.
- Strong communication skills, with the ability to articulate complex concepts to diverse stakeholders.
- A team-oriented mindset, with a passion for collaborative work and mutual learning opportunities.
- Must be available to work from the San Francisco office throughout the internship duration.
- An eagerness to explore and AI tools to enhance productivity and outcomes.
Nice to have
- Experience with projects or roles focused on Security Governance, Risk, and Compliance (GRC).
- Relevant security certifications such as CISSP, CRISC, or ISO 27001 Lead Implementer would be beneficial.
- Familiarity with Security Orchestration, Automation, and Response (SOAR) tools, such as Tines, is a plus.
Skills & tools
- Proficient in Python and REST API integration.
- Familiar with compliance frameworks and standards including SOC2, ISO 27001, and HIPAA.
- Experience with automation tools and techniques to streamline compliance processes.
- Strong analytical skills for assessing risks and compliance metrics.
- Excellent communication and interpersonal skills for effective collaboration.
Practical notes
- This internship is an in-person opportunity requiring attendance at the San Francisco office during the specified internship period.
- Notion mandates that all interns work from the office on Mondays, Tuesdays, and Thursdays, with the possibility of additional in-office days as needed.
- The internship is scheduled to run from January to April 2026, providing a valuable opportunity to gain hands-on experience in the field of governance, risk, and compliance.