GRC Analyst II
Job description
About the role
You will take ownership of core GRC program areas while supporting senior-level initiatives across risk, audit, and compliance at Payscale. The role requires hands-on experience to maintain and evolve critical governance processes. You will drive compliance and risk outcomes through structured analysis and proactive problem-solving. This position demands strong communication skills to translate complex topics for diverse audiences. You will operate independently across technical and business stakeholders to ensure alignment. The role emphasizes accuracy, process discipline, and continuous improvement in all GRC activities. You will act as a key contributor to the integrity of the organization's risk and compliance posture.
Key facts
What you'll do
- Oversee the maintenance and enhancement of Payscale's data classification program, including classification schema, tagging standards, and coordination with data owners to ensure accurate and consistent classification across systems and assets.
- Partner with technology teams to maintain the system classification and ownership inventory, ensuring systems are properly classified, attributed, and reviewed on a defined cadence.
- Coordinate and support audit activities for SOC 2 and other compliance frameworks, facilitating evidence collection and documentation to meet audit objectives.
- Conduct vendor security assessments reviews to evaluate third-party risk and validate control effectiveness.
- Manage the full policy management lifecycle, including drafting new policies and standards, tracking review cycles, coordinating approvals, and maintaining version control.
- Identify control gaps or process improvement opportunities and partner with business units to implement and sustain effective controls that reduce risk exposure.
- Support the development and maintenance of risk registers, issue tracking, and remediation plans to ensure timely resolution of findings.
- Collaborate with internal audit and external auditors to streamline assessment cycles and improve the efficiency of compliance testing.
- Leverage GRC tools or platforms to centralize documentation, track metrics, and generate reports that provide visibility into program health.
- Act as a subject matter expert for GRC-related topics, providing guidance and training to cross-functional teams on policies and procedures.
- Monitor regulatory and industry trends to assess potential impacts on Payscale's risk landscape and recommend appropriate controls.
- Facilitate cross-functional workshops and working sessions to align stakeholders on risk appetite, tolerance, and mitigation strategies.
Requirements
- Hold a Bachelor's degree in cybersecurity, information systems, or a related field.
- Bring 2-4 years of work experience in GRC, information security, or a related field within a commercial SaaS or software company.
- Demonstrate a working knowledge of information security control frameworks such as SOC 2, ISO 27001, NIST 800-53, or CIS.
- Show proven experience with data classification frameworks and data governance concepts.
- Have experience conducting vendor security assessments and managing third-party risk workflows.
- Possess hands-on experience with audit support activities, including evidence collection for SOC 2 or similar frameworks.
- Maintain a solid understanding of information security policies, standards, and procedures.
- Use hands-on experience with GRC tools or platforms (e.g., Drata, ServiceNow GRC, or similar).
- Exhibit strong written and verbal communication skills with the ability to engage both technical and non-technical stakeholders.
- Show the ability to manage multiple workstreams independently, prioritize effectively, and meet deadlines in a fast-paced environment.
Practical notes
Location
Payscale has an employee centric remote-first model that provides you the flexibility to do your best work in a space that supports you, while also finding time to collaborate in person for the moments that matter.
In our remote-first model, employees can work from the location that works best for them. We do not have centralized corporate offices. Employees can choose to work from home, in company-paid co-working spaces, or any combination of the two that best suits their unique needs.
If you work from home, we recommend ensuring that you can meet the following technology, equipment and workspace requirements:
- High-Speed Internet
- A stable broadband or fiber connection (satellite is highly discouraged) with a minimum speed of 100 Mbps in a dedicated workspace that has a reliable Wi-Fi signal.
- Device for Multifactor Authentication (MFA/2FA) - smartphone, tablet, etc.
When matters arise (usually no more than a few times a year) we take the time to gather for in-person events.
Payscale has employees across the US, Canada, UK, The Philippines and Romania however we are currently unable to hire in the Quebec Province, Northern Ireland, and Hawaii.
Benefits and Perks
- Data informed decision making.
- Customer first. Always.
- Succeed together.
- Relentless about results. Obsessed with excellence.
- Lead the change. Shape the standard.
An open and inclusive environment where you'll learn and grow through programs and resources like:
- Monthly company All Hands meetings
- Regular opportunities for executive leadership exposure through things like AMAs
- Access to continued learning & development opportunities
- Our commitment to a continuous feedback culture which allows us to drive performance and career growth
- A growing network of Employee Resource Groups
- Company sponsored volunteer hours
Our more standard benefits include comprehensive medical, dental, and vision coverage, 401k with company match, paid time off, parental leave, and more.