Senior Governance, Risk, and Compliance
Job description
About the role
The Senior Governance, Risk, and Compliance Analyst owns the end-to-end lifecycle of our governance, risk, and compliance initiatives, ensuring they are robust, scalable, and aligned with our rapid growth. You will architect and implement control frameworks that proactively identify emerging risks and translate complex regulatory landscapes into actionable policies for the organization. This role requires you to lead comprehensive risk assessments that evaluate both third-party and operational exposures while driving continuous improvement across our processes. You will provide critical audit support by designing testing methodologies, gathering compelling evidence, and delivering clear insights to stakeholders and external auditors. Your work will establish the foundational documentation that defines how we manage risk and ensure adherence to our strategic objectives. You will act as a key subject matter expert, shaping the maturity of our program beyond maintenance to strategic enhancement and future-proofing. Finally, you will serve as the central liaison between security, privacy, legal, and product teams to ensure cohesive execution of our compliance posture.
Key facts
What you'll do
- Design intake workflows that capture essential control requirements and map them effectively to our event platforms, ensuring all regulatory touchpoints are addressed.
- Configure build processes within our RainFocus software to guarantee strict alignment with established risk and privacy standards, embedding compliance at the infrastructure level.
- Drive routine reviews that rigorously test controls, evidence integrity, and policy adherence prior to major software releases, mitigating potential failures before deployment.
- Orchestrate ship documentation to ensure all compliance artifacts, including risk assessments and policy updates, move in tandem with product changes and release cycles.
- Act as a central coordinator, interfacing with vendors, external auditors, and internal legal teams to address shared risk topics and facilitate timely resolutions.
- Establish strict intake criteria for third-party risk, evaluating new integrations and responding to critical customer demands with data-driven assessments.
- Implement build safeguards that embed privacy and security rules directly into event configuration workflows, preventing deviations and enforcing governance automatically.
- Maintain dynamic review checklists that track control effectiveness, testing outcomes, and evolving regulatory changes to ensure ongoing relevance and compliance.
- Leverage Salesforce, Snowflake, ServiceNow, Jira, and Confluence to centralize risk data, automate reporting, and provide transparent oversight of compliance activities.
- Champion a culture of proactive risk management by coaching stakeholders on best practices and fostering a shared understanding of compliance obligations across the organization.
- Analyze audit findings and translate them into actionable remediation plans, prioritizing efforts based on risk impact and resource allocation.
- Collaborate with product and engineering teams to integrate compliance requirements into agile development cycles without compromising innovation or speed.
Requirements
Successful candidates must possess a minimum of three years of professional experience within governance, risk, and compliance or related disciplines. Demonstrated expertise with ISO 27001, SOC 2, and various privacy frameworks is required, with proven application in real-world operational settings. You must have a clear understanding of how to assess third-party risk and efficiently manage vendor questionnaires for critical service providers. Proficiency with specific operational tools is mandatory, including Salesforce, Snowflake, ServiceNow, Jira, and Confluence. You must be able to interpret complex regulatory requirements and convert them into practical policies and controls that are easily understood and implemented by cross-functional teams. The ideal candidate will demonstrate strong analytical skills, capable of identifying patterns in risk data and recommending strategic improvements to governance frameworks. You must possess excellent written and verbal communication skills to articulate technical compliance concepts to both technical and non-technical stakeholders effectively. A proven track record of working within fast-paced, dynamic environments is essential to navigate shifting priorities and deliver consistent results. You should exhibit a high level of ownership and initiative, taking responsibility for end-to-end processes and driving projects to completion with minimal supervision. The ability to manage multiple priorities simultaneously while maintaining attention to detail is critical to success in this role.
Nice to have
Experience supporting audits for global enterprises and within complex event technology environments is highly valued.
Practical notes
Please confirm all critical details on the official application page before proceeding. Ensure your submission reflects the most current information available.