Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal Governance Risk & Compliance Analyst image - Rise Careers
Job details

Principal Governance Risk & Compliance Analyst

Who We Are

Red Canary was founded to create a world where every organization can make its greatest impact without fear of cyber threats. We’re a cyber security company who protects, supports and empowers organizations to make better security decisions so they can focus on their mission without fear of cyber threats.


The combination of our market-defining technology and expertise prevents breaches every day and sets a new standard for partnership in the industry. We’re united in our commitment to customers and grounded in our values, which earned us a place on the Forbes Best Start-up Employers 2022 list.  If our mission resonates with you, let’s talk.


What We Believe In

- Do what’s right for the customer

- Be kind and authentic

- Deliver great quality

- Be relentless


Challenges You Will Solve

At Red Canary, the protection of our customers and employees is of the utmost importance. Red Canary’s Governance, Risk & Compliance (GRC) team provides oversight to ensure that our people, platforms, and data remain secure in compliance with our policies and applicable laws. 


As a Principal GRC Analyst, you will help ensure that our controls, policies, and procedures are  designed, implemented, and tested to deliver the best possible outcomes for Red Canary and our customers. Reporting to the General Counsel, the Principal GRC Analyst is responsible for activities and improvements across the entire scope of Red Canary’s GRC programs.


What You'll Do
  • Lead governance, risk, and compliance initiatives.
  • Lead regular reviews to ensure that policies and controls are effective, while aligning them to company values and all applicable compliance requirements; identify potential improvements and manage their implementation.
  • Identify, design, and lead projects to automate the collection and presentation of auditing data for internal and external consumption.
  • Lead internal audits and risk assessments of the Red Canary environment; identify potential improvements and manage their implementation.
  • Schedule, prepare for, and lead annual external audits against SOC 2 Type II, ISO 27001, ISO 27701, and other standards.
  • Maintain security and compliance certifications; identify and manage new certification initiatives.
  • Lead the vendor risk management function for evaluating Red Canary’s vendors and partners to identify potential risks; identify potential improvements and manage their implementation.
  • Lead the response to questions and questionnaires from customers, potential customers, and partners regarding security and compliance; identify potential improvements and manage their implementation.
  • Support the sales team in vetting security and compliance terms in customer contracts.
  • Help oversee security awareness training that is both relevant and instructive.
  • Lead relevant and engaging business continuity and incident response exercises. 


What You'll Bring
  • 5+ years of experience with SOC 2 Type II and ISO 27001 audits.  Experience with audits under ISO 27701, FedRAMP, and CMMC experience is a plus.
  • 5+ years of managing or performing security questionnaires and vendor assessments.
  • Experience addressing security and compliance terms in commercial contracts.
  • The ability to articulate and shift between various compliance and regulatory frameworks.  
  • An understanding of the unique risks presented by cloud-native architecture and compliance and audit strategies for environments heavily reliant on SaaS.
  • Strong experience interacting with auditors and gaining their confidence as a source of truth.
  • Expertise in designing and managing strategies to identify, articulate, and mitigate risks.
  • Experience in designing and implementing automation to the collection and presentation of audit data.
  • Outstanding written and verbal communication skills.
  • A practical mindset that can balance compliance and business needs.
  • The ability to lead multiple projects simultaneously.  
  • A patient and positive attitude.


Targeted base salary range: $130,000 - $150,000 + bonus eligibility and equity depending on experience.


The application deadline is December 13th, 2024.


Why Red Canary?

Red Canary is where people embody our mission to improve security outcomes for all. People work hard to maintain a culture that encourages authenticity in order to do your best work. Our people are driven and committed to finding the best security outcomes, delivering real and actionable answers, and being transparent along the way. 


At Red Canary, we offer a very rich benefits program to our full-time team members so they can focus on their families and improving our customers’ security. For a full list of benefits, please review our Benefits Summary:

https://resource.redcanary.com/rs/003-YRU-314/images/RedCanary_2024BenefitsSummary.pdf?version=0


Individuals seeking employment at Red Canary are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Red Canary Glassdoor Company Review
3.7 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Red Canary DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Red Canary
Red Canary CEO photo
Brian Beyer
Approve of CEO

Average salary estimate

$140000 / YEARLY (est.)
min
max
$130000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal Governance Risk & Compliance Analyst, Red Canary

Are you ready to take your career to new heights as a Principal Governance Risk & Compliance Analyst at Red Canary? At Red Canary, a leading cyber security company that protects and empowers organizations, we’re on a mission to help our clients navigate the complex world of cyber threats with confidence. As a key member of our Governance, Risk & Compliance (GRC) team, you will be instrumental in enforcing the highest standards of security and compliance across our organization. Your role will involve leading vital initiatives that ensure our policies and controls are effective and aligned with our core values. You'll drive regular reviews, lead internal audits, and manage projects to streamline and automate our auditing processes. Working closely with our General Counsel, you will oversee the entire scope of Red Canary's GRC programs and ensure we meet and maintain critical certifications like SOC 2 Type II and ISO 27001. Your extensive experience with security questionnaires and vendor assessments will be invaluable as you support our sales team and handle customer inquiries. At Red Canary, we believe in the power of kindness, authenticity, and delivering great quality. If you're excited about helping to safeguard our customers while enjoying a culture that values transparency and collaboration, we’d love to hear from you!

Frequently Asked Questions (FAQs) for Principal Governance Risk & Compliance Analyst Role at Red Canary
What responsibilities does a Principal Governance Risk & Compliance Analyst have at Red Canary?

As a Principal Governance Risk & Compliance Analyst at Red Canary, you will lead governance, risk, and compliance initiatives, conduct internal audits, and implement improvements across our GRC programs. Your role is vital to ensuring compliance with policies and applicable laws while managing vendor risks and streamlining auditing processes.

Join Rise to see the full answer
What qualifications do I need to apply for the Principal Governance Risk & Compliance Analyst position at Red Canary?

To qualify for the Principal Governance Risk & Compliance Analyst role at Red Canary, you should have over 5 years of experience with SOC 2 Type II and ISO 27001 audits, as well as experience with vendor assessments. Strong communication skills and a deep understanding of compliance frameworks are essential.

Join Rise to see the full answer
What is the work environment like for a Principal Governance Risk & Compliance Analyst at Red Canary?

The work environment for a Principal Governance Risk & Compliance Analyst at Red Canary is remote, supportive, and collaborative. We emphasize a culture of kindness and authenticity, where you can thrive while contributing to our mission of enhancing security outcomes.

Join Rise to see the full answer
How does Red Canary support its employees in the Principal Governance Risk & Compliance Analyst role?

Red Canary supports its employees by providing a rich benefits program that includes equity and bonus eligibility, ensuring a work-life balance. Our culture fosters authenticity, collaboration, and continuous learning, helping you grow within your role.

Join Rise to see the full answer
What are the opportunities for growth as a Principal Governance Risk & Compliance Analyst at Red Canary?

As a Principal Governance Risk & Compliance Analyst at Red Canary, you will have opportunities to lead significant projects and initiatives that shape our GRC programs. Your expertise will be valued as you help evolve our compliance strategies and enhance security outcomes.

Join Rise to see the full answer
What types of projects will a Principal Governance Risk & Compliance Analyst lead at Red Canary?

You will lead various projects such as automating audit data collection, managing vendor risk assessments, and overseeing security awareness training programs. Each project will contribute significantly to the security posture of Red Canary and its customers.

Join Rise to see the full answer
What skills are essential for success as a Principal Governance Risk & Compliance Analyst at Red Canary?

Essential skills for success in this role include expertise in compliance frameworks, strong analytical abilities, and outstanding verbal and written communication skills. A practical mindset that balances compliance with business needs is also crucial.

Join Rise to see the full answer
Common Interview Questions for Principal Governance Risk & Compliance Analyst
How do you ensure compliance with various regulatory frameworks in your previous experience?

To ensure compliance with regulatory frameworks, I have implemented a systematic approach that includes regular audits, updating policies to reflect changes in regulations, and conducting training sessions to maintain awareness among staff. I also emphasize open communication with different departments to align compliance efforts with organizational goals.

Join Rise to see the full answer
Can you describe your experience with leading internal audits?

In my previous role, I led multiple internal audits by first developing a comprehensive audit plan. This involved collaborating with teams to identify key risks, conducting detailed assessments, and providing actionable recommendations to improve compliance and security controls. Keeping stakeholders informed throughout the process was paramount for successful audits.

Join Rise to see the full answer
What strategies do you use to manage vendor risk?

I utilize a multi-faceted approach to manage vendor risk, which includes conducting thorough assessments, scrutinizing vendor security policies, and implementing continuous monitoring for compliance. It's also important to establish clear communication and strong relationships with vendors to ensure alignment on compliance expectations.

Join Rise to see the full answer
How have you improved compliance processes in past positions?

I have improved compliance processes by introducing automation tools that streamline data collection and reporting. Additionally, I have conducted training sessions and workshops to educate staff on best practices, which has led to heightened awareness and adherence to compliance requirements across the organization.

Join Rise to see the full answer
What role does communication play in your work as a Principal GRC Analyst?

Communication plays a vital role in my work as a Principal GRC Analyst. It involves collaborating with various teams, explaining complex compliance requirements in understandable terms, and fostering a culture of accountability. Maintaining transparency ensures that compliance initiatives are understood and supported across the organization.

Join Rise to see the full answer
How do you stay current with changes in compliance regulations?

To stay current with compliance regulations, I subscribe to industry newsletters, attend relevant webinars and workshops, and engage with compliance networks. Continuous education is crucial in adapting to new regulations and implementing best practices effectively.

Join Rise to see the full answer
Describe a challenging audit experience and how you handled it.

In a challenging audit, discrepancies were found in our reporting processes. I swiftly organized a cross-functional team meeting to address the issues, gathered necessary data, and implemented corrective measures. Open communication with auditors and internal stakeholders helped resolve concerns and led to a successful outcome.

Join Rise to see the full answer
What experience do you have with security awareness training?

I have designed and implemented security awareness training programs that focus on practical scenarios and relatable content to engage employees. This approach not only educates them about compliance but also empowers them to recognize and respond to potential security threats effectively.

Join Rise to see the full answer
How would you prioritize your tasks as a Principal Governance Risk & Compliance Analyst?

I prioritize tasks based on urgency, impact, and alignment with organizational goals. I use project management tools to monitor deadlines and ensure that critical compliance initiatives receive timely attention while also balancing routine tasks and audits.

Join Rise to see the full answer
Why do you want to work at Red Canary as a Principal GRC Analyst?

I am drawn to Red Canary's commitment to customer security and its values of kindness and authenticity. Being a part of a team that truly prioritizes protective measures and fosters a positive work culture aligns perfectly with my professional and personal values.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 4 days ago
Jobot Hybrid Bryn Athyn, PA
Posted 4 days ago
Photo of the Rise User
Agent Remote No location specified
Posted yesterday
Photo of the Rise User
CyberCoders Hybrid Baltimore, MD
Posted 3 days ago
Photo of the Rise User
Visa Remote Almaty, Kazakhstan
Posted 13 days ago
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Posted 9 days ago

Red Canary was founded to make security for every business better by protecting organizations around the world from cyber threats. Our combination of market-defining technology, processes, and expertise delivered using an innovative SaaS model is ...

32 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
November 24, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!