
Senior GRC Analyst, Security
3 days ago
Ethos was built to make it faster and easier to get life insurance for the next million families. Our approach blends industry expertise, technology, and the human touch to find you the right policy to protect your loved ones.
We leverage deep technology and data science to streamline the life insurance process, making it more accessible and convenient. Using predictive analytics, we are able to transform a traditionally multi-week process into a modern digital experience for our users that can take just minutes We've issued billions in coverage each month and eliminated the traditional barriers, ushering the industry into the modern age. Our full-stack technology platform is the backbone of family financial health.
We make getting life insurance easier, faster and better for everyone.
Our investors include General Catalyst, Sequoia Capital, Accel Partners, Google Ventures, SoftBank, and the investment vehicles of Jay-Z, Kevin Durant, Robert Downey Jr and others. This year, we were named on CB Insights' Global Insurtech 50 list and BuiltIn's Top 100 Midsize Companies in San Francisco. We are scaling quickly and looking for passionate people to protect the next million families
About the Role
The GRC Analyst is responsible for supporting the organization's information security governance, risk, and compliance activities. This role involves ensuring that the organization's security policies, procedures, and practices are aligned with regulatory requirements, industry standards, and best practices. The ideal candidate will have a strong understanding of information Security & Privacy principles, Third Party Vendor Risk management, ITGC & SOC2 audit controls, and the ability to communicate complex security issues to various stakeholders.
Duties and Responsibilities:
- Governance:
- Develop, implement, and maintain information security policies and procedures.
- Ensure alignment of security governance frameworks with business objectives and regulatory requirements.
- Assist in the creation and maintenance of the information security governance structure.
- Conduct information security risk assessments and evaluate the effectiveness of existing controls.
- Identify, assess, and document risks related to information security & privacy across the organization.
- Conduct regular risk assessments for existing and potential vendors.
- Monitor and report on the organization's information security risk posture.
- Ensure compliance with relevant information security regulations, standards, and frameworks (e.g., ISO 27001, SOC2, ITGC, NIST, PCI-DSS, CCPA, NYDFS, HIPAA).
- Conduct regular security compliance assessments and audits.
- Track and report on compliance gaps and work with relevant teams to address deficiencies.
- Stay current on emerging security regulations and industry best practices.
- Develop and deliver information security awareness and training programs to staff at all levels.
- Maintain comprehensive and accurate documentation related to information security governance, risk, and compliance.
- Prepare and present reports on the organization's information security activities, risk assessments, and compliance status to senior management.
- Ensure all documentation is up-to-date and in compliance with regulatory and organizational requirements.
Qualifications and Skills:
- Bachelor's degree in Information Security, Computer Science, Cybersecurity, or a related field.
- 3+ years of experience in information security, risk management and compliance.
- Strong knowledge of information security frameworks, standards, and regulations (e.g., ISO 27001, NIST, CCPA, PCI-DSS, NYDFS, HIPAA).
- Experience with security & privacy risk assessment and management methodologies.
- Extensive experience in Third Party/Vendor Risk Management (TPRM) with hands-on expertise in managing VRM tools (e.g.,OneTrust, ProcessUnity, Vanta).
- Experience in supporting security audits (SOC2, Customer & Partners Audits) - At least 2 complete audit cycles of SOC2.
- Excellent communication skills, with the ability to convey complex security concepts to non-technical stakeholders.
- Relevant certifications such as ISO 27001 LA LI, CISA, CRISC are highly desirable.
#LI-Hybrid
Don't meet every single requirement? If you're excited about this role but your past experience doesn't align perfectly with every qualification in the job description, we encourage you to apply anyway. At Ethos we are dedicated to building a diverse, inclusive and authentic workplace.
We are an equal opportunity employer who values diversity and inclusion and look for applicants who understand, embrace and thrive in a multicultural world. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Pursuant to the SF Fair Chance Ordinance, we will consider employment for qualified applicants with arrests and conviction records.
To learn more about what information we collect and how it may be used, please refer to our California Candidate Privacy Notice.
-
Senior Security GRC Analyst Bengaluru, Karnataka
2 weeks ago
Bengaluru, Karnataka, India Greenlight Financial Technology Full time US$ 90,000 - US$ 1,20,000 per yearGreenlight is the leading family fintech company on a mission to help parents raise financially smart kids. We proudly serve more than 6 million parents and kids with our award-winning banking app for families. With Greenlight, parents can automate allowance, manage chores, set flexible spend controls, and invest for their family's future. Kids and teens...
-
GRC Analyst
7 days ago
Bengaluru, Karnataka, India Digitap Full time ₹ 15,00,000 - ₹ 25,00,000 per yearJob description : We are seeking a motivated and skilled GRC professional to join our team. As a GRC Analyst, you will be responsible for managing cybersecurity risks, conducting compliance assessments, and implementing security policies based on industrys best practices, including ISO 27001/22301 and RBI/SEBI guidelines. This role offers an excellent...
-
GRC Analyst
2 weeks ago
Bengaluru, Karnataka, India Digitap Full time ₹ 6,00,000 - ₹ 18,00,000 per yearDIGITAP.AI provides high tech advanced AI / ML solutions to new age internet driven businesses for reliable, fast and 100% compliant Customer On boarding, Automated Risk Management along with Big Data enabled services like Risk Analytics and Customized Scorecards. For customers on boarding and risk management, extracts the data from various sources through...
-
GRC Security
2 weeks ago
Bengaluru, Karnataka, India Careernet Full time ₹ 15,00,000 - ₹ 25,00,000 per yearKey Skills: SAP Security, Governance, Risk, and Compliance (GRC), S/4HANA.Roles & Responsibilities:Lead the implementation and enhancement of GRC solutions within the organization.Provide support for SAP Security initiatives, ensuring compliance with industry standards.Collaborate with cross-functional teams to assess and mitigate risks associated with SAP...
-
GRC Analyst
2 weeks ago
Bengaluru, Karnataka, India Digitap Enterprise Solutions Full time ₹ 9,00,000 - ₹ 12,00,000 per yearDIGITAP.AIprovides high tech advanced AI / ML solutions to new age internet driven businesses for reliable, fast and 100% compliant Customer On boarding, Automated Risk Management along with Big Data enabled services like Risk Analytics and Customized Scorecards. For customers on boarding and risk management, extracts the data from various sources through...
-
GRC Analyst
1 day ago
Bengaluru, Karnataka, India DigiFortex Full time ₹ 9,00,000 - ₹ 12,00,000 per yearJob Description: Governance, Risk, and Compliance (GRC) ConsultantPosition:GRC Analyst/ Consultant (2-6 Years' Experience)Location:Bengaluru, Work from OfficeEmployment Type:Full-TimeAbout the RoleWe are seeking an experienced Governance, Risk, and Compliance (GRC) professional with proven expertise in implementing and managing compliance frameworks,...
-
SAP GRC and Security Consultant
7 days ago
Bengaluru, Karnataka, India Oscillix Full time ₹ 15,00,000 - ₹ 25,00,000 per yearResponsibilities:Senior SAP GRC AC & IAG Consultant. Configure GRC (ARA/ARM/EAM/BRM), IAG + Bridge, BTP IAS/IPS; design S/4HANA & Fiori security; set up SAML/OAuth; deliver projects & support with clients. Bangalore | Join in 1530 days.
-
SAP GRC/SECURITY Consultant
5 days ago
Bengaluru, Karnataka, India Talent Worx Full time ₹ 20,00,000 - ₹ 25,00,000 per yearSAP GRC (Governance, Risk, and Compliance)/ Security Consultant to join our team. In this role, you will be responsible for implementing and managing security protocols and compliance measures within our SAP environment to safeguard sensitive data and ensure adherence to regulations.As a Senior Consultant, you will lead projects focused on SAP GRC solutions,...
-
SAP Security and GRC Consultant
1 week ago
Bengaluru, Karnataka, India Acesoft Labs Full time ₹ 20,00,000 - ₹ 25,00,000 per yearJob Title: SAP Security and GRC Consultant.Project OverviewThis role is part of the Mozart GP6A/B Rollouts within the SAP security domain. The consultant will focus on SAP S/4HANA, GRC, and Cloud Security, working across implementation, security architecture, and ongoing operations support for SAP and integrated systems like VIM, BTP, and Power AppsRoles &...
-
GRC Analyst, Security
2 weeks ago
Bengaluru, Karnataka, India Ethos Life Full time ₹ 9,00,000 - ₹ 12,00,000 per yearAbout the role The trust and safety team is responsible for safeguarding Ethos information assets, managing technology compliance, and ensuring the trust, privacy, and safety of Ethos customers and employees. As a key member of the GRC team, within the overall trust and safety team, this is a great opportunity to shape the compliance, governance, and...