SlipstreamJobsFresh Startup & VC-Backed Jobs

GRC Analyst II

Metropolis Technologies - Los Angeles, CA, United States - In-office - posted 2026-07-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 100,000 - 135,000 / annual

Metropolis Technologies is seeking a Governance, Risk, and Compliance (GRC) Analyst II to join the Security team, reporting to the Senior Manager of GRC. The role focuses on maturing information security policies, driving employee security awareness, and pioneering an AI governance framework across the organization. Key responsibilities include authoring, updating, and enforcing corporate security policies to ensure cross-departmental compliance. You will serve as the platform owner for information security training campaigns, transforming static policies into interactive modules with comprehension quizzes and mandatory sign-offs. A significant portion of the role involves establishing and enforcing an internal AI governance framework in partnership with Data, Legal, and Technology teams, conducting structured risk assessments on emerging tools and internal AI models to maintain behavioral guardrails. You will report training metrics, policy exceptions, and risk postures directly to senior management, and review vendor security profiles and software pipelines to mitigate security risk. The role requires partnering across Technology, Legal, Internal Audit, Procurement, and People Operations to safeguard customer trust and support operational excellence. Required qualifications include 3+ years of experience in information security GRC, cybersecurity training, or technology compliance. You should have a proven track record managing required security awareness programs and driving cross-functional accountability, with experience using modern training orchestration platforms. Knowledge of AI and machine learning data security, SOC 2, and PCI-DSS frameworks is essential. Strong communication skills are needed to explain complex regulatory requirements to non-technical employees. A Bachelor's degree in Cybersecurity, Information Systems, or equivalent technical discipline is required. GRC certifications such as CISA or CRISC are a plus. Metropolis operates on an office-first model requiring employees to be on-site at least four days per week to foster innovation and collaboration.

Similar roles