SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior GRC Analyst

Gusto - San Francisco, CA, USA - Hybrid - posted 2026-08-27

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 183,000 - 205,000 / annual

Gusto is seeking a Senior Governance, Risk & Compliance (GRC) professional to lead the company's security governance, risk, and compliance initiatives. You will guide Gusto from foundational GRC maturity through steady-state operations, leveraging AI to automate and improve compliance practices and tools. This cross-functional role ensures ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC, and related frameworks while embedding security-minded practices throughout the organization. Key responsibilities include developing and maintaining security and compliance standard operating procedures, internal documentation, and company-wide policies to support SOC 2 and future framework adoption. You will own and manage trust management platforms, documenting controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate control implementation and evidence collection. Collaboration with Legal, Enterprise Applications, and other departments will be essential to establish and maintain data governance policies covering classification, retention, and handling. You will conduct ongoing internal risk assessments to identify exposure and control gaps, coordinating remediation plans with functional teams. Managing the third-party vendor risk program—including onboarding reviews, monitoring, and renewal assessments—is a core responsibility. You will lead interactions with external auditors and regulatory bodies during compliance assessments and oversee responses to client security assessments and due diligence requests. The role requires staying current on relevant compliance frameworks, laws, and regulations to ensure appropriate coverage and adaptability. You will partner cross-functionally with Security, Legal, Engineering, Sales, and IT teams to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights. Required qualifications include 8+ years of GRC experience within SaaS, ideally in HCM, payroll, or fintech sectors, and a Bachelor's degree in Business, Information Systems, or a related field. You must have strong understanding of SaaS business models and proven experience leading or supporting SOC 2 Type 2 compliance initiatives. Familiarity with compliance tools such as Optro, Vanta, Drata, or Viso Trust is expected. Professional certifications (CISA, CRISC, or GRCP preferred) are valued.

Similar roles