SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior GRC Analyst - Central or Eastern time, US or Canada

Shift Technology - Boston, MA, United States - Hybrid - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 120,000 - 150,000 / annual

Shift Technology is an AI-driven insurance platform that delivers AI agents transforming critical insurance workflows. As a Senior GRC Analyst, you will be a cornerstone of Shift's security program, responsible for developing, maintaining, and assessing the integrated security and privacy management framework. You will report to the GRC Lead within the Information Security department. Key responsibilities include: Governance & Policy Management: Act as a lead contact translating Shift's global information security expectations into actionable policies, standards, and procedures. Promote security and compliance mindset across the organization as a subject matter expert. Contribute to security awareness program development and partner with the Data Protection Officer on privacy policies, data handling standards, and public-facing privacy notices aligned with GDPR and global regulations. Risk Management & Security Assurance: Develop and maintain the security assurance plan ensuring key controls meet Shift policies and standards. Improve third-party information security assurance and continuous assessment processes. Identify key risk areas with engineering and business teams, facilitate security control evaluations and testing, review architectural designs for security alignment, and support Data Protection Impact Assessments (DPIAs) for new products. Compliance & Audits: Manage and coordinate internal and external audits for certifications such as ISO 27001 and SOC 2 Type II. Perform analysis and compile documentation demonstrating compliance levels. Work with internal teams on audit finding remediation and support legal teams in responding to Data Subject Access Requests (DSARs). Third-Party Risk Management: Develop, execute, and improve third-party information security assurance processes. Communicate with third parties and suppliers to conduct risk assessments, review security posture, and manage remediation of identified issues. Requirements: - 7+ years of proven experience in GRC, IT Audit, Security Assurance, or Information Security roles - Bachelor's Degree in a relevant field or equivalent work experience - Professional certifications highly desirable: CIPP/E, CIPP/US, CIPT, CISA, CISM, CRISC, or CISSP - Direct experience in highly regulated industries (financial services, healthcare) - Direct experience managing or supporting formal audit and certification processes from start to finish - Deep knowledge of security and privacy frameworks: ISO 27001, ISO 27701, SOC 2 Type II, HITRUST, NIST CSF - Strong knowledge of global privacy and healthcare regulations: GDPR, HIPAA - Working knowledge of AI regulations and frameworks: EU AI Act, ISO 42001 - Working knowledge of business continuity, disaster recovery, and incident response planning - Hands-on experience with modern GRC management tools, preferably Drata (connecting integrations, tuning automated evidence collection, building custom controls) - Exceptional communication and presentation skills - Strong stakeholder management and influence without direct authority - Highly organized with strong project management capabilities - Analytical mindset balancing regulatory requirements with business objectives

Similar roles