At Drata, members of the GRC team have a rare opportunity to be Customer Zero—we actively use the same GRC platform that our customers rely on. This means your work as a Senior GRC Analyst will contribute directly to both the strength of Drata’s internal GRC program and the continuous evolution of our product. You'll provide hands-on feedback to our product and engineering teams based on real-world use, helping to refine user experience and functionality for thousands of customers. This isn’t just a GRC role – it’s a chance to help shape a category-defining solution while strengthening trust and security from the inside out.
Drata’s Senior GRC Analyst will support the execution of governance, risk, compliance, and trust-related initiatives to help ensure Drata remains aligned with key security frameworks, laws, and industry best practices. In this role, you’ll assist with internal control testing, evidence collection, audit readiness, and documentation across compliance programs such as SOC 1/2/3, ISO 27001/17/18, ISO 42001, HIPAA, and FedRAMP, among others. You’ll work closely with internal stakeholders and external assessors to support continuous improvement of controls and risk mitigation efforts. A strong understanding of security compliance programs and familiarity with frameworks such as GDPR, data privacy laws, and data security regulations is essential.
What you'll do:
By weaving together automation, innovation, and clear communication, you’ll play a pivotal role in shaping Drata’s future and redefining what it means to be secure and compliant in a modern, fast-paced world. Let’s revolutionize the industry—together!
What you’ll you bring:
Benefits:
This role will receive a competitive base salary, benefits, and stock, typically in the form of Restricted Stock Units (RSUs). The applicable salary range for each US-based role is based on where the employee works and is aligned to one of 3 tiers based on the cost of labor for that geographic area. The expected salary ranges for this role are below, subject to change.
Tier 1: $136,595- $168,700
Tier 2: $122,900 - $151,800
Tier 3: $109,300 - $135,000
You can view which tier applies to where you plan to work here. A variety of factors are considered when determining someone’s leveling and compensation–including a candidate’s professional background and experience. These ranges may be modified in the future and final offer amounts may vary from the amounts listed above.
Drata is on a mission to serve as the trust layer between great companies.
Drata is a trust management platform that uses AI-driven automation to modernize governance, risk, and compliance, helping thousands of businesses develop a more secure, proactive, and risk-aware organization to continuously maintain trust with customers.
We all recognize the importance of earning and keeping the trust of our customers when it comes to protecting their data. We know how burdensome achieving and maintaining a strong GRC posture can be with the rise in compliance regulations. It’s a manual, redundant, error-prone, and unscalable process - and it only grows more complex and expensive over time.
Our team of SaaS, security, compliance, and audit experts have built a better way - with automation
Employment at Drata is based solely upon individual merit and qualifications directly related to professional competence. We strictly prohibit unlawful discrimination or harassment on the basis of race, color, religion, veteran status, national origin, ancestry, pregnancy status, sex, gender identity or expression, age, marital status, mental or physical disability, medical condition, sexual orientation, or any other characteristics protected by law. We also make reasonable accommodations to meet our obligations under laws protecting the rights of the disabled.
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Drive impactful partner marketing campaigns and manage MDF programs remotely for Drata, a leader in trust management automation.
Support Wiz’s global employment legal team as an Employment / Litigation Paralegal in a fast-growing cloud security startup.
Join American Express as a Director of Compliance Issues Management to enhance governance and drive compliance initiatives in a dynamic environment.
Lead and manage the Agreements Team in the Innovations and Partnerships Office at LLNL, overseeing complex partnership agreements and intellectual property licensing to support national security innovations.
Corporate Counsel needed at Planful to provide expert legal support in employment law, litigation management, and commercial contracts.
Lead compliance efforts and drive fair lending initiatives at American Express as a Fair Lending Manager.
Serve as Associate General Counsel at Anduril Industries, leveraging your expertise in government contracts to drive strategic growth and legal compliance within the Maritime Division.
Experienced Tax Counsel needed at Chevron to deliver comprehensive tax planning support for its upstream, midstream, and downstream operations.
Provide expert legal support on commercial transactions and marketing agreements at a renowned global retail company.
Presbyterian Healthcare Services needs a Compliance Specialist to oversee compliance education, policies, and vendor credentialing to maintain regulatory adherence and promote continuous improvement.
Analyze and mitigate complex financial crime risks as a Compliance Analyst with American Express’ dedicated Global Financial Crimes Compliance team.
Lead the Internal IT Audit function at Real, focusing on SOX compliance, cybersecurity, and IT governance in a fully remote capacity.
Lead Synchrony's Community Reinvestment Act strategy and community engagement efforts in a senior leadership role driving CRA program success.
Deutsche Bank is looking for a Transaction Monitoring Investigator – Fraud SAR (Assistant Vice President) to join their Anti Financial Crime team, focusing on AML investigations and compliance.
Drata is a security and compliance automation platform that continuously monitors and collects evidence of a company's security controls, while streamlining compliance workflows end-to-end to ensure audit readiness.
21 jobsSubscribe to Rise newsletter