← WORK 목록으로
GLOBALRemoteOK기타REMOTE

RainFocus - Senior Governance Risk and Compliance Analyst

이 공고는 개발 프로젝트가 아니라 이벤트 관리 SaaS 기업 RainFocus의 정규직 '시니어 GRC(거버넌스·리스크·컴플라이언스) 분석가' 채용 공고입니다. SOC 2, ISO 27001, PCI DSS, NIST 800 시리즈 등 보안 규정 준수 프로그램 운영, 리스크 평가, 감사 대응, DLP·AI 거버넌스 구축을 담당합니다. 소프트웨어 개발자가 아니라 정보보안 컴플라이언스·감사 경력 6년 이상의 보안 GRC 전문가에게 적합합니다.

2026.09.27VIEW 26RemoteOK에서 수집
Budget협의
Difficulty전문가
Duration정규직 (기간 없음)
Work style원격 가능
Required stack

필요 기술

SOC 2ISO 27001PCI DSSNIST 800-30GDPRDLPCloud Security
Project brief

프로젝트 내용

RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst. 

 

About RainFocus

 

RainFocus cares about its employees, customers, and the world in which we live. Our rapidly growing team serves Fortune 500 companies like Adobe, Cisco, IBM, Oracle, VMware, and others to prepare and execute in-person, virtual, and hybrid events across the world. Those events are delivered through our industry-disrupting software platform, with groundbreaking business intelligence, to elevate the attendee experience, streamline event operations, and accelerate marketing results. We are well-funded, growing fast, and building a company that is changing the market — it will be challenging, fun, and exciting.

About the Role

We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting audits, and driving the program's maturity forward rather than simply maintaining the status quo. You will report directly to the CISO and have significant ownership from day one.

\n

Key Responsibilities:Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory compliance frameworks, including audit prep, evidence collection, and auditor relationships.

 

Manage and mature our control framework, mapping new regulations and conducting gap assessments.

 

Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder interviews, risk scoring, and residual risk tracking.

 

Maintain and update security policies, standards, and documentation to ensure compliance with industry best practices.

 

Partner with Engineering and Security to mature vulnerability management and secrets-scanning practices, moving these from reactive to proactive, pre-deployment controls.

 

Help build out and operationalize a Data Loss Prevention (DLP) program, including policy design and rollout across email, endpoint, and cloud storage.

 

Grow and mature RainFocus's security awareness training program.

 

Drive AI governance efforts — policy, tooling, and monitoring for approved vs. unapproved AI tool usage across the company.

 

Identify and help close Shadow IT / unmanaged SaaS visibility gaps in partnership with IT.

 

Collaborate with cross-functional teams to implement risk management practices and ensure compliance across the organization.

 

Respond to security and privacy inquiries from clients, partners, and employees.

 

Prepare and present reports on the organization's security and privacy compliance status, including program maturity and remediation progress.

Stay abreast of emerging security threats, vulnerabilities, and compliance requirements.

Qualifications:Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.

6+ years of proven experience in GRC, IT audit, information security compliance, or a related field.

In-depth knowledge of relevant regulations, standards, and frameworks (e.g., SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and others).

Experience running or contributing heavily to formal risk assessments — not just tracking a compliance checklist.

Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are highly desirable.

Familiarity with modern security tooling such as Drata, OneTrust, Vanta, etc.

Strong analytical and problem-solving skills, with keen attention to detail.

Excellent communication and interpersonal skills to work effectively with technical and non-technical stakeholders.

Ability to manage multiple projects and meet deadlines in a fast-paced environment.

Experience with cloud security and compliance frameworks is a plus.

Experience with OneTrust or related GRC technologies is a plus.

Personal Characteristics:Strong work ethic and commitment to excellence.

Ability to work independently and as part of a team.

Excellent problem-solving and analytical skills.

Strong communication and interpersonal skills.

Ability to adapt to change and learn quickly.

Passion for security and privacy.

\nWhy work at RainFocus?

 

At RainFocus we delight millions of attendees at large-scale events by delivering better insights, experiences, and marketing. We were able to pivot our product and services offering in 2020 to continue growing and serving new clients and events.

 

As a member of the RainFocus team, you will have the opportunity to experience first-hand the impact of our platform at events around the world. Additionally, RainFocus offers competitive salaries, competitive benefits, 401k, generous PTO, and countless other team building activities. 

 

What are you waiting for? Apply today! We need more talented, hard-working, fun-loving team members just like yourself!

Please mention the word **INSIGHTFULLY** and tag RMTUuMTY1LjI0MC4xNDk= when applying to show you read the job post completely (#RMTUuMTY1LjI0MC4xNDk=). This is a beta feature to avoid spam applicants. Companies can search these words to find applicants that read this and see they're human.
지원 기회 분석

지원 전에 볼 것

핵심 요구사항

  • GRC·IT 감사·정보보안 컴플라이언스 6년 이상 경력
  • SOC 2·ISO 27001·PCI DSS·NIST·GDPR 등 프레임워크 숙지
  • NIST 800-30 기반 정식 리스크 평가 수행 경험
  • DLP·AI 거버넌스·섀도우 IT 관리 프로그램 구축
  • CISA·CRISC·CISSP·CIPP·CIPM 등 자격증 우대

예상 산출물

  • 보안 정책·표준·문서 유지관리
  • 연간 보안 리스크 평가 보고서
  • 컴플라이언스·프로그램 성숙도 보고서

매력 포인트

  • CISO 직속 및 초기부터 큰 오너십
  • 성장 중인 안정적 기업(포춘500 고객)
  • 완전 원격 근무

확인할 점

  • 개발 외주가 아닌 정규직 보안 컴플라이언스 채용 공고
  • 예산·기간 정보 없음
  • IT 개발자 대상 프리랜서 프로젝트와 무관
Client signal

클라이언트 정보

회사 · RainFocus / 지역 · Orem, UT
START THE LOOP · CHOOSE

시장과 사람의 답을 봤다면,
다음 결과물의 구조를 고릅니다.

한 번의 결과에 기대지 않고 다시 만들 수 있도록, 문제 발견부터 제작·배포·수익화까지 이어지는 전체 흐름을 익혀보세요.

TTJ CLASS에서 다음 구조 고르기 →
처리 중...