GRC Analyst

Vercel · Remote - United States · Security · listed July 2, 2026

The shape of it

Seniority
Mid level
Experience asked
3+ years
Where
Hybrid
Stated pay
$134,000 – $202,000
Requirements listed
3
Length
736 words

In the posting’s own words

We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements.

What it asks for · 3

  • At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
  • Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
  • Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.

Also a plus

  • Strong experience with cloud infrastructure (e.g., Azure, AWS)
  • Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.)
  • Experience with frontend development and open source components
  • Relevant industry certifications (i.e., CISM, CISSP, CCEP) is a plus, but not required

What the job covers

  • Collaborate with internal teams to maintain an effective suite of internal controls and driving remediation efforts to completion with clear documentation of progress.
  • Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
  • Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
  • Monitor and improve controls , processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting
  • Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
  • Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization.

Tools and skills named

Security & compliance
  • Audit3×
  • PCI3×
  • Security3×
  • HIPAA2×
  • Regulatory2×
  • SOC 22×
Cloud & infra
  • AWS
  • Azure
  • Datadog
Ways of working
  • Technical writing2×
  • Cross-functional
Operations & finance
  • Project management
  • Recruiting
Go to market
  • Go-to-market

Words the posting leans on

  • compliance8×
  • audit4×
  • controls4×
  • experience4×
  • grc4×
  • internal4×
  • collaborate3×
  • security3×
  • skills3×
  • accountability2×
  • business2×
  • clear2×
  • completion2×
  • development2×
  • documentation2×
  • e.g2×

Counted from the posting after the mission statement and the legal notices are set aside. The ones near the top are the ones a screener is looking for.

The posting, your resume, and the gaps between them. One click loads all three.

More open at Vercel

every open role at Vercel

How this page was made

An automated read of a public job posting, fetched August 24, 2026 and last changed by Vercel on August 18, 2026. Every list above is pulled from the posting’s own sentences — nothing rewritten, nothing added, no judgment about the role or the company. Counts and seniority are read off the text by rule, so they can be wrong where the posting is unusual. The original is the only thing that binds. Openings close without warning; check the source before spending an evening on it.