Skip to main content

Senior GRC Analyst

Gusto
Hybrid - San Francisco, CA, 2-3 days/weekUpdated 2d ago
Base salary
$183k–$205k
Published base salary range
Location
Hybrid - San Francisco, CA, 2-3 days/week
Remote eligibility
Employment
Full-time
Senior
Role family
Security
Fintech
Apply on job-boards.greenhouse.io
Job actionsApply now
Job actionsApply now

About the job

About Gusto

Gusto is on a mission to grow the small business economy, handling payroll, health insurance, 401(k)s, and HR for over 500,000 small businesses nationwide. The company has teams in Denver, San Francisco, and New York.

About the Role

Gusto is seeking a Security, Governance, Risk & Compliance professional to join the team managing security governance, risk, and compliance initiatives. This role will guide the company from foundational GRC maturity to steady-state operations, leveraging AI to automate and improve practices and tools, ensuring ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC, and related frameworks.

Responsibilities

  • Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies, particularly supporting SOC 2 and future framework adoption.
  • Own and manage trust management platforms, including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve controls framework and evidence collection.
  • Collaborate with Legal, Enterprise Applications, and other counterparts to establish and maintain data governance policies (e.g., classification, retention, handling).
  • Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams.
  • Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
  • Lead interactions with external auditors and regulatory bodies during compliance assessments (e.g., SOC 2 Type 2) and oversee responses to client security assessments and due diligence requests.
  • Stay current on relevant compliance frameworks, laws, and regulations.
  • Partner cross-functionally to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights.

Qualifications

  • 8+ years of experience in governance, risk, and compliance within SaaS, ideally in HCM, payroll, or fintech sectors.
  • Bachelor’s degree in Business, Information Systems, or a related field.
  • Strong understanding of SaaS business models, with experience implementing controls and policies in fast-paced, product-driven environments.
  • Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams.
  • Familiarity with compliance tools and platforms such as Optro, Vanta, Drata, Viso Trust, or similar.
  • Demonstrated ability to translate complex GRC requirements into actionable, scalable processes.
  • Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders.
  • A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.
  • One or more relevant professional certifications: CISA, CRISC, or GRCP preferred; CGEIT, CRMA, or PMI-RMP are a bonus.

Compensation & Benefits

Cash compensation for this role is targeted at $183,000-205,000 in the San Francisco Bay Area. Stock equity is additional. All full-time employees receive competitive base pay, benefits, and equity (RSUs).

Work Location

This role is based in San Francisco, CA with a hybrid work schedule. Employees based in Denver, San Francisco, or New York City are expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.

Application Instructions

Apply through the provided Greenhouse link.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.