InterviewHack.ai
Start free
Jobs / RainFocus

Senior Governance Risk and Compliance Analyst

RainFocus · Orem, UTRemotesenior

In short

  • ▸Analista sénior de GRC que lidera programas de cumplimiento en SOC 2, ISO 27001 y PCI DSS.
  • ▸Dia a dia: evalúa riesgos, prepara auditorías, mejora políticas y controla riesgos de seguridad y privacidad.
  • ▸Destacado: tiene autonomía directa con el CISO y puede definir el crecimiento del programa, no solo mantenerlo.

Experiencia en entornos internacionales y capacidad para comunicarse en inglés es necesari

Apply on company site ↗Share on WhatsApp

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Free, no card.

What they ask for

  • ✓6+ años de experiencia en GRC, auditoría de TI o ciberseguridad.
  • ✓Conocimiento profundo de marcos como SOC 2, ISO 27001, PCI DSS, NIST SP 800-30.
  • ✓Experiencia comprobada en evaluaciones de riesgo y gestión de control framework.
  • ✓Habilidades analíticas y de comunicación para trabajar con equipos técnicos y no técnicos.
  • ✓Capacidad para gestionar múltiples proyectos bajo presión en entorno ágil.
  • ✓Certificaciones como CISA, CRISC, CISSP, CIPP o CIPM son altamente deseadas.

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

SOC 2ISO 27001PCI DSSNIST SP 800-30GDPRDrataOneTrustVantaDLPvulnerability management

Who should you write to at RainFocus?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst . About RainFocus RainFocus cares about its employees, customers, and the world in which we live. Our rapidly growing team serves Fortune 500 companies like Adobe, Cisco, IBM, Oracle, VMware, and others to prepare and execute in-person, virtual, and hybrid events across the world. Those events are delivered through our industry-disrupting software platform, with groundbreaking business intelligence, to elevate the attendee experience, streamline event operations, and accelerate marketing results. We are well-funded, growing fast, and building a company that is changing the market — it will be challenging, fun, and exciting. About the Role We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting audits, and driving the program's maturity forward rather than simply maintaining the status quo. You will report directly to the CISO and have significant ownership from day one. Responsibilities: Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory compliance frameworks, including audit prep, evidence collection, and auditor relationships. Manage and mature our control framework, mapping new regulations and conducting gap assessments. Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder interviews, risk scoring, and residual risk tracking. Maintain and update security policies, standards, and documentation to ensure compliance with industry best practices. Partner with Engineering and Security to mature vulnerability management and secrets-scanning practices, moving these from reactive to proactive, pre-deployment controls. Help build out and operationalize a Data Loss Prevention (DLP) program, including policy design and rollout across email, endpoint, and cloud storage. Grow and mature RainFocus's security awareness training program. Drive AI governance efforts — policy, tooling, and monitoring for approved vs. unapproved AI tool usage across the company. Identify and help close Shadow IT / unmanaged SaaS visibility gaps in partnership with IT. Collaborate with cross-functional teams to implement risk management practices and ensure compliance across the organization. Respond to security and privacy inquiries from clients, partners, and employees. Prepare and present reports on the organization's security and privacy compliance status, including program maturity and remediation progress. Stay abreast of emerging security threats, vulnerabilities, and compliance requirements. Qualifications: Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable. 6+ years of proven experience in GRC, IT audit, information security compliance, or a related field. , SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and others). Experience running or contributing heavily to formal risk assessments — not just tracking a compliance checklist. Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are highly desirable. Familiarity with modern security tooling such as Drata, OneTrust, Vanta, etc. Strong analytical and problem-solving skills, with keen attention to detail. Excellent communication and interpersonal skills to work effectively with technical and non-technical stakeholders. Ability to manage multiple projects and meet deadlines in a fast-paced environment. Experience with cloud security and compliance frameworks is a plus. Experience with OneTrust or related GRC technologies is a plus. Personal Characteristics: Strong work ethic and commitment to excellence.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsFree ATS checkerInterview-English checkSalary checkLATAM salary reportFree coursesBlogTailored CVReal coachPricing

Remote jobs

ReactPythonFull-StackLATAMMexicoSee all →

Prepare

Practice with a coachFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything.