Serve Robotics Logo

Serve Robotics

Senior GRC Analyst

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in USA
120K-140K Annually
Senior level
Remote
Hiring Remotely in USA
120K-140K Annually
Senior level
The Senior GRC Analyst will enhance security best practices, conduct risk assessments, manage compliance documentation, and report on internal control compliance.
The summary above was generated by AI

At Serve Robotics, we’re reimagining how things move in cities. Our personable sidewalk robot is our vision for the future. It’s designed to take deliveries away from congested streets, make deliveries available to more people, and benefit local businesses.

The Serve fleet has been delighting merchants, customers, and pedestrians along the way in Los Angeles, Miami, Dallas, Atlanta and Chicago while doing commercial deliveries. We’re looking for talented individuals who will grow robotic deliveries from surprising novelty to efficient ubiquity.

Who We Are

We are tech industry veterans in software, hardware, and design who are pooling our skills to build the future we want to live in. We are solving real-world problems leveraging robotics, machine learning and computer vision, among other disciplines, with a mindful eye towards the end-to-end user experience. Our team is agile, diverse, and driven. We believe that the best way to solve complicated dynamic problems is collaboratively and respectfully.

As a Senior Governance, Risk, and Compliance (GRC) Analyst you will partner with Serve business and technology stakeholders to facilitate and align on security best practices. As a high-level subject matter expert in governance and risk, this position will apply technical knowledge and to assess and mitigate risks related to Serve’s financial and IT systems and business processes.

Responsibilities

  • Serve as a subject matter expert on security best practices, compliance frameworks and standards such as SOX Section 404 IT General Controls, ISO 27001, GDPR, CCPA.

  • Maintain security documentation including, but not limited to: information security policies and procedures, risk assessment methodology and treatment plans, privacy and business impact assessments (BIA/PIA), and compliance audit procedures.

  • Manage Serve’s security awareness program platform and quarterly phishing simulation campaigns and reporting.

  • Conduct periodic risk assessments of third-party vendor services and establish corrective action plans for risk mitigation.

  • Support periodic IT audits for Serve critical business systems to ensure compliance with IT General control (ITGC) requirements.

  • Track and manage audit findings and remediation activities to ensure timely resolution.

  • Manage Serve’s compliance framework, risk and control matrix and compliance automation system of record.

  • Prepare weekly reports for senior leadership on the compliance status of internal controls.

Qualifications

  • Knowledge in ISO 27001/2 and SOC 2 trust principles.

  • Knowledge in Information Security best practices.

  • The following certifications are desired but not required: ISO/IEC 27001 Lead Implementer/Auditor, CISA, CISSP.

  • Experience with participating in compliance audits in a lead or supporting role.

  • Experience in preparing compliance audit workpapers such as artifact request lists, standard test cases and test plans.

  • Experience with managing and supporting an Enterprise Risk Management (ERM) Lifecycle.

  • Familiarity with the use of Standard Information Gathering (SIG) for Third-Party Vendor Risk Assessments.

  • Experience using Atlassian Jira for team workload assignment and prioritization through Scrum or Kanban project management.

  • Experience configuring, managing and providing support for GRC or IRM tools such as Archer, ZenGRC or RSAM, Vanta.

  • Experience with developing compliance and security analytics/insights through Looker, PowerBI, Chartio or similar BI/analytics tooling.

  • Ability to work effectively while prioritizing and juggling competing priorities in a fast-paced work environment.

Top Skills

Archer
Atlassian Jira
Ccpa
Chartio
Gdpr
Iso 27001
Looker
Power BI
Rsam
Sox
Vanta
Zengrc

Similar Jobs

3 Days Ago
Easy Apply
Remote
USA
Easy Apply
120K-160K Annually
Senior level
120K-160K Annually
Senior level
Enterprise Web • Information Technology • Mobile
The Senior GRC Analyst will manage the security and compliance program, maintain SOC 2 certification, coordinate penetration tests, and ensure compliance initiatives support business goals.
Top Skills: Grc ToolingIal2/Ial3Nist 800-63Soc 2
23 Days Ago
Remote
United States
135K-190K Annually
Senior level
135K-190K Annually
Senior level
Fintech • Real Estate • Software
Lead and scale the company GRC program: maintain compliance certifications (SOC2, ISO 27001), run audits, manage policies, training, phishing, risk registers, and third-party risk assessments while supporting customer trust and cross-functional stakeholders.
Top Skills: Grc FrameworksIso 27001Soc2
5 Days Ago
Easy Apply
Remote
USA
Easy Apply
Senior level
Senior level
Internet of Things
Lead the development of a Governance, Risk, and Compliance framework, ensuring regulatory compliance and risk management across Mozilla's products and enterprise sectors.
Top Skills: Bi ToolsCcpaGdprIsoNistSeimSoc2

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account