Vercel Logo

Vercel

Staff GRC Analyst

Posted 7 Days Ago
Remote
Hiring Remotely in United States
180K-270K Annually
Senior level
Remote
Hiring Remotely in United States
180K-270K Annually
Senior level
The Staff GRC Analyst will lead audits, manage compliance programs, enhance risk management processes, and collaborate with teams to ensure adherence to security requirements.
The summary above was generated by AI
About Vercel:

Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web.

Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.

About the role:

We are looking for a Staff GRC Analyst to join our Governance, Risk, and Compliance (GRC) team. You will have the opportunity to enhance our global compliance posture and further our commitment to managing enterprise risk. Your role will be instrumental in ensuring that our company operates in accordance with security requirements and embodies an environment where it’s everyone’s responsibility. This role will help shape the next iteration of the GRC program and further embed compliance requirements into the business.

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

Getting started:
  • We want you to feel like part of the team early on! Our team will help integrate you into the company with explanations on our product, policies, processes, team structure and roadmap.
  • We’re excited for you to learn, grow, and contribute right away! We trust that you’ll bring experience and knowledge that will uplift and up-level the team, but we don’t expect you to know everything on Day 1.
What you will do:
  • Own and scale commercial attestation program and audits (i.e., SOC 2, ISO 27001, PCI DSS, etc.) while maintaining alignment with business objectives and market demand.
  • Design and strengthen continuous monitoring processes to improve control effectiveness and mature control implementation from audit-ready to always-ready.
  • Drive evolution of security and compliance control frameworks that set the direction for proactive risk management.
  • Partner with cross-functional stakeholders, acting as a strategic connector ****to plan, implement, maintain & remediate control activities and supporting requirements (e.g. policies, standards, processes, system configurations, etc.)
  • Champion a culture of compliance accountability and business-enablement across the organization through autonomous program governance and reporting and building trusted relationships.
About you:
  • Experience managing and running audits, certification programs and enterprise control assessments, including scope planning, defining requirements, policy and standards development, and control testing
  • Deep knowledge of audit processes, evidence requirements, and remediation lifecycle management for security and compliance frameworks (i.e., SOC 2, ISO 27001, PCI DSS)
  • Proven experience owning large-scale GRC programs, collaborating with technical and non-technical teams and driving initiatives to completion
Bonus if you:
  • Familiarity with data governance, compliance or software development tools and systems (e.g., Drata, Linear, Github, etc.)
  • Experience supporting cloud, AI-native, and open source development environments and systems
  • Experience with FedRAMP or NIST frameworks, such as 800-53, AI RMF
  • Security certifications (e.g. CISA, CISSP)
Benefits:
  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $180,000.00 - $270,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process. 

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.


Top Skills

Drata
Git
Iso 27001
Linear
Pci Dss
Soc 2

Similar Jobs at Vercel

12 Hours Ago
Remote
United States
196K-294K Annually
Senior level
196K-294K Annually
Senior level
Artificial Intelligence • Cloud • Software
The Senior Product Security Engineer will enhance product security through threat modeling, secure code reviews, SDLC tooling, and managing the bug bounty program while collaborating with engineering teams to embed security in workflows.
Top Skills: Ci/CdDependency Scanning ToolsGithub Advanced SecurityJavaScriptNext.JsNode.jsOpen-Source Security ToolsStatic Analysis ToolsTypescript
12 Hours Ago
Remote
United States
196K-294K Annually
Senior level
196K-294K Annually
Senior level
Artificial Intelligence • Cloud • Software
As a Senior Software Engineer in Trust & Safety, you'll analyze threats, design systems for abuse detection, and collaborate with teams to implement scalable defenses.
Top Skills: AWSJavaScriptLlmPythonTypescript
12 Hours Ago
In-Office or Remote
245K-307K Annually
Senior level
245K-307K Annually
Senior level
Artificial Intelligence • Cloud • Software
Lead and develop the Americas Majors/Commercial SA team, ensuring technical excellence in pre and post-sales support, mentoring, and collaborating with sales and engineering.
Top Skills: APIsCloud InfrastructureNext.JsNode.jsReact

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account