A

Security GRC Analyst I

Virtualmid
OtherSecurity Grc Analyst
0 views0 saves0 applied

Quick Summary

Key Responsibilities

Security Awareness Support administration of AvidXchange’s security awareness and phishing simulation program in KnowBe4, including training assignments, campaign design, and coordination.

Technical Tools
OtherSecurity Grc Analyst

As a Security GRC Analyst I, you will play an important role in supporting and strengthening AvidXchange’s information security governance, risk, and compliance program. You will collaborate with teams across the organization to support audits, security awareness initiatives, reporting, risk assessments, and related compliance efforts. This role will contribute to a broad range of operational GRC activities, helping improve cybersecurity visibility, risk management, and program maturity across the organization.

Responsibilities

~1 min read
  • Support administration of AvidXchange’s security awareness and phishing simulation program in KnowBe4, including training assignments, campaign design, and coordination.

  • Assist with building creative cybersecurity awareness communications, campaigns, and recurring outreach activities designed to engage a wide range of teammates and cyber knowledge levels.

  • Monitor participation, phishing, and engagement metrics to measure program effectiveness and identify improvement opportunities.

  • Contribute to ongoing enhancement of awareness content to keep training engaging, relevant, and aligned with emerging threats.

  • Enhance and support our Security Champion Program to empower security-focused individuals to make a difference in their team.

  • Assist with cybersecurity risk assessments, audits, and third-party/vendor reviews.

  • Coordinate assessment and audit efforts through documentation, evidence gathering, and cross-functional collaboration.

  • Track remediation items, risk findings, audit observations, and follow-up efforts across teams.

  • Develop and maintain cybersecurity metrics, dashboards, and reporting tailored to technical teams, leadership, and executive audiences.

  • Create visualizations, presentations, and other deliverables using tools such as Power BI, Excel, and PowerPoint.

  • Coordinate recurring reporting activities related to risk committees, audits, awareness initiatives, and operational metrics.

  • Analyze data to identify meaningful trends, gaps, and opportunities for program improvement.

  • Maintain cybersecurity documentation, policies, standards, repositories, and other governance materials.

  • Assist with customer and vendor due diligence activities, including questionnaire responses, customer assurance communications, and trust center maintenance.

  • Coordinate business continuity and incident response preparedness efforts, including tabletop exercises and related operational initiatives.

 

  • 1 – 3 years of experience in cybersecurity, including exposure to one or more of the following areas:

    • risk management (including third-party/vendor)

    • compliance and control frameworks

    • audit and assessments

    • security awareness programs

    • reporting, analytics, or operational support functions

  • Experience developing reports, dashboards, presentations, or visualizations using tools such as Excel or Power BI.

  • Strong verbal and written communication skills, with the ability to communicate effectively with technical and non-technical stakeholders.

  • Strong analytical and problem-solving skills, with the ability to identify risks, organize information, and support risk and compliance efforts.

  • Excellent organizational skills, with the ability to manage multiple priorities, deadlines, and cross-functional initiatives.

  • Comfortable working collaboratively across technical, operational, and business teams.

  • Familiarity with industry frameworks and regulations (e.g., NIST, NYDFS, SOC 1/2, PCI, ISO 27001) and comfort mapping controls to requirements.

  • Experience with or exposure to LogicGate or other GRC/TPRM tools.

  • Self-motivated and curious, with interest in cybersecurity, risk management, and evolving industry trends.

  • Relevant certifications such as Security+, ISC2 CC, CISA, or similar certifications are preferred.

 

AvidXchange is a leading provider of accounts payable (“AP”) automation software and payment solutions for middle-market businesses and their suppliers. By trade, we are a technology company, but if you ask anyone who works here, they’ll tell you our people are at the core of who we are. At AvidXchange, mindset is everything. We are Connected as People, Growth Minded, and Customer Obsessed. These three mindsets represent our culture – who we are, who we’ve always been, and they guide us to improve every day. Since our founding in 2000 in Charlotte, NC, we’ve created a company of over 1,500 teammates working across the U.S., or remotely. AvidXchange is proud to be Certified™ as a Great Place to Work®. The prestigious recognition is based on anonymous data from our teammates and makes official what our teammates have known for years – that AvidXchange is a Great Place to Work®. 

  • A go-getter with an entrepreneurial mindset – that means you are not afraid of taking risks, winning big or facing the unknown. 
  • Someone who understands that business is people centric. Connecting with others as humans first allows you to develop mutually beneficial working relationships. 
  • Focused on making a difference for our customers. AvidXchange exists to help solve complex problems for our customers so we can all realize our potential. 

AvidXchange teammates (we call them AvidXers) get the perks and prestige of a growing tech company paired with the flexibility of a founder-led startup. We help our AvidXers develop as professionals and as human beings, providing work/life balance, development programs, and competitive benefits. At AvidXchange, we are building more than a tech company – we are building an experience. We remain committed to a culture where you can fully be 'you’ – connected with others, chasing big goals, and making a meaningful impact. If you want to help us grow while realizing your potential and creating stories you’ll tell for years, you’ve come to the right place.

  • 18 days PTO* 
  • 11 Holidays (8 company recognized & 3 floating holidays) 
  • 16 hours per year of paid Volunteer Time Off (VTO) 
  • Competitive Healthcare 
    • High Deductible Heath Plan Option that has $0 monthly premium for teammate-only coverage 
    • 100% AvidXchange paid Dental Base Plan Coverage
    • 100% AvidXchange paid Life Insurance 
    • 100% AvidXchange paid Long-Term Disability 
    • 100% AvidXchange paid Short-Term Disability  
    • Employee Assistance Program (EAP) - Provides counseling services, legal and financial consultations and health advocacy for Teammates and their eligible dependents
    • Onsite Health Clinic with Atrium Health - available to Teammates and their eligible dependents
  • 401(k) Match: 100% match on the first 3% of your salary, plus 50% match on the next 2%
  • Parental Leave: 8 weeks 100% paid by AvidXchange** 
  • Discounts on Pet, Home, and Auto insurance 
  • WeeCare Childcare Service: helps teammates find affordable daycare, childcare, and tutors 40% less expensive than traditional daycare centers 
  • Perks at Work: free discount program that provides teammates the opportunity to save on items from electronics, movie tickets, car buying, vacations, and more 
  • Onsite gym fitness center, yoga studio, and basketball court
  • Tuition Reimbursement up to the federal maximum of $5,250***
  • Hybrid Workplace Flexibility
  • Free parking

*Fully granted from beginning of year, pro-rated if hired mid-year 

**Must be full-time for at least 3 months

***Must be full-time for at least one year 

AvidXchange is an equal opportunity employer. AvidXchange is committed to equal employment opportunity in accordance with applicable federal, state, and local laws. AvidXchange will not discriminate against applicants for employment on any legally recognized basis. This includes, but is not limited to veteran status, race, color, religion, sex, sexual orientation, gender identity, gender expression, national origin, age and physical or mental disability. 

Location & Eligibility

Where is the job
Virtual
On-site at the office
Who can apply
Same as job location

Listing Details

Posted
May 28, 2026
First seen
May 28, 2026
Last seen
May 29, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
60%
Scored at
May 28, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

A
Security GRC Analyst I