Vercel
Vercel~1mo ago
$180,000 – $270,000/yr

Staff GRC Analyst

United StatesUnited StatesRemotelead
SecurityGrc AnalystCybersecurity
6 views0 saves0 applied

Quick Summary

Overview

About Vercel: Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web.

Key Responsibilities

Own and scale commercial attestation program and audits (i.e., SOC 2, ISO 27001, PCI DSS, etc.) while maintaining alignment with business objectives and market demand.

Requirements Summary

Experience managing and running audits, certification programs and enterprise control assessments, including scope planning, defining requirements, policy and standards development, and control testing Deep knowledge of audit processes, evidence…

Technical Tools
javascriptnextjsvercelmentoring

Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web.

Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.

About the Role

~1 min read

We are looking for a Staff GRC Analyst to join our Governance, Risk, and Compliance (GRC) team. You will have the opportunity to enhance our global compliance posture and further our commitment to managing enterprise risk. Your role will be instrumental in ensuring that our company operates in accordance with security requirements and embodies an environment where it’s everyone’s responsibility. This role will help shape the next iteration of the GRC program and further embed compliance requirements into the business.

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

  • We want you to feel like part of the team early on! Our team will help integrate you into the company with explanations on our product, policies, processes, team structure and roadmap.
  • We’re excited for you to learn, grow, and contribute right away! We trust that you’ll bring experience and knowledge that will uplift and up-level the team, but we don’t expect you to know everything on Day 1.

Responsibilities

~1 min read
  • Own and scale commercial attestation program and audits (i.e., SOC 2, ISO 27001, PCI DSS, etc.) while maintaining alignment with business objectives and market demand.
  • Design and strengthen continuous monitoring processes to improve control effectiveness and mature control implementation from audit-ready to always-ready.
  • Drive evolution of security and compliance control frameworks that set the direction for proactive risk management.
  • Partner with cross-functional stakeholders, acting as a strategic connector to plan, implement, maintain & remediate control activities and supporting requirements (e.g. policies, standards, processes, system configurations, etc.)
  • Champion a culture of compliance accountability and business-enablement across the organization through autonomous program governance and reporting and building trusted relationships.
  • Experience managing and running audits, certification programs and enterprise control assessments, including scope planning, defining requirements, policy and standards development, and control testing
  • Deep knowledge of audit processes, evidence requirements, and remediation lifecycle management for security and compliance frameworks (i.e., SOC 2, ISO 27001, PCI DSS)
  • Proven experience owning large-scale GRC programs, collaborating with technical and non-technical teams and driving initiatives to completion

Nice to Have

~1 min read
  • Familiarity with data governance, compliance or software development tools and systems (e.g., Drata, Linear, Github, etc.)
  • Experience supporting cloud, AI-native, and open source development environments and systems
  • Experience with FedRAMP or NIST frameworks, such as 800-53, AI RMF
  • Security certifications (e.g. CISA, CISSP)

What We Offer

~1 min read
Competitive compensation package, including equity.
Inclusive Healthcare Package.
Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
Flexible Time Off.
We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

Location & Eligibility

Where is the job
United States
Remote within one country
Who can apply
US
Listed under
United States

Listing Details

First seen
March 25, 2026
Last seen
May 10, 2026

Posting Health

Days active
46
Repost count
0
Trust Level
51%
Scored at
May 11, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Vercel
Vercel
greenhouse

We enable developers to build and publish wonderful things. We build products for developers and designers. And those who aspire to become one.

Employees
350
Founded
2020
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

VercelStaff GRC Analyst$180k–$270k