Zone & Co
Tech / AI / Software
GRCAnalyst
Neural analysis suggests this role is
optimal for Mid candidates.
“GRC Analyst at Zone & Co. Skills: Security and Privacy Compliance, Governance, Risk, and Compliance (GRC), SOC 2 Type II, ISO 27001, GDPR, CCPA/CPRA. Lead the management and continuous scaling of Zone & Co’s core security compliance frameworks, specifically SOC 2 Type II and ISO 27001.. Govern global data privacy operations to ensure strict, ongoing alignment with GDPR, CCPA/CPRA, and other emerging data protection laws.”
What You'll Achieve.
safeguard our organization and our customers' data; maturing our governance, risk, and compliance (GRC) programs; maintains the highest standards of data protection and privacy; proactively identify and mitigate vulnerabilities; ensure strict, ongoing alignment with GDPR, CCPA/CPRA, and other emerging data protection laws
Industry & Context.
Analytical & Problem-Solving Skills; Proven ability to translate complex regulatory requirements into actionable, practical controls for IT and engineering teams without stifling innovation.
What They're Looking For.
Must Have
3+ years of direct experience in IT Audit, Information Security, Privacy Operations, or GRC (Governance, Risk, and Compliance), Bachelor’s degree in Information Systems, Cybersecurity, Business, or a related field
Nice to Have
preferably within a B2B SaaS, FinTech, or cloud technology environment, Relevant industry certifications such as CISA, CISM, CIPP/E, CIPP/US, or Security+
What You'll Do.
Lead the management and continuous scaling of Zone & Co’s core security compliance frameworks
specifically SOC 2 Type II and ISO 27001.
Govern global data privacy operations to ensure strict
ongoing alignment with GDPR
and other emerging data protection laws.
Serve as the primary security liaison for enterprise customers
directly supporting the sales cycle by demonstrating and communicating a robust
mature security posture.
Manage the organization's internal audit program and oversee the third-party vendor risk lifecycle to proactively identify and mitigate vulnerabilities.
Coordinate evidence collection
manage project timelines
and partner directly with external auditors during annual compliance assessments.
Conduct Data Privacy Impact Assessments (DPIAs) for new products and process Data Subject Access Requests (DSARs) within mandated SLAs.
Accurately and efficiently complete incoming vendor security questionnaires from prospects and maintain up-to-date documentation in our customer-facing Trust Center.
Design and execute internal audits to test whether technical and administrative controls are operating effectively.
Track control gaps and drive engineering/IT remediation efforts.
Evaluate the security and privacy postures of prospective and existing third-party vendors and sub-processors through comprehensive risk assessments.
and publish internal security policies
standard operating procedures (SOPs)
and incident response plans.
Develop and administer engaging company-wide security and privacy awareness training.
How You'll Work.
Team & Collaboration
partner directly with external auditors; drive engineering/IT remediation efforts; communicate compliance postures to both internal engineering teams and enterprise customers
Communication Scope
clearly communicate compliance postures; Outstanding written and verbal communication skills; write clear policies; translate technical risks for business leaders; confidently answer complex customer security questions
Process & Methodology
manage project timelines
Full Job Description
About Zone & Co: Zone & Co is on a mission to empower finance professionals to drive strategic growth through seamless, intelligent operations. We build cloud-native software solutions on Oracle NetSuite, automating complex financial processes like billing, accounts payable, reporting, and reconciliation. Our vision is to unlock the full strategic potential of finance by infusing the ERP with the intelligence and automation needed for truly transformative operations. Join our rapidly growing team as we redefine financial efficiency for scaling businesses worldwide. The Role: We are seeking a meticulous and proactive Security and Privacy Compliance Analyst to help safeguard our organization and our customers' data. Reporting directly to the Director of IT, Security and Compliance, you will play a critical role in maturing our governance, risk, and compliance (GRC) programs. In this position, you will bridge the gap between technical security controls and regulatory requirements, ensuring that Zone & Co's rapidly expanding suite of financial software maintains the highest standards of data protection and privacy. This role requires a strong foundational knowledge of major security frameworks and privacy regulations, a keen eye for detail in auditing internal processes, and the ability to clearly communicate compliance postures to both internal engineering teams and enterprise customers. Essential Job Functions: Compliance Framework Governance: Lead the management and continuous scaling of Zone & Co’s core security compliance frameworks, specifically SOC 2 Type II and ISO 27001. Privacy Operations Leadership: Govern global data privacy operations to ensure strict, ongoing alignment with GDPR, CCPA/CPRA, and other emerging data protection laws. Customer Trust & Revenue Enablement: Serve as the primary security liaison for enterprise customers, directly supporting the sales cycle by demonstrating and communicating a robust, mature security posture. Risk & Audit Managemen
Applying for this GRC Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Greenhouse
- Create a Greenhouse profile before applying — it saves time across multiple applications.
- Upload your resume as a PDF; the parser handles it better than Word.
- Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
- Enable email notifications to track application status in real time.
ANONYMOUS · UNFILTERED
What do employees actually say about Zone & Co?
Real rants from real employees. Read before you apply.