Zone & Co

Tech / AI / Software

GRCAnalyst

United States Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“GRC Analyst at Zone & Co. Skills: Security and Privacy Compliance, Governance, Risk, and Compliance (GRC), SOC 2 Type II, ISO 27001, GDPR, CCPA/CPRA. Lead the management and continuous scaling of Zone & Co’s core security compliance frameworks, specifically SOC 2 Type II and ISO 27001.. Govern global data privacy operations to ensure strict, ongoing alignment with GDPR, CCPA/CPRA, and other emerging data protection laws.”

What You'll Achieve.

safeguard our organization and our customers' data; maturing our governance, risk, and compliance (GRC) programs; maintains the highest standards of data protection and privacy; proactively identify and mitigate vulnerabilities; ensure strict, ongoing alignment with GDPR, CCPA/CPRA, and other emerging data protection laws

Industry & Context.

Tech / AI / Software
Problems you'll solve

Analytical & Problem-Solving Skills; Proven ability to translate complex regulatory requirements into actionable, practical controls for IT and engineering teams without stifling innovation.

What They're Looking For.

Must Have

3+ years of direct experience in IT Audit, Information Security, Privacy Operations, or GRC (Governance, Risk, and Compliance), Bachelor’s degree in Information Systems, Cybersecurity, Business, or a related field

Nice to Have

preferably within a B2B SaaS, FinTech, or cloud technology environment, Relevant industry certifications such as CISA, CISM, CIPP/E, CIPP/US, or Security+

What You'll Do.

Lead the management and continuous scaling of Zone & Co’s core security compliance frameworks

specifically SOC 2 Type II and ISO 27001.

Govern global data privacy operations to ensure strict

ongoing alignment with GDPR

and other emerging data protection laws.

Serve as the primary security liaison for enterprise customers

directly supporting the sales cycle by demonstrating and communicating a robust

mature security posture.

Manage the organization's internal audit program and oversee the third-party vendor risk lifecycle to proactively identify and mitigate vulnerabilities.

Coordinate evidence collection

manage project timelines

and partner directly with external auditors during annual compliance assessments.

Conduct Data Privacy Impact Assessments (DPIAs) for new products and process Data Subject Access Requests (DSARs) within mandated SLAs.

Accurately and efficiently complete incoming vendor security questionnaires from prospects and maintain up-to-date documentation in our customer-facing Trust Center.

Design and execute internal audits to test whether technical and administrative controls are operating effectively.

Track control gaps and drive engineering/IT remediation efforts.

Evaluate the security and privacy postures of prospective and existing third-party vendors and sub-processors through comprehensive risk assessments.

and publish internal security policies

standard operating procedures (SOPs)

and incident response plans.

Develop and administer engaging company-wide security and privacy awareness training.

How You'll Work.

Team & Collaboration

partner directly with external auditors; drive engineering/IT remediation efforts; communicate compliance postures to both internal engineering teams and enterprise customers

Communication Scope

clearly communicate compliance postures; Outstanding written and verbal communication skills; write clear policies; translate technical risks for business leaders; confidently answer complex customer security questions

Process & Methodology

manage project timelines

Full Job Description

About Zone & Co: Zone & Co is on a mission to empower finance professionals to drive strategic growth through seamless, intelligent operations. We build cloud-native software solutions on Oracle NetSuite, automating complex financial processes like billing, accounts payable, reporting, and reconciliation. Our vision is to unlock the full strategic potential of finance by infusing the ERP with the intelligence and automation needed for truly transformative operations. Join our rapidly growing team as we redefine financial efficiency for scaling businesses worldwide. The Role: We are seeking a meticulous and proactive Security and Privacy Compliance Analyst to help safeguard our organization and our customers' data. Reporting directly to the Director of IT, Security and Compliance, you will play a critical role in maturing our governance, risk, and compliance (GRC) programs. In this position, you will bridge the gap between technical security controls and regulatory requirements, ensuring that Zone & Co's rapidly expanding suite of financial software maintains the highest standards of data protection and privacy. This role requires a strong foundational knowledge of major security frameworks and privacy regulations, a keen eye for detail in auditing internal processes, and the ability to clearly communicate compliance postures to both internal engineering teams and enterprise customers. Essential Job Functions: Compliance Framework Governance: Lead the management and continuous scaling of Zone & Co’s core security compliance frameworks, specifically SOC 2 Type II and ISO 27001. Privacy Operations Leadership: Govern global data privacy operations to ensure strict, ongoing alignment with GDPR, CCPA/CPRA, and other emerging data protection laws. Customer Trust & Revenue Enablement: Serve as the primary security liaison for enterprise customers, directly supporting the sales cycle by demonstrating and communicating a robust, mature security posture. Risk & Audit Managemen

Free ATS check

Applying for this GRC Analyst role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Greenhouse

  • Create a Greenhouse profile before applying — it saves time across multiple applications.
  • Upload your resume as a PDF; the parser handles it better than Word.
  • Answer all knockout questions carefully — wrong answers auto-reject before a human sees you.
  • Enable email notifications to track application status in real time.

ANONYMOUS · UNFILTERED

What do employees actually say about Zone & Co?

Real rants from real employees. Read before you apply.

Read Company Rants →