Bold Penguin Logo

Bold Penguin

Senior Governance, Risk, & Compliance (GRC) Specialist

Posted 5 Hours Ago
Be an Early Applicant
Remote
Hybrid
Hiring Remotely in Dublin, OH
Senior level
Remote
Hybrid
Hiring Remotely in Dublin, OH
Senior level
As a GRC Specialist, you will lead GRC initiatives, manage audits, and collaborate with teams to maintain compliance and security.
The summary above was generated by AI

Description
YOUR ROLE
As a Governance, Risk, & Compliance (GRC) Specialist, you will support and eventually lead our Governance, Risk, and Compliance (GRC) program. You will ensure our security practices meet industry standards, manage audits, and collaborate with teams to maintain compliance.
WHAT YOU'LL DO

  • Assist in developing, updating, and maintaining security policies, risk assessments, and compliance documentation to support GRC activities.
  • Lead the planning, execution, and follow-up of SOC 2 Type 2 audits, including evidence collection and coordination with external auditors.
  • Expand the SOC 2 audit scope to incorporate additional business units and integrate privacy controls into the Trust Services Criteria.
  • Leverage tools to automate compliance controls and monitor systems for continuous audit readiness.
  • Conduct third-party vendor risk assessments and collaborate with teams to mitigate identified risks.
  • Perform regular user access reviews for AWS and other critical systems to enforce least privilege and ensure security.
  • Respond to security questionnaires and provide compliance documentation to clients, partners, and auditors.
  • Partner with engineering, product, and legal teams to integrate compliance requirements into product development and business processes.
  • Monitor regulatory developments and adjust the compliance program to maintain alignment with industry standards.
  • Support the development and delivery of compliance training and awareness programs for internal teams
  • Other duties and responsibilities as assigned


Requirements
Flexible Workplace
This role is a flex office/home role and comes with the expectation you will engage onsite a certain number of working days per month, in our brand-new office located in Dublin, Ohio, with your Bold Penguin colleagues and customers. On-site workdays will be managed at the team level to maintain an environment focused on work-life balance, innovation velocity, and the delivery of exceptional customer experiences.
In this role, you will be expected to work 20% of working days per month (4 days per month on average) in the office. This is a minimum expectation. All employees are welcome to work in the office as much as they like. Applicants must be local (within 35 miles) to Dublin, Ohio.
Skills & Experience

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or relevant work experience.
  • 5+ years of relevant work experience with 2+ years of experience in security, compliance, or risk management, preferably in tech or startups.
  • Knowledge of SOC 2 Type 2 audits, compliance frameworks, and privacy regulations.
  • Strong communication, organizational, and detail-oriented skills.
  • Ability to adapt and learn quickly in a fast-paced environment.
  • Proficiency with compliance tools (e.g., Drata) and cloud platforms (e.g., AWS).
  • Preferred, but not required: Certifications such as CISA, CRISC, or CIPP/US.


Physical Requirements

  • Must be able to sit/stand/walk for prolonged periods of time, (up to 8 hours per day) at a desk working on a computer.
  • Must be able to use standard office equipment for extended periods of time, including but not limited to, a mouse, keyboard, phone and video conferencing.


Summary
Bold Penguin is a leading integrated digital solution platform dedicated to simplifying small commercial insurance. Our technology makes the quote and bind process quick, effortless, and profitable for all parties - agents, brokers, and carriers. Bold Penguin's innovative product suite has digitized and transformed a slow, manual process resulting in reduced costs, increased efficiency, and better overall outcomes. For more information, please visit www.boldpenguin.com .
Or, simply put.... We simplify commercial insurance.
Benefits
We offer competitive compensation and progressive benefits that include:

  • Medical, Dental, and Vision
  • Flexible PTO Policy
  • 401(k) with a company match
  • Employee Assistance Program
  • Parental Leave
  • Disability and Life Benefits


Stay connected to the Glacier. We have great SLACK channels for work and play. We also like to video conference and hold all-hands "Waddles" regularly.
Penguin bling. Like swag themed after a certain Antarctic bird? Just. You. Wait.
Bold Penguin believes in inclusion. That's why we're proud to be an equal opportunity employer that considers all qualified applicants regardless of race, color, religion, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. To learn more about our results-focused culture and employee-focused perks, read more on our careers page .

Top Skills

AWS
Compliance Tools
Drata

Similar Jobs at Bold Penguin

5 Hours Ago
Remote
Hybrid
Dublin, OH, USA
Mid level
Mid level
Insurance • Sales • Software
As a Senior Cloud Security Engineer, you'll secure cloud infrastructure, manage compliance, evaluate vulnerabilities, and integrate security practices in collaboration with teams.
Top Skills: Ci/CdCloud InfrastructureCloud Security Posture ManagementEndpoint Detection And ResponseInfrastructure As CodeSecurity Information And Event ManagementSecurity Tools
5 Days Ago
Remote
Hybrid
United States
100K-147K Annually
Senior level
100K-147K Annually
Senior level
Insurance • Sales • Software
As a Senior Software Engineer, you'll develop APIs, write clean code, mentor others, and collaborate in a cross-functional team to enhance products for the commercial insurance industry.
Top Skills: Cloud ArchitectureGitRuby On RailsScrum
5 Days Ago
Remote
Hybrid
United States
117K-181K Annually
Senior level
117K-181K Annually
Senior level
Insurance • Sales • Software
Lead and architect scalable software solutions while mentoring junior engineers and collaborating with various teams to deliver high-complexity features.
Top Skills: Cloud ArchitectureContinuous IntegrationDevOpsRuby On RailsSite-Reliability Engineering

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account