Tines Logo

Tines

Senior GRC Analyst

Posted 6 Days Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
The Senior GRC Analyst will lead compliance strategies, assist in FedRAMP certification, maintain SOC 2 compliance, and manage vendor security assessments.
The summary above was generated by AI

Founded in 2018 with co-headquarters in Dublin and Boston, Tines powers some of the world's most important workflows. Our orchestration, automation, and AI platform enables businesses to operate more effectively, mitigate risk, reduce tech debt, and focus on high-impact work.

Tines serves a diverse range of customers, from startups to public companies, including Canva, Databricks, Elastic, Kayak, Intercom, and McKesson. As an integrator across the entire tech stack, Tines connects with any API-enabled service. This flexibility enables our customers to achieve their highest-priority goals faster. And because Tines is secure and private by design, it’s popular with security, IT and other security-focused teams. 

At Tines, we're driven by our values of Simplicity, Speed, and Soundness. We're committed to delivering exceptional customer experiences while fostering a company culture that nurtures individual curiosity, growth, and integrity. We’re excited about what’s next, and we’re looking for others to join us on our journey.

About the Role

Tines is seeking an experienced Senior Governance, Risk, and Compliance (GRC) Analyst to strengthen our compliance strategy and execution during a pivotal growth phase. Reporting directly to the Head of IT Operations & Information Security, you will play a critical role in our FedRAMP program while maintaining our existing SOC 2 compliance.

Location: Based remotely in the United States.

Key Responsibilities
  • FedRAMP Certification Efforts - Assist our FedRAMP certification program, including gap analysis, remediation planning, documentation development, and coordination with 3PAO assessors
  • Maintain SOC 2 Compliance - Support continuous compliance with SOC 2 requirements, including evidence collection, control testing, and audit coordination
  • Vendor Risk Management - Establish and manage a comprehensive vendor risk assessment program, evaluating security controls and compliance posture before acquisition
  • Risk Assessment and Management - Conduct thorough risk analyses for systems, processes, and third-party applications, implementing appropriate controls to mitigate identified risks
  • Compliance Automation - Leverage Tines automation capabilities to streamline compliance processes, evidence collection, and reporting
  • Customer Security Assurance - Respond to customer security inquiries, questionnaires, and audit requests, maintaining our Trust Center with up-to-date documentation
  • Policy Development and Maintenance - Review, update, and develop security policies and procedures aligned with regulatory requirements and industry best practices
  • Cross-functional Collaboration - Partner with engineering, product, legal, and leadership teams to embed compliance requirements into organizational processes
  • Contract Review and Management - Collaborate closely with the legal team to review contracts for security and compliance requirements, ensure appropriate security provisions are included, identify potential compliance risks, and recommend mitigating controls. Help develop standardized security language for various contract types.
  • Regulatory Monitoring - Stay current with evolving compliance standards and regulatory requirements relevant to our business and customers
QualificationsRequired
  • 8+ years of experience in IT compliance, security, or risk management
  • Demonstrated experience with FedRAMP certification processes and requirements
  • Hands-on experience implementing or maintaining ISO 27001 compliance
  • Strong knowledge of SOC 2 compliance frameworks and audit processes
  • Experience conducting vendor security assessments and risk analyses
  • Excellent understanding of information security principles, controls, and best practices
  • Strong project management skills with ability to manage multiple compliance initiatives simultaneously
  • Exceptional communication skills for translating technical requirements to non-technical stakeholders
Preferred
  • Industry certifications such as CISSP, CISA, or CISM
  • Experience with compliance automation tools and techniques
  • Knowledge of cloud security principles and controls (AWS, Azure, GCP)
  • Experience reviewing contracts for security and compliance requirements
  • Experience in SaaS or technology companies
  • Familiarity with privacy regulations (GDPR, CCPA)
  • Experience working in remote-first environments

Target Annual Compensation: $170-185K

Applicants for this opportunity must be authorized to work for any employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.

#LI-SW1

At Tines, we’re all about trying new things and taking the leap. If you’re second-guessing your application, we hope you’ll trust your gut and take the leap too! Applying for a new job isn’t always easy, especially if you’re thinking of a career pivot – but we’re big believers in learning and growth here at Tines, so you’ve nothing to worry about. A variety of experience, perspectives, and voices makes us the company we are. We’d love to hear from you.

Tines provides equal employment opportunities to all employees and applicants for employment without regard to sex, race, colour, ethnic or social origin, genetic features, language, religion or belief, political or any other opinion, membership of a national minority, property, birth, disability, age or sexual orientation.

Top Skills

AWS
Azure
Ccpa
Compliance Automation Tools
Fedramp
GCP
Gdpr
Iso 27001
Soc 2

Similar Jobs

8 Days Ago
Remote
USA
153K-180K Annually
Senior level
153K-180K Annually
Senior level
Security • Cybersecurity
Lead the SOx IT compliance program, coordinating audits, managing controls, documentation, and improving operational effectiveness while ensuring communication with stakeholders.
Top Skills: Cloud InfrastructureDrataIt General ControlsSaas ApplicationsServicenow
17 Hours Ago
Easy Apply
Remote
United States
Easy Apply
109K-169K
Senior level
109K-169K
Senior level
Security • Software • Cybersecurity • Automation
The Senior GRC Analyst will manage governance, risk, and compliance initiatives, ensuring adherence to security frameworks and supporting internal control testing and audit readiness.
Top Skills: AWSAzureGCP
17 Hours Ago
Remote
United States
145K-174K
Senior level
145K-174K
Senior level
Healthtech
The Senior Security GRC Analyst will lead security governance initiatives, conduct risk assessments, manage audits, and develop security awareness programs.
Top Skills: Aicpa Trust Services CriteriaAws Security Best PracticesDrataHipaa Security RuleHitrust CsfNist 800-53Nist CsfPci DssPhishing Simulation Tools

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account