I

GRC Analyst (Compliance & Risk Management) - SOC 2 / ISO 27001

ivo • United State
Visa Sponsorship Relocation
Apply
AI Summary

Support Ivo’s compliance programs, including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001, by managing audits, evidence collection, risk assessments, and cross-functional collaboration. Maintain security policies, vendor risk assessments, and AI governance initiatives in a fast-growing startup environment. Requires 3–5 years of GRC, IT audit, or information security experience with hands-on compliance platform expertise.

Key Highlights
Critical role in maintaining compliance with SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001
Fully onsite position in San Francisco with direct collaboration across Security, Engineering, IT, and Operations
Responsibilities include audit coordination, evidence management, risk assessments, and policy maintenance
Key Responsibilities
Support and coordinate compliance programs for SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001
Assist with annual, surveillance audits, and customer security assessments, including evidence collection and audit readiness
Monitor automated compliance evidence collection and control monitoring within Vanta GRC platform
Perform vendor and third-party risk assessments, maintain risk registers, and support enterprise risk management
Maintain and update security policies, standards, and procedures, including AI governance and responsible AI compliance
Technical Skills Required
Governance, Risk & Compliance (GRC) SOC 2 Type II Compliance ISO 27001 Compliance
Benefits & Perks
Competitive Compensation ($135K - $165K annual)
Equity in a rapidly scaling company
Relocation and Visa Support
Comprehensive medical, dental, and vision plans
401(k) Program
Unlimited PTO
Premium office perks (catered lunches, gym, dog-friendly environment)
Nice to Have
Experience working at a SaaS or AI company
Familiarity with GDPR, CCPA, and third-party risk management
Knowledge of cloud environments (GCP, AWS, Azure)
Relevant certifications (Security+, CISA, CRISC, CCSK, ISO 27001 Lead Implementer/Auditor)

Job Description


Why Join Ivo?

Every civilization runs on the same infrastructure: agreements between people who don't fully trust each other. Sumerians pressed them into clay. Romans carved them into stone. We bury them in 80-page PDFs.

The way those agreements are reviewed hasn't changed in four thousand years - a human reads the whole thing and tries not to miss anything. We're building the AI that finally changes that. Ivo is the contract intelligence platform of choice for companies like Uber, Meta, Canva, IBM, and Shopify. We recently raised our Series B and have grown 800% over the last 12 months.

The Opportunity

Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in maintaining and enhancing Ivo's compliance programs, including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001.

The ideal candidate has experience supporting security audits, managing evidence collection, conducting risk assessments, maintaining policies and procedures, and partnering cross-functionally with engineering, IT, legal, HR, and business stakeholders.

This is a fully onsite role based out of Ivo's San Francisco headquarters to support close cross-functional collaboration with Security, Engineering, IT, and Operations teams.

What You'll Do

  • Support and coordinate Ivo's compliance programs including SOC 2 Type II, ISO 27001, CSA STAR, and ISO/IEC 42001.
  • Assist with annual audits, surveillance audits, and customer security assessments.
  • Coordinate evidence collection and maintain audit readiness across teams.
  • Support and maintain Ivo's Vanta GRC platform and associated compliance workflows.
  • Monitor automated compliance evidence collection and control monitoring within Vanta.
  • Perform vendor and third-party risk assessments.
  • Support enterprise risk management and risk register maintenance.
  • Maintain and update security policies, standards, and procedures.
  • Support AI governance and responsible AI compliance initiatives.

What We're Looking

  • 3–5 years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Audit, or related field.
  • Hands-on experience supporting SOC 2 Type II, ISO 27001, CSA STAR, and in-depth knowledge of ISO/IEC 42001.
  • Experience administering or working extensively with Vanta or similar GRC/compliance automation platforms.
  • Experience managing and maintaining a customer-facing Trust Center, including security documentation, compliance artifacts, sub-processor disclosures, and customer assurance materials.
  • Strong understanding of information security principles and common security controls.
  • Experience with audits, evidence management, and customer security reviews.
  • Excellent written and verbal communication skills.

Nice to Haves

  • Experience working at a SaaS or AI company.
  • Familiarity with GDPR, CCPA, privacy regulations, and third-party risk management.
  • Knowledge of cloud environments such as GCP, AWS, or Azure.
  • Relevant certifications such as Security+, CISA, CRISC, CCSK, or ISO 27001 Lead Implementer/Auditor.

Ivo might be a good fit for you if you:

  • Would describe yourself as being relentlessly resourceful.
  • You have a strong internal sense of urgency. You have a bias towards doing things today, rather than tomorrow.
  • Experience working in a startup environment is preferred but not required.
  • Are excited about the adventure of building a company!

What We Offer

  • Competitive Compensation: Final offer details are determined based on experience, expertise, and overall fit.
  • Equity: Meaningful ownership in a company that's scaling fast
  • Relocation and Visa Support: We also offer relocation assistance for successful applicants moving to SF, as well as support for visa and green card applications where applicable.
  • Health & Wellness: Comprehensive medical, dental, and vision plans to suit the needs of you and your family.
  • Flexible Spending & Insurance: Access to HSA and FSA accounts, plus life insurance coverage.
  • 401(k) Program: Save for the future with our 401(k) program.
  • Commuter Benefits: We help make getting to and from the office easier and more convenient.
  • Unlimited PTO: So you can take the time you need to recharge, stay healthy, and bring your best self to work.
  • Office Perks: Enjoy a vibrant Downtown San Francisco office with catered lunch five days a week, premium snacks and coffee, an in-building gym, and a dog-friendly environment.

FAQ

  • What stage of growth is Ivo at?: We launched in early access in 2023. Since then, we’ve had an incredible response from the market and are growing rapidly. We 6x'd in ARR in the last 12 months. Our clients include companies like Uber, Reddit, IBM, Canva, Pinterest, WordPress, and more. We're happy to share more details with candidates who go through our interview process.
  • Is this a chill gig?: Startups are very hard, especially if they’re growing fast. You’ll have a ton of responsibility, and there’s always an enormous amount of stuff to do. It’s hard work but the payoff is uncapped.
  • Can I work remotely?: We require candidates to work with us in-person 5 days a week in our San Francisco office.

Ivo is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Compensation Range: $135K - $165K


Similar Jobs

Explore other opportunities that match your interests

Senior Front End Engineer (AI Automation, Consumer Operations Technology)

Programming
•
54m ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

h1bconnect

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

remote talent

United State

Staff+ Software Engineer, Infrastructure Systems

Programming
•
12h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

anthropic

United State

Subscribe our newsletter

New Things Will Always Update Regularly