Security Governance Risk & Compliance (GRC) Analyst

Other Jobs To Apply

<div class="content-intro"><p><strong>About Virtru:</strong></p> <p><span style="font-weight: 400;">Virtru is a leading data protection provider backed by some of the foremost venture capital firms in Silicon Valley and the Mid-Atlantic region, including Iconiq Capital, Bessemer Venture Partners, Foundry Capital, and Tiger Global. </span><span style="font-weight: 400;">Today, more than ever, data demands respect, and that’s why </span><span style="font-weight: 400;">Virtru is committed to changing the rules for data privacy. </span><span style="font-weight: 400;">At Virtru, we equip our customers to take granular control of their data—everywhere it’s shared—through end-to-end encryption for Google, Microsoft, and other data sharing platforms. Our market-leading portfolio of data encryption and privacy enhancing applications are remarkably easy to use, fast to implement, affordable for all, and built on the Trusted Data Format (TDF) open standard.</span></p> <p><span style="font-weight: 400;">At Virtru, our motto is "Respect the people. Respect the data." Respecting data to us means keeping it secure and protected at all times across its entire lifecycle. We firmly believe that when you respect data, you’re demonstrating respect for the people who own that data.</span></p> <p><span style="font-weight: 400;">Working at Virtru, you'll be inspired by colleagues who are passionate about the work they do. We are dedicated to creating an atmosphere that sparks creativity, connection, and professional growth while empowering each other to do our best work. We're building something special at Virtru. We hope you consider joining our team and helping us create a brighter future for data privacy.</span></p></div><p><strong>Compensation: $130,000-$180,000/year </strong></p> <p><strong>Team & Position Details: </strong></p> <p>Here at Virtru you’ll help build a cutting edge security compliance program aligned with FedRAMP, SOC 2, PCI, HIPAA, GDPR, and just about any other security/privacy framework you can think of, whilst getting your hands on some of today’s most important tools and tech like Kubernetes, GCP, AWS, Terraform. We put a high value on input from everyone on our team. Your voice will have a significant impact. With a constantly growing customer base, there is no shortage of challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service.</p> <p>As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's efforts to achieve and maintain CMMC compliance, by conducting gap analyses and developing a roadmap to address compliance requirements. You will also play a vital role in supporting our existing FedRAMP, SOC2, and PCI DSS compliance.</p> <p>Get in touch if you are excited to help us grow into a world-class security compliance program.</p> <p><strong>As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities will include:</strong></p> <ul> <li>Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc).</li> <li>Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.</li> <li>Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies.</li> <li>Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders.</li> <li>Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities  (FedRAMP, SOC 2, PCI).</li> <li>Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners.</li> <li>Participate in incident response (IR) activities, providing risk analysis and remediation support as needed.</li> <li>Enhance the team with your individualism, spirit, and love of learning.</li> </ul> <p><strong>Skills that will help you thrive in this role: </strong></p> <ul> <li>Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience</li> <li>Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks</li> <li>Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk)</li> <li>You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization</li> <li>Have experience training and coaching teams to become better security and privacy practitioners</li> <li>Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you'll collaborate with everyone to make sure we produce and implement the right solutions</li> <li>Ability to resolve conflicts and drive issues to completion.</li> <li>Work independently with little or no supervision while maintaining a high level of efficiency.</li> <li>Hands on experience deploying and managing vulnerability scanning/cloud security posture management tools (Wiz, Prismacloud, etc.) to meet security compliance requirements</li> <li>Real-world IR experience participating on security On-Call teams</li> <li>Basic knowledge of scripting languages like Bash, Python, or Javascript to automate manual tasks</li> <li>Familiarity with GitOps and Infrastructure-as-Code concepts</li> </ul> <p><strong>Virtruvian qualities that will set you up for success:</strong></p> <ul> <li>Thinking outside of the box to respectfully challenge your teammates and managers in the pursuit of excellence</li> <li>Strong sense of urgency with an action-oriented mindset</li> <li>Able to collaborate and adapt to shifting priorities as business needs evolve</li> <li>Comfortable with asynchronous communication including slack, email, zoom, etc.</li> </ul> <p><strong>Perks & Benefits:</strong></p> <p>At Virtru, we believe people do their best work when their wellbeing is put first. This is why we make your wellbeing our priority with a thoughtful and holistic program that encompasses Occupational, Mental, Social, Physical, and Environmental Wellness by offering benefits such as…</p> <ul> <li>A Flexible PTO policy — we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge. </li> <li>A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow.</li> <li>Frequent company-sponsored team celebrations that provide ample opportunities to connect with teammates and be social!</li> <li>Access to an Employee Assistance Program</li> <li>Access to Headspace, a mental health app tailored to your specific needs.</li> <li>A flat 3% contribution to your retirement account</li> <li>A high degree of flexibility — Have an appointment, errand, or family emergency to take care of? Hop to it! We give you the time and space to take care of you and your own first.</li> </ul> <p>In addition to wellbeing, Virtru places a strong emphasis on diversity, equity, inclusion, and belonging. Our DE&I Council is dedicated to fostering an inclusive workplace and making the psychological safety of each and every one of our teammates a top priority. </p> <p><strong>Additional perks include: </strong></p> <ul> <li>Competitive compensation</li> <li>Generous parental, medical, and bereavement policies</li> <li>401K contribution and stock options</li> <li>Full medical, dental, and vision benefits</li> <li>New Hire Swag and IT Welcome boxes</li> <li>Structured semi-annual 360° performance reviews</li> </ul> <p>Virtru is committed to building an inclusive environment for people of all backgrounds and everyone is encouraged to apply. Virtru is an Equal Opportunity Employer and does not discriminate on the basis of race, color, gender, sexual orientation, gender identity or expression, religion, disability, national origin, protected veteran status, age, or any other status protected by applicable national, federal, state, or local law.</p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...