Back to all jobs
Demandbase

Senior GRC Analyst

Demandbase Location TBD 3 days ago
healthcare
Introduction to Demandbase: Demandbase is the only pipeline AI platform that empowers GTM teams to automate growth at scale. With a unified view of data, insights, actions, and outcomes, B2B enterprises can seamlessly align and execute their account-based GTM strategies with confidence. Thousands of businesses trust Demandbase to maximize revenue, minimize waste, and consolidate their data and tech stacks – all in one platform. As a company, we’re as committed to growing careers as we are to building world-class technology. We invest heavily in people, our culture, and the community around us. We have also continuously been recognized as One of The Best Places To Work in the San Francisco Bay Area by Fortune, and One of The 60 Best Companies To Sell For by Selling Power. Our offices are located in San Francisco, New York, Austin, Seattle, India, and the United Kingdom. About the Role As a Senior GRC Analyst, you will play a pivotal role in advancing Demandbase’s global Governance, Risk, and Compliance (GRC) program. Reporting to the Senior Director of GRC, you will partner across teams to strengthen our compliance framework, manage audits, perform risk assessments, and drive continuous improvement in our security and privacy posture. You will help ensure ongoing alignment with global standards such as ISO 27001, ISO 27701, ISO 42001, and SOC 2, while contributing to the maturity of our enterprise risk and compliance operations. This is an opportunity to make a significant impact on a growing, global security program and advance your expertise in governance, risk, compliance, and AI assurance. Responsibilities Governance, Risk & Compliance Execution - Perform walkthroughs, control testing, and evidence collection across IT systems, applications, and infrastructure to support internal and external security audits. - Conduct and assist in risk assessments, identifying and tracking remediation efforts to resolution. - Support audits and assessments by coordinating with internal stakeholders and external auditors, ensuring timely and complete corrective actions. - Maintain documentation and dashboards within GRC tools (e.g., MetricStream, Hyperproof, Vanta) to monitor compliance posture and progress. Frameworks & Program Development - Contribute to maintaining and improving compliance programs in alignment with ISO 27001, ISO 27701, ISO 42001, SOC 2, and other relevant standards (NIST CSF, NIST 800-53, RMF). - Collaborate with technical and business teams to translate regulatory and control requirements into practical implementation steps. - Support operationalization of Business Continuity, Disaster Recovery, and Incident Response processes and exercises. - Contribute to the design and governance of emerging compliance domains, including AI Governance, Third-Party Risk Management, and Security Reviews. Culture, Communication & Continuous Improvement - Promote security and privacy awareness across the organization through training, education, and engagement initiatives. - Review and refine customer- and public-facing communications related to privacy, compliance, and security. - Identify opportunities to improve the data lifecycle (inventory, governance, retention, and protection). - Partner with cross-functional teams to enhance operational resilience and embed compliance best practices into daily workflows. Qualifications - 5+ years of experience in Information Security, GRC, ERM, compliance, audit, or internal controls, preferably in a cloud-based technology company. - Strong understanding of IT and cloud security controls, including Information Security, Business Continuity, Disaster Recovery, Vendor Management, and SDLC processes. - Familiarity with global frameworks and standards (ISO 27001, ISO 27701, ISO 42001, SOC 2, NIST CSF, NIST 800-53, RMF). - Proven ability to work across business and technical domains, translating complex control requirements into actionable solutions. - Excellent communication, organization, and stakeholder management skills. - Experience managing GRC platforms and compliance dashboards (e.g., MetricStream, Hyperproof, Vanta). - Strong project management background with experience coordinating complex, cross-functional initiatives. - Flexible and self-driven, able to thrive in a dynamic, fast-paced environment. - Bachelor’s or Master’s degree in Computer Science, Information Systems, Engineering, or a related field. Benefits Our benefits include Group Medical, Personal Accident, and Term Life Insurance for comprehensive protection. Preventive healthcare covers dental, vision, and OPD needs, complemented by strong mental health support. We also provide a fitness benefit, car lease policy, and gratuity for long-term financial well-being. Our Commitment to Diversity, Equity, and Inclusion at Demandbase At Demandbase, we believe in creating a workplace culture that values and celebrates diversity in all its forms. We recognize that everyone brings unique experiences, perspectives, and identities to the table, and we are committed to building a community where everyone feels valued, respected, and supported. Discrimination of any kind is not tolerated, and we strive to ensure that every individual has an equal opportunity to succeed and grow, regardless of their gender identity, sexual orientation, disability, race, ethnicity, background, marital status, genetic information, education level, veteran status, national origin, or any other protected status. We do not automatically disqualify applicants with criminal records and will consider each applicant on a case-by-case basis. We recognize that not all candidates will have every skill or qualification listed in this job description. If you feel you have the level of experience to be successful in the role, we encourage you to apply! We acknowledge that true diversity and inclusion requires ongoing effort, and we are committed to doing the work required to make our workplace a safe and equitable space for all. Join us in building a community where we can learn from each other, celebrate our differences, and work together. Unsolicited Submissions At Demandbase, we value thoughtful partnerships and direct connections with candidates. We’re not accepting unsolicited resumes or outreach from third-party recruiting agencies. Any unsolicited submissions will not be reviewed, and no fees will be paid.