GRC Analyst
Uplight
full-remotemidpermanentsecuritylegal-compliance Full remote 110 days ago via WTTJ
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
GRCVendor Risk ManagementPolicy ManagementRisk AssessmentIT AuditsIncident ResponseSecurity QuestionnairesRFPAWSAzure/GCP
About the role
Role Overview
As a GRC Analyst at Uplight (full remote), you will help drive the organization’s governance, risk, and compliance efforts by managing third-party/vendor risk assessments and supporting security and compliance processes. You’ll also contribute to privacy and information security posture through ongoing GRC initiatives.
Key Missions / Responsibilities
- Third-party/Vendor risk management: Manage vendor/security and compliance-related risk assessment activities and support sales and operations with security/compliance tasks.
- GRC execution: Participate in GRC processes including risk assessments, policy management, and audits.
- Privacy & information security posture: Contribute to improvement projects across GRC, privacy, and information security.
- Security incident response support: Assist with incident response activities, including developing playbooks, managing incident response processes, and supporting continuous improvement.
Requirements
- Understanding of GRC processes such as policy management, risk assessment, and IT audits.
- Experience with third-party/vendor risk management.
- Excellent verbal and written communication skills.
- 1–3 years experience in a GRC and/or security role.
- Experience supporting sales activities (e.g., security questionnaires and Requests for Proposals (RFPs)).
- Exposure to public cloud and cloud security concepts (e.g., AWS, Azure, or GCP).
Nice-to-Haves
- GRC or Privacy certifications, e.g., CISA, CIPP (or similar).
About Uplight
Uplight creates software-driven solutions to support the clean energy industry. The company focuses on enabling a new category of energy through technology, with an emphasis on strong governance, risk, compliance, privacy, and information security practices.
Scraped 7/16/2026