GRC Analyst
MercuryFull Time
Mid-level (3 to 4 years), Senior (5 to 8 years)
Candidates should possess 7-10 years of experience in security governance, risk, or compliance roles, preferably within SaaS or regulated industries. A strong track record of operationalizing ISMS frameworks, managing control assurance, and supporting security governance programs is required. Experience with ISO 27001, SOC 2, and FedRAMP is beneficial, along with knowledge of emerging regulations like DORA, SEC, and the UK AI Act. Familiarity with GRC tooling and a global team environment is also expected.
The GRC Lead will maintain and improve the ISO 27001-aligned ISMS, oversee the control assurance program, and manage internal and external audit workstreams. Responsibilities include driving the cybersecurity risk assessment lifecycle, enhancing risk methodologies, and supporting risk acceptance processes. The role involves monitoring regulations, managing customer security assessments, and leading third-party security reviews. Additionally, the GRC Lead will maintain the InfoSec policy lifecycle, develop governance metrics and reporting, deliver security training, and refine GRC workflows and tooling.
Archiving and compliance solutions provider
Smarsh provides archiving and compliance solutions specifically designed for financial services, government agencies, and other regulated industries. Their main product is a cloud-based archive that allows organizations to securely store, search, and manage their communications data, including emails, text messages, and social media interactions. This system helps businesses meet complex security, data privacy, and regulatory requirements. Smarsh differentiates itself from competitors by offering a scalable Software-as-a-Service (SaaS) model that caters to both large enterprises and smaller organizations, ensuring that clients can adapt to evolving regulations. Their goal is to help organizations efficiently manage their communication data, identify risks, and maintain compliance, particularly through tools like Connected Capture for Microsoft Teams, which supports remote workforces.