GRC Senior Analyst

Posted 56 days ago
$190k–210k / year
Remote
Full-Time
analyst
grc
infosec

GRC Senior Analyst

About Us

Notion helps you build beautiful tools for your life’s work. In today's world of endless apps and tabs, Notion provides one place for teams to get everything done, seamlessly connecting docs, notes, projects, calendar, and email—with AI built in to find answers and automate work. Millions of users, from individuals to large organizations like Toyota, Figma, and OpenAI, love Notion for its flexibility and choose it because it helps them save time and money.

In-person collaboration is essential to Notion's culture. We require all team members to work from our offices on Mondays, Tuesdays, and Thursdays, our designated Anchor Days. Certain teams or positions may require additional in-office workdays.

About the Role

Millions of people use Notion — and this number is increasing every day. Our users depend on us to deliver a secure, consistent and trustworthy experience, and we value this more than anything. We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion. This is where you come in — partnering with teams across the organization to envision, plan and build Notion's Information Security posture through governance, risk and compliance.

What You'll Achieve

  • Coordinate evidence collection, manage timelines with internal partners, support external auditors for compliance frameworks such as SOX ITGCs, SOC 2 Type II, ISO, HIPAA, and BSI C5.
  • Help improve and maintain information security policies, controls, procedures, and standards, for processes, applications, and infrastructure.
  • Use and help build custom AI agents and automation to scale and mature our Security GRC programs. For example, automate evidence collection, control monitoring workflows, and reporting.
  • Contribute to the development of dashboards and metrics for compliance and audit reporting.
  • Implement and expand our continuous control monitoring efforts using our compliance automation tool.
  • Identify gaps in our security controls and work with teams across the organization to strengthen them.

Skills You'll Need to Bring

  • Bachelor’s or master’s degree in Computer Science, Information Technology, Management Information Systems, or Cybersecurity, or equivalent practical experience.
  • Strong understanding of the governance, risk, and compliance domain and why it matters for organizational security and privacy.
  • Familiarity with compliance automation tools (e.g., Anecdotes, Vanta).
  • Familiarity with cloud technologies (e.g., AWS, Wi)
Notion
Remote
View company profile
Share this job