Are you applying to the internship?

Job Description

GRC Analyst, Entry Level | Jobright.ai

The Tone:
This is a remote role at Jobright.ai, a company at the forefront of AI innovation, building personal AI job search agents that simplify and accelerate the job search process for users. Joining Jobright.ai means working at the intersection of AI, agents, and product development, with a unique opportunity to shape how people experience AI-driven job search. The Entry-Level GRC Analyst supports critical governance, risk, and compliance operations by ensuring the integrity of documentation, coordinating security assessments, and preparing essential audit evidence. This role offers high ownership and direct impact on the company’s security posture and continuous compliance, making it fundamental to Jobright.ai’s success and trustworthiness.

The TL;DR
• Role: Early Career
• Type: Full-time
• Location: Remote – United States

• Mission: Own the accurate maintenance of risk and compliance documentation, support assessment coordination, and prepare evidence for audits and reviews to strengthen Jobright.ai’s GRC framework and ensure operational integrity.
• Tech Stack: Spreadsheets, trackers, GRC tools, ticketing tools, document management tools, risk tracking tools.

What You’ll Actually Do
• Maintain: Proactively maintain and update essential GRC documentation, including detailed risk registers, comprehensive control inventories, and organized compliance evidence, ensuring accuracy and accessibility for ongoing operations and reviews.
• Assist: Provide dedicated support for various control assessments, conduct thorough gap analyses to identify areas for improvement, and diligently track remediation efforts from initiation through successful completion.
• Collect: Systematically collect, organize, and prepare necessary evidence packages for internal and external audits, as well as customer security reviews, ensuring all specific requirements are met.
• Update: Actively contribute to the ongoing development, review, and refinement of vital security documentation, policies, and procedures, ensuring they remain current, accurate, and aligned with company standards.
• Track: Effectively manage the full lifecycle of security findings by meticulously tracking owners, establishing clear due dates, and monitoring status diligently to ensure timely resolution and successful closure.

The Must-Haves
• Background: An entry-level candidate with a basic understanding of governance, risk, compliance (GRC), or fundamental information security concepts.
• Experience: Demonstrated ability to manage multiple priorities independently within a remote work environment, coupled with comfort in working with spreadsheets, trackers, and structured review processes. This includes the capacity to interpret complex requirements and document findings or evidence clearly and accurately.
• Skills: Strong attention to detail, exceptional organizational abilities, and clear, concise written communication are essential for maintaining accurate documentation and effective collaboration.
• Bonus: Preferred qualifications include exposure to industry-recognized frameworks such as NIST, ISO 27001, SOC 2, or CIS Controls. Candidates with internship, coursework, certification, or project experience in security, audit, or compliance are highly valued. Familiarity with GRC, ticketing, document management, or risk tracking tools, along with entry-level certifications like Security+ or ISO 27001 Foundation, will also be a significant asset.

Related Jobs