Information Security GRC Analyst
Confirmed live in the last 24 hours
OneTrust
Compensation
$58.52 USD
Job Description
Strength in Trust
OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society.
The Challenge
The Security Customer Assurance Analyst plays a critical role in building and maintaining customer trust by responding to customer security, privacy, and compliance inquiries. This role partners closely with Information Security, GRC, Legal, Privacy, Sales, and Customer Success to efficiently support customer due diligence requests while ensuring accuracy, consistency, and alignment with company security posture and contractual commitments. This is a mid-level role suited for someone who has experience supporting customer security questionnaires, audits, and evidence requests, and who is ready to operate independently within established processes while contributing to continuous improvement efforts
Your Mission
Customer Assurance & Due Diligence
- Respond to customer security questionnaires (SIG, CAIQ, custom questionnaires) and due diligence requests in a timely and accurate manner
- Provide security documentation and artifacts (e.g., SOC reports, ISO certificates, policies, architecture diagrams) to customers and prospects
- Serve as a primary point of contact for customer-facing security and compliance inquiries during sales cycles and renewals
Cross-Functional Collaboration
- Partner with Sales, Customer Success, Legal, Privacy, and GRC teams to support customer assurance needs
- Coordinate with internal control owners to validate responses and obtain evidence when needed
- Ensure responses align with contractual commitments, published documentation, and approved security messaging
Process & Knowledge Management
- Maintain and update a centralized repository of approved questionnaire responses and security artifacts
- Identify recurring customer questions and contribute to standardized responses, FAQs, and enablement materials
- Support continuous improvement initiatives to reduce manual effort and improve response quality and turnaround time
Risk Awareness & Escalation
- Identify customer requests that may introduce security, compliance, or contractual risk and escalate appropriately
- Apply sound judgment when handling non-standard or high-risk customer requests
You Are/Have
- 2–4 years of experience in Information Security, GRC, Customer Assurance, Risk Management, or Compliance
- Hands-on experience responding to customer security questionnaires and audit requests
- Familiarity with common security frameworks and standards (e.g., SOC 2, ISO 27001, NIST, PCI DSS, HIPAA)
- Strong written communication skills with the ability to translate technical concepts for non-technical audiences
- Ability to manage multiple requests simultaneously in a fast-paced environment
- Experience in a SaaS or cloud-based environment
- Familiarity with tools such as GRC platforms, CRM systems (e.g., Salesforce), or customer assurance portals
- Understanding of data protection and privacy concepts (e.g., GDPR, CCPA)
- Experience supporting sales cycles or customer-facing teams
Similar Jobs
Linxon
Application Engineering Manager
Linxon
Application Security Lead
Synchrony Financial
Sr. Analyst, SOX IT Testing (L09)
Western Union
Information Security & Resilience Risk Senior Manager
Nasdaq
Physical Security - Controls Management & Training
Integer Holdings