Senior GRC Analyst at Pax8
Denver, Colorado, USA -
Full Time


Start Date

Immediate

Expiry Date

30 Jun, 25

Salary

125000.0

Posted On

13 Jun, 25

Experience

3 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Good communication skills

Industry

Financial Services

Description

Pax8 is the leading cloud-based technology marketplace, simplifying the cloud journey for our partners by integrating technology, business intelligence and proactive service to deliver an unparalleled experience. Serving thousands of partners through the indirect sales channel, our mission is to build the technology marketplace of the future. We are a fast-growing, dynamic and high-energy startup organization, allowing you to make a meaningful impact on the business. Culture is important to us, and at Pax8, it’s business, and it IS personal. We are passionate, creative and humorously offbeat. We work hard, keep it fun, and expect the best.
We Elev8 each other. We Advoc8 for our partners. We Innov8 continuously. We Celebr8 life.
No matter who you are, Pax8 is a place you can call home. We know there’s no such thing as a “perfect” candidate, so we don’t look for the right “fit” – instead, we look for the add. We encourage you to apply for a role at Pax8 even if you don’t meet 100% of the bullet points. We believe in cultivating an environment with a diversity of perspectives, in hopes that we can all thrive in an inclusive environment.
We are only as great as our people. And we have great people all over the world. No matter where you live and work, you’re a part of the Pax8 team. This means embracing hybrid- and remote-work whenever possible.

POSITION SUMMARY:

We are seeking a detail-oriented and proactive Senior Technology Governance, Risk, and Compliance (GRC) Analyst to join our growing organization. In this role, you will play a critical part in safeguarding our cloud-based platforms by identifying and managing technology risks, supporting compliance initiatives, and ensuring the effectiveness of security controls. You will collaborate cross-functionally with teams across engineering, security, technology services, legal, and customer success to maintain our compliance posture, support audits, and drive continuous improvement in our GRC program.
The ideal candidate has a strong understanding of cloud-native technologies, SaaS delivery models, and regulatory frameworks such as SOC 2, ISO 27001, and GDPR. This role requires a mix of analytical rigor, technical acumen, and business judgment to help scale and mature our risk and compliance functions in a dynamic, fast-paced environment.

IDEAL SKILLS, EXPERIENCE, AND COMPETENCIES:

  • 3-5 years in a technology GRC role.
  • Technical background with a focus on SaaS and multi-tenant cloud platforms highly preferred.
  • Proven experience in running assessments and/or audits with demonstratable track record of driving improvements.

REQUIRED EDUCATION & CERTIFICATIONS:

  • B.A./B.S. in a related field or equivalent work experience.
Responsibilities
  • Conduct regular IT risk assessments to identify and mitigate technology and cybersecurity risks in a SaaS environment.
  • Perform control assessments to ensure alignment with internal policies, regulatory requirements, and industry standards (e.g., ISO 27001, NIST, SOC 2).
  • Maintain and update the GRC framework, ensuring it supports strategic business objectives and regulatory compliance for a cloud-native environment and DevSecOps practices.
  • Coordinate and support internal and external IT audits, including evidence collection, walkthroughs, and remediation tracking.
  • Facilitate and monitor the completion of risk treatment plans, working with business units to implement mitigation strategies.
  • Lead or support the incident response process, including documentation, root cause analysis, and post-incident reviews. Includes on-call Incident Commander rotation (approximately 1 out of 6 weeks).
  • Maintain the risk register, ensuring accurate and up-to-date records of all identified risks and mitigation actions.
  • Develop and deliver GRC training and awareness programs for staff, promoting a culture of risk-conscious behavior.
  • Track and report compliance metrics, risk trends, and audit findings to key stakeholders and leadership.
  • Collaborate with IT, security, legal, and business teams to assess and manage third-party/vendor risks.
  • Ensure timely updates and maintenance of policies, standards, and procedures related to IT risk and compliance.
  • Monitor and interpret emerging regulations and industry best practices, recommending changes to the GRC program as needed.
  • Participate in the development of business continuity and disaster recovery plans, ensuring alignment with risk management objectives.
  • Utilize GRC tools and platforms to streamline risk, compliance, and audit processes.
  • Provide ongoing support for special projects and initiatives related to cybersecurity, data privacy, and regulatory compliance.
Loading...