Mid-Senior Information Security Analyst - Remote GRC Role
About the Role
We’re hiring a Mid-Senior Information Security Analyst to join XBOW, a pioneering company in the cybersecurity space. This remote role focuses on Governance, Risk & Compliance (GRC), where you will play a crucial part in scaling our security and trust function. As an Information Security Analyst, you will support customer and prospect security reviews, assess third-party vendor risk, and continuously improve our risk management processes.
What You'll Do
- Support customers and prospects by completing technical security questionnaires, risk assessments, and due diligence requests.
- Partner with Sales and Customer teams to explain XBOW’s security controls, architecture, and compliance posture.
- Assess and manage third-party and vendor security risk, including reviews of SaaS providers and service partners.
- Help maintain and improve risk assessment frameworks, methodologies, and documentation.
- Track and support remediation of identified risks in collaboration with internal stakeholders.
- Contribute to compliance initiatives aligned with frameworks such as SOC 2 and ISO 27001.
- Maintain clear, well-structured risk registers, policies, and supporting evidence.
- Coordinate risk management sessions and processes.
- Identify opportunities to streamline and automate risk and compliance processes as the company scales.
- Support audits, customer reviews, and internal assurance activities as needed.
Requirements
- 3–5+ years of experience in risk, compliance, security assurance, or related roles.
- Hands-on experience completing or reviewing technical security questionnaires and customer risk assessments.
- Familiarity with common security and compliance frameworks (e.g., SOC 2, ISO 27001, NIST, FedRAMP).
- Comfortable assessing technical controls and working with engineers to understand system architecture.
- Experience conducting or supporting vendor/third-party risk assessments.
- Strong written communication skills, with the ability to explain complex security concepts clearly.
- Highly organized and detail-oriented, with a pragmatic approach to risk.
- Comfortable working in a fast-moving, remote-first startup environment.
Nice to Have
- Experience working in a SaaS or security-focused company.
- Security or risk certifications (e.g., CRISC, SOC2, ISO 27001 Lead Implementer, FedRAMP).
- Experience supporting a company through audit readiness or first-time compliance efforts.
What We Offer
- Competitive salary and meaningful stock options.
- Opportunity to learn from and collaborate with top security and AI experts.
- Work on complex technical challenges that support the foundation of our company.
- Remote-first work environment with regular opportunities to meet in person.
What Else You Should Know
This is a full-time remote position, preferably for candidates located on the US East Coast. Join us in shaping the next frontier of autonomous security!
This role offers a unique opportunity to work in a cutting-edge cybersecurity company that leverages AI technology. The chance to grow within the organization and work remotely adds to its appeal.
About XBOW
Explore career opportunities at XBOW in 2026. Discover a range of remote, hybrid, and office roles tailored to your skills. Utilize advanced filters, application tracking, and company insights to streamline your job search. Stay updated with industry news and vacancy scores to find your ideal XBOW position. Start your journey to a fulfilling career at XBOW today!
Who Will Succeed Here
Strong understanding of Governance, Risk Management, and Compliance frameworks, particularly ISO 27001 and SOC 2, with the ability to implement these standards effectively in a remote setting.
Proficient in conducting technical security questionnaires and vendor risk assessments, showcasing analytical skills and attention to detail, essential for remote collaboration with cross-functional teams.
Experience with continuous improvement methodologies in risk management processes, demonstrating a proactive mindset and adaptability to evolving security landscapes.
Learning Resources
Career Path
Market Overview
Skills & Requirements
Domain Trends
Industry News
Loading latest industry news...
Finding relevant articles from the last 6 months