XBOW26.01.26
AI SCORE 8.5

Mid-Senior Information Security Analyst - Remote GRC Role

$90K–$120K/year

About the Role

We’re hiring a Mid-Senior Information Security Analyst to join XBOW, a pioneering company in the cybersecurity space. This remote role focuses on Governance, Risk & Compliance (GRC), where you will play a crucial part in scaling our security and trust function. As an Information Security Analyst, you will support customer and prospect security reviews, assess third-party vendor risk, and continuously improve our risk management processes.

What You'll Do

  • Support customers and prospects by completing technical security questionnaires, risk assessments, and due diligence requests.
  • Partner with Sales and Customer teams to explain XBOW’s security controls, architecture, and compliance posture.
  • Assess and manage third-party and vendor security risk, including reviews of SaaS providers and service partners.
  • Help maintain and improve risk assessment frameworks, methodologies, and documentation.
  • Track and support remediation of identified risks in collaboration with internal stakeholders.
  • Contribute to compliance initiatives aligned with frameworks such as SOC 2 and ISO 27001.
  • Maintain clear, well-structured risk registers, policies, and supporting evidence.
  • Coordinate risk management sessions and processes.
  • Identify opportunities to streamline and automate risk and compliance processes as the company scales.
  • Support audits, customer reviews, and internal assurance activities as needed.

Requirements

  • 3–5+ years of experience in risk, compliance, security assurance, or related roles.
  • Hands-on experience completing or reviewing technical security questionnaires and customer risk assessments.
  • Familiarity with common security and compliance frameworks (e.g., SOC 2, ISO 27001, NIST, FedRAMP).
  • Comfortable assessing technical controls and working with engineers to understand system architecture.
  • Experience conducting or supporting vendor/third-party risk assessments.
  • Strong written communication skills, with the ability to explain complex security concepts clearly.
  • Highly organized and detail-oriented, with a pragmatic approach to risk.
  • Comfortable working in a fast-moving, remote-first startup environment.

Nice to Have

  • Experience working in a SaaS or security-focused company.
  • Security or risk certifications (e.g., CRISC, SOC2, ISO 27001 Lead Implementer, FedRAMP).
  • Experience supporting a company through audit readiness or first-time compliance efforts.

What We Offer

  • Competitive salary and meaningful stock options.
  • Opportunity to learn from and collaborate with top security and AI experts.
  • Work on complex technical challenges that support the foundation of our company.
  • Remote-first work environment with regular opportunities to meet in person.

What Else You Should Know

This is a full-time remote position, preferably for candidates located on the US East Coast. Join us in shaping the next frontier of autonomous security!

Why This Job8.5 of 10

This role offers a unique opportunity to work in a cutting-edge cybersecurity company that leverages AI technology. The chance to grow within the organization and work remotely adds to its appeal.

Salary Range
Required
0/1
Optional
0/1
Bonus
0/1

About XBOW

Explore career opportunities at XBOW in 2026. Discover a range of remote, hybrid, and office roles tailored to your skills. Utilize advanced filters, application tracking, and company insights to streamline your job search. Stay updated with industry news and vacancy scores to find your ideal XBOW position. Start your journey to a fulfilling career at XBOW today!

Industry
Tech
Location
Remote

Who Will Succeed Here

Strong understanding of Governance, Risk Management, and Compliance frameworks, particularly ISO 27001 and SOC 2, with the ability to implement these standards effectively in a remote setting.

Proficient in conducting technical security questionnaires and vendor risk assessments, showcasing analytical skills and attention to detail, essential for remote collaboration with cross-functional teams.

Experience with continuous improvement methodologies in risk management processes, demonstrating a proactive mindset and adaptability to evolving security landscapes.

Learning Resources

ISO 27001:2013 - Information Security Management System (ISMS) - A Complete Guidecourse

Career Path

Mid-Senior Information Security Analyst - Remote GRC Role(Now)Information Security Manager(2-4 years)Director of Information Security(5-7 years)

Market Overview

Market Size 2024
$21.6B
Annual Growth
12.5%
AI Adoption
45%
Investment in Cybersecurity
+30%
Labour Demand for GRC Roles
+25%
Avg Salary for Information Security Analyst
$95K

Skills & Requirements

Required
GovernanceRisk ManagementCompliance
Growing in Demand
Cloud Security Frameworks (e.g., CSA STAR)Automated Risk Assessment ToolsData Privacy Regulations (e.g., GDPR, CCPA)
Declining
Manual Compliance ChecklistsStatic Risk Assessment Models

Domain Trends

Increased Focus on Data Privacy
With 70% of organizations prioritizing data privacy compliance, knowledge of GDPR and CCPA is crucial for GRC roles.
Integration of AI in Risk Management
45% of companies are adopting AI tools for risk assessment, enhancing the need for analysts skilled in AI-driven security solutions.
Shift Towards Continuous Compliance
82% of organizations are transitioning to continuous compliance monitoring, creating demand for automated compliance solutions.

Industry News

Loading latest industry news...

Finding relevant articles from the last 6 months

All job postings are automatically gathered by algorithms. We do not review or verify listings, be careful when applying and do not sign-in with iCloud or Google services.