Roadie Logo

Roadie

GRC Analyst

Reposted 18 Hours Ago
Easy Apply
Remote
Hiring Remotely in USA
Mid level
Easy Apply
Remote
Hiring Remotely in USA
Mid level
The GRC Analyst at Roadie manages governance, risk, and compliance programs, ensuring HIPAA and SOC2 compliance through audits, risk assessments, and policy development.
The summary above was generated by AI

Roadie, a UPS company, is a leading logistics and delivery platform that helps businesses tackle the complexities of modern retail with unmatched delivery coverage, flexibility and visibility. Reaching 97% of U.S. households across more than 30,000 zip codes — from urban hubs to rural communities — Roadie provides seamless, scalable solutions that meet a variety of delivery needs. 

With a network of more than 310,000 independent drivers nationwide, Roadie offers flexible delivery solutions that make complex logistics challenges easy, including solutions for local same-day delivery, delivery of big and bulky items, ship-from-store and DC-to-door.

 

Under the supervision of the Lead Information Security Engineer, the GRC Analyst is responsible for establishing, maintaining, and continuously improving Roadie’s governance, risk, and compliance program to ensure the confidentiality, integrity, availability, and safety of information systems and data. This role supports compliance efforts for HIPAA and SOC2, performs risk assessments across systems, applications, and vendors, and translates regulatory and security requirements into practical, auditable controls. The GRC Analyst partners closely with Engineering, Product, Legal, Information Security, and Operations teams to embed security and privacy-by-design into processes and application development while supporting audits, evidence management, and ongoing risk remediation.

What You’ll Do

  • Support and conduct audits to ensure compliance with Roadie directives, and regulatory frameworks including HIPAA and SOC2
  • Develop, maintain, and update policies, procedures, and documentation
  • Prepare and manage audit evidence, findings, and remediation tracking
  • Coordinate with external auditors and internal control owners throughout the audit process
  • Identify compliance gaps and support risk treatment and corrective action plans
  • Perform risk assessments across systems, applications, and vendors
  • Advise teams on security and privacy requirements in system and application design
  • Stay current on regulatory standards, compliance requirements, and industry best practices
  • Support security and compliance awareness through training and guidance
  • Communicate compliance status, risks, and mitigation strategies to stakeholders

What You Bring

  • 4+ years of experience in GRC, information security, or compliance, with hands-on audit and risk management experience
  • Working knowledge of HIPAA, SOC2, and applicable federal and state regulatory requirements
  • Experience translating regulatory and contractual requirements into policies, controls, and evidence
  • Strong understanding of risk assessment methodologies, control frameworks, and governance best practices
  • Ability to collaborate with technical teams to embed security and privacy requirements into systems and application design
  • Experience managing audits and working directly with external auditors
  • Excellent analytical, documentation, and stakeholder communication skills
  • Relevant certifications such as CISA, CRISC, CISSP
  • Experience with ISO, Cloud Infrastructure, and Application Development preferred

Why Roadie? 

  • Competitive total rewards package
  • 100% company-paid health insurance for yourself
  • 401(k) with company match
  • Tuition & student loan repayment assistance- yes, we’ll contribute directly to your student loans!
  • Remote-first environment
  • Unlimited PTO
  • Inclusive family leave policy that supports all new parents
  • Paid Wellness Days in addition to Company holidays 
  • Monthly WFH stipend
  • Paid sabbatical leave- tenured Roadies are given extra time to unplug, rest, and explore
  • The technology you need to get the job done

This role is not eligible for Visa sponsorship. Applicants must be authorized to work for any employer in the U.S. 

Top Skills

Application Development
Cloud Infrastructure
Hipaa
Iso
Soc2

Similar Jobs

2 Days Ago
Remote or Hybrid
TX, USA
100K-155K Annually
Senior level
100K-155K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Cyber GRC Senior Analyst role at CrowdStrike involves managing security policies, conducting risk assessments, collaborating with teams on security issues, and optimizing processes within the Cyber GRC framework.
Top Skills: CismCisspCriscCsa-CcmGdprIso27001Iso27002Iso27031Nist 800-53Nist Risk 800-34Pci-DssServicenowSoc1Soc2
3 Hours Ago
Remote
US
87K-186K Annually
Junior
87K-186K Annually
Junior
Artificial Intelligence • Information Technology • Software
The GRC Analyst will evaluate and document security risks, manage controls, support compliance processes, and automate compliance monitoring.
Top Skills: AWSCis ControlsCsa CcmFedrampGrc ToolsHitrustIso 27001Nist 800-171Nist 800-53Nist CsfOciPam ToolsPci DssSIEMSoc 1Soc 2Vulnerability Scanning Solutions
6 Days Ago
Easy Apply
Remote
Arizona, USA
Easy Apply
73K-108K Annually
Junior
73K-108K Annually
Junior
Legal Tech
Assist in risk identification and monitoring, governance support, compliance alignment, and operational support while collaborating with security leadership and cross-functional teams.
Top Skills: CcpaCobitCrq ToolsGdprGrc ToolsIso 27001Nist CsfSoc2

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account