Nametag Logo

Nametag

Senior GRC Analyst

Posted Yesterday
Be an Early Applicant
Easy Apply
Remote
Hiring Remotely in USA
120K-160K Annually
Senior level
Easy Apply
Remote
Hiring Remotely in USA
120K-160K Annually
Senior level
The Senior GRC Analyst will manage the security and compliance program, maintain SOC 2 certification, coordinate penetration tests, and ensure compliance initiatives support business goals.
The summary above was generated by AI

Nametag is building the future of secure digital identity. Our mission is to make it easy for people and organizations to prove who they are online - safely and seamlessly. We’re pioneering next-generation identity verification and account protection so that users can control their own identity, and companies can build trust without friction.

About the Role

Nametag is seeking an experienced Senior GRC Analyst to own and evolve our security and compliance program. This role is ideal for someone who thrives in a fast-paced startup environment, has deep experience with SOC 2 and other compliance frameworks, and is comfortable building and running programs with limited resources. You will report directly to the Head of Engineering and partner closely with the engineering team to ensure security is built into everything we do.

As a Senior GRC Analyst, you will own the entire security and compliance function as an individual contributor, maintaining our existing certifications, driving new compliance initiatives, coordinating penetration tests, and building trust with customers and prospects. You will work closely with engineering, product, sales, and customer success to ensure security enables the business rather than blocking it.

What You'll Do

Compliance Program Management

  • Own and maintain SOC 2 Type II certification, including evidence collection, control monitoring, and audit coordination
  • Drive IAL3 compliance readiness and implementation
  • Manage accessibility compliance (WCAG) requirements
  • Identify and pursue additional certifications as needed based on customer and market requirements

Security Operations

  • Coordinate penetration testing cycles and drive remediation with engineering
  • Maintain a living view of organizational risk and surface it to leadership
  • Develop and maintain security policies, procedures, and controls
  • Respond to security incidents with speed and clarity

Customer Trust

  • Respond to customer security questionnaires promptly and accurately
  • Support sales in security-sensitive enterprise deals
  • Maintain public-facing trust documentation
  • Participate in customer security calls and reviews as needed

Cross-Functional Partnership

  • Partner with engineering to build security into the development process
  • Provide clear security guidance and timely reviews so teams can ship with confidence
  • Collaborate with product on security and accessibility features
  • Work with customer success to address customer security concerns

Ideal Qualifications

We know that no candidate will perfectly match every requirement, and that's okay. If you're passionate about what we're building and have most of the skills below, we'd love to hear from you.

  • 5+ years of experience in security, compliance, or GRC, with demonstrated hands-on ownership of SOC 2 Type II programs
  • Experience building or running compliance programs in startup or resource-constrained environments
  • Strong understanding of how auditors think, ideally from auditor-side experience or running multiple audit cycles
  • Technical fluency to read pen test reports, understand cloud architecture, and have informed conversations with engineers
  • Knowledge of GRC tooling and vendors, with opinions on what's worth investing in at different company stages
  • Excellent communication skills, able to translate security topics for executives, salespeople, and customers
  • Experience with identity verification, authentication, or security-focused products is a strong plus
  • Familiarity with IAL2/IAL3 or NIST 800-63 identity proofing standards is a strong plus
  • CISSP, ISO 27001 Lead Auditor, or similar certifications are a plus but not required

What We Value

  • Intellectual horsepower: quickly grasping complex technical and business concepts
  • Kindness and integrity: earning trust is central to how we build relationships with customers and colleagues
  • Bias for action: we move quickly to deliver impact and protect our customers against fast-moving threats

Compensation

The base salary range for this full-time position is $120,000-$160,000, plus equity and benefits.

Nametag is a founding member of the Open Imperative, publicly committed to pay equity in the technology industry. We post positions with ranges to encourage people of different backgrounds and experiences to apply. Every offer is benchmarked against market data to ensure fairness and consistency.

Final compensation is determined by role, level, and additional factors such as skills, experience, and education. Your recruiter or hiring manager can share more details during the hiring process.

Culture & Perks

At Nametag, we believe trust starts with how we treat each other. We are a remote-first team that values autonomy, inclusivity, and collaboration, with regular in-person time to stay connected and innovate together.

  • Remote-first: Work from anywhere in the US. Our team spans Seattle, San Francisco, Ann Arbor, Denver, New York City, and beyond
  • Quarterly off-sites: We bring the team together once per quarter for in-person collaboration, often off-site in new places
  • Flexible schedules: Work in your own time zone; we align key meetings across a shared window

We Offer

  • Competitive salary
  • Meaningful equity ownership
  • Comprehensive health benefits (medical, dental, vision)
  • Flexible paid time off
  • Quarterly team off-sites and travel support
  • New computer hardware and equipment
  • An inclusive environment where your voice has impact and your work drives change

Top Skills

Grc Tooling
Ial2/Ial3
Nist 800-63
Soc 2

Similar Jobs

21 Days Ago
Remote
United States
135K-190K Annually
Senior level
135K-190K Annually
Senior level
Fintech • Real Estate • Software
Lead and scale the company GRC program: maintain compliance certifications (SOC2, ISO 27001), run audits, manage policies, training, phishing, risk registers, and third-party risk assessments while supporting customer trust and cross-functional stakeholders.
Top Skills: Grc FrameworksIso 27001Soc2
2 Days Ago
Remote or Hybrid
TX, USA
100K-155K Annually
Senior level
100K-155K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Cyber GRC Senior Analyst role at CrowdStrike involves managing security policies, conducting risk assessments, collaborating with teams on security issues, and optimizing processes within the Cyber GRC framework.
Top Skills: CismCisspCriscCsa-CcmGdprIso27001Iso27002Iso27031Nist 800-53Nist Risk 800-34Pci-DssServicenowSoc1Soc2
3 Days Ago
Easy Apply
Remote
USA
Easy Apply
Senior level
Senior level
Internet of Things
Lead the development of a Governance, Risk, and Compliance framework, ensuring regulatory compliance and risk management across Mozilla's products and enterprise sectors.
Top Skills: Bi ToolsCcpaGdprIsoNistSeimSoc2

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account