Benepass
Senior GRC Analyst
U.S Remote · Senior
Sponsorship not specified$130k-$160kDetected 63 days ago
CybersecurityComplianceProject ManagementProcess ImprovementHRISCustomer SuccessHIPAACommunicationInternal Audit
About the role
- We believe people are the most important asset to any company.
- To date, the company has raised approximately $75 million in equity capital.
- Articles - Founder Story - Jaclyn Chen - Benepass Raises $40M Series B Candidate Resources - Benepass | Candidate Resource Page - Benepass Listed on Inc.
Responsibilities
- Governance & Policy: Maintain and improve information security policies, standards, procedures, control documentation, and related governance materials.
- Policy Operations: Support policy exceptions, risk acceptances, remediation tracking, control owner follow-ups, and recurring governance workflows.
- Compliance & Audit Readiness: Support SOC 2, ISO 27001, and HITRUST readiness, audit preparation, evidence collection, auditor coordination, and audit response management.
- Control Testing: Maintain recurring evidence-gathering and control testing workflows, helping ensure controls operate consistently across the business.
- Risk Management: Support risk assessments, control gap assessments, internal reviews, and maintenance of the risk register.
- Customer Assurance: Own or support customer security questionnaires, RFP security sections, due diligence requests, and trust or compliance documentation.
- Response Libraries: Maintain reusable questionnaire content, approved responses, compliance artifacts, and customer-facing assurance materials.
- Security Awareness: Support employee security awareness programs and create clear internal guidance for policies, controls, and compliance responsibilities.
- Vendor Risk: Support vendor security reviews, third-party risk assessments, remediation tracking, risk acceptance documentation, and vendor compliance evidence.
- Maintain and improve information security policies, standards, procedures, control documentation, and related governance materials.
Requirements
- 5+ years of experience in GRC, information security compliance, IT audit, risk management, security assurance, or a closely related field.
- Working knowledge of ISO 27001/27002, HITRUST, NIST CSF, or similar security and compliance frameworks.
- Experience maintaining security policies, controls, control narratives, evidence repositories, and audit documentation.
- Experience supporting internal or external audits, including evidence collection, auditor coordination, control owner follow-up, and remediation tracking.
- Strong written communication skills, with the ability to produce clear policies, questionnaire responses, process documentation, and stakeholder updates.
- Experience responding to customer security questionnaires, RFP security sections, or due diligence requests.
- Familiarity with GRC, compliance automation, or audit management tools.
- Comfort working in a startup or fast-moving environment where processes need to be mature enough to scale without creating unnecessary friction.
- Ability to work with both technical and non-technical teams and communicate security and compliance expectations clearly.
- Experience supporting HITRUST readiness or validated assessments.
Compensation
- $130,000-160,000 + Equity
- Range(s) is subject to change. Benepass takes a number of factors into account when determining individual starting pay, including market comparables, interview performance, peer compensation, and years of experience.
- $250 WFH setup (one time)
- $150/month cell phone + internet
- We offer several team onsites a year
Benefits
- 95% coverage of medical, dental, and vision
- Fantastic benefits (of course 😃), including:
- $500/year Learning & Development Benefit
- $100/month Wellness
- $100/month Co-working and Commuter Benefit
Company info
- At Benepass we're making benefits easy. We believe people are the most important asset to any company. Traditional one-size-fits-all benefits packages no longer cut it in today's hybrid and remote-first environment. With Benepass, companies can tailor their benefits to the unique needs of their workforce.
- Through our easy-to-use and highly customizable fintech platform, People teams can implement, administer, and track the benefits that meet employees where they are. Employers design their benefits and perks plan by setting a contribution amount and eligible spend categories. Every employee has their own individual definition of wellness and needs different things to help them be their most productive, fulfilled self.
- Our Mission
- Helping companies reimagine how companies take care of their people.
- Founder Story
- Jaclyn Chen
- Benepass Raises $40M Series B
- Benepass | Candidate Resource Page
- Benepass Listed on Inc. Magazine's Best Workplaces of 2023
- At Benepass we're making benefits easy.
- Traditional one-size-fits-all benefits packages no longer cut it in today's hybrid and remote-first environment.
- With Benepass, companies can tailor their benefits to the unique needs of their workforce.
- Through our easy-to-use and highly customizable fintech platform, People teams can implement, administer, and track the benefits that meet employees where they are.
Apply directly at Benepass →Create a free account for alerts like thisView Benepass immigration profile
This listing is sourced directly from Benepass's careers page and normalized into a canonical job model.