Associate GRC Analyst
Kayak
| Company | Kayak |
| Category | Legal & Compliance |
| Location | Cambridge |
| Remote | Hybrid |
| Employment | Not stated |
| Level | Entry |
| Salary | Not stated by the employer |
| Posted | 29 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (ashby) |
Description
KAYAK, part of Booking Holdings (NASDAQ: BKNG), is a leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car and vacation package. We're also transforming business travel with a new corporate travel solution, KAYAK for Business.
As an employee of KAYAK, you will be part of a travel company that operates a portfolio of global metasearch brands including momondo, Cheapflights and HotelsCombined, among others. From start-up to industry leader, innovation is in our DNA and every employee has an opportunity to make their mark. Our focus is on building the best travel search engine to make it easier for everyone to experience the world.
KAYAK is looking for a motivated Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team! This is an exciting opportunity for an early-career professional to grow within a dynamic cybersecurity and risk management environment. A great candidate has a solid foundational understanding of GRC concepts, some hands-on exposure through internships or academic projects, and a curiosity for modern approaches (such as GRC Engineering) where automation, code, and data-driven workflows are transforming traditional GRC practices.
You will work alongside an experienced team to support risk assessments, compliance activities, policy management, control monitoring, and business continuity and disaster recovery (BC/DR) efforts—while contributing to the modernization of our GRC program.
Note, this position is required to work from our Cambridge or Concord, MA office 3 days per week.
In this role you will:
- Support the execution of risk assessments, including identifying, documenting, and tracking risks across business and technology areas
- Help maintain and update policies, standards, and procedures aligned with security and compliance frameworks such as NIST CSF, SOC 2, PCI DSS, and GDPR
- Help coordinate internal and external audits by gathering evidence, tracking findings, and following up on remediation steps
- Contribute to control testing and monitoring, verifying that implemented controls are working as intended
- Maintain the risk register and support risk treatment tracking
- Assist with customer-facing security reviews, including completing security questionnaires and preparing due diligence documentation
- Support the development, maintenance, and testing of Business Continuity and Disaster Recovery plans, including Business Impact Analyses (BIAs) and recovery strategies
- Collaborate with engineering, security, and business teams to gather evidence, clarify requirements, and communicate compliance obligations
- Contribute to efforts to automate and streamline GRC processes — for example, helping to reduce manual evidence collection through scripts, APIs, or compliance platform integrations
- Stay current on regulatory changes, emerging frameworks, and evolving approaches to governance and compliance
Please apply if you have:
- A bachelor's degree in a relevant field (such as cybersecurity, information systems, computer science, risk management, or business) — or equivalent practical experience, training, or transferable skills
- A foundational understanding of GRC concepts, including risk management, controls, compliance frameworks, and audit processes
- Basic familiarity with Business Continuity and Disaster Recovery principles, including concepts like Business Impact Analyses, recovery time objectives, and recovery point objectives
- Some familiarity with at least one major security or compliance framework (such as NIST CSF, SOC 2, or PCI DSS)
- Experience in a GRC, cybersecurity, internal audit, IT risk, or business continuity context — paid, academic, capstone, or volunteer experience is all considered
- Clear written and verbal communication skills, including the ability to explain risk and compliance concepts to a range of audiences
- Strong o
991,236 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →