Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

GRC Analyst II

Payscale
CompanyPayscale
CategoryLegal & Compliance
LocationRemote-Canada
RemoteRemote
EmploymentNot stated
LevelMid
SalaryUSD 63k
Posted15 Jul 2026
Last verified7 Aug 2026
SourceEmployer ATS (ashby)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
ABOUT PAYSCALE Payscale is the pioneer of compensation intelligence, helping organizations make smarter pay decisions that drive business performance. For more than 20 years, Payscale has combined trusted market data with AI-powered technology to deliver actionable insights that turn pay from a cost into a catalyst for growth. The Payscale Intelligence Cloud portfolio of solutions — Ascent, JobNav, and Paycycle — empower top companies and businesses like Cintas, Leidos, Chipotle, Ohio State University, and TJX Companies. Create confidence in your compensation. Payscale. To learn more, visit www.payscale.com http://www.payscale.com. Job Summary Payscale is looking for a GRC Analyst II to join our Information Security Team, reporting to the Manager of GRC. In this role, you will take on broader ownership of core GRC program areas while supporting senior-level initiatives across risk, audit, and compliance. The ideal candidate brings hands-on GRC experience, strong communication skills, and the ability to operate independently across technical and business stakeholders to drive compliance and risk outcomes. What You'll Do - Maintain Payscale's data classification program, including classification schema, tagging standards, and coordination with data owners to ensure accurate and consistent classification across systems and assets - Maintain the system classification and ownership inventory, partnering with teams to ensure systems are properly classified, attributed, and reviewed on a defined cadence - Support audit coordination activities for SOC 2 and other compliance frameworks. - Conduct vendor security assessments reviews. - Manage the policy management lifecycle, including drafting new policies and standards, tracking review cycles, coordinating approvals, and maintaining version control. - Identify control gaps or process improvement opportunities and partner with business units to implement and sustain effective controls. What We're Looking For - Bachelor's degree in cybersecurity, information systems, or a related field - 2-4 years of work experience in GRC, information security, or a related field within a commercial SaaS or software company - Working knowledge of information security control frameworks such as SOC 2, ISO 27001, NIST 800-53, or CIS - Demonstrated experience with data classification frameworks and data governance concepts - Experience conducting vendor security assessments and managing third-party risk workflows - Hands-on experience with audit support activities, including evidence collection for SOC 2 or similar frameworks - Solid understanding of information security policies, standards, and procedures - Hands-on experience with GRC tools or platforms (e.g., Drata, ServiceNow GRC, or similar) - Strong written and verbal communication skills with the ability to engage both technical and non-technical stakeholders - Ability to manage multiple workstreams independently, prioritize effectively, and meet deadlines Location Payscale has an employee centric remote-first model that provides you the flexibility to do your best work in a space that supports you, while also finding time to collaborate in person for the moments that matter. In our remote-first model, employees can work from the location that works best for them. We do not have centralized corporate offices. Employees can choose to work from home, in company-paid co-working spaces, or any combination of the two that best suits their unique needs. If you work from home, we recommend ensuring that you can meet the following technology, equipment and workspace requirements: - High-Speed Internet - A stable broadband or fiber connection (satellite is highly discouraged) with a minimum speed of 100 Mbps in a dedicated workspace that has a reliable Wi-Fi signal. - Device for Multifactor Authentication (MFA/2FA) - smartphone, tablet, etc. When it matters (usually no more than a few times a year) we tak