Senior GRC Analyst I, SOC 1 & SOC 2
This role works across both platform-enabled (e.g., Drata, Vanta) and traditional audit environments, requiring adaptability in leveraging automated evidence as well as performing manual audit procedures. The Senior GRC Auditor I will build strong client relationships through a deep understanding of client systems, technology environments, and compliance requirements, while effectively communicating audit findings and recommendations.
- Lead and conduct detailed external audits of clients' business processes and IT controls, ensuring compliance with industry standards and regulations.
- Observe, review, document, and test key business process transactions, access controls, change management controls, operational and organizational controls, and automated controls for engagements
- Review, document, evaluate and test application controls, particularly automated controls on a wide range of systems and software applications across a wide variety of client business processes
- Evaluate clients' business, IT, and security risks, identifying areas of concern and recommending appropriate control measures and process improvements to mitigate risks.
- Assess security policies and procedures, reviewing risk management / risk assessment documentation, and controls of our clients’ business applications, networks, operating systems, and other components of their technology infrastructure
- Support internal and external security assessments of new and existing services and infrastructure including operational, regulatory, and contractual requirements
- Develop and nurture strong relationships with clients, gaining insight into their businesses, risks, and compliance
- Bachelor’s degree required
- 3+ years of IT Audit experience or Audit experience
- Experience leading SOC 1 & SOC 2 audits
- Experience with controls reviews along with recommending, designing and advising on applicable IT controls
- Experience teaching, training, mentoring other staff members is preferred
- Relevant professional designation such as CISA, CISSP, CIPP, etc. is a plus
- Experience with SOC 2 readiness platforms (e.g., Drata, Vanta, etc.) is preferred
- Experience leading SOC 1s and developing SOC 1 controls around financial reporting and business processing
- US Payzone 1: $80,800 - $101,000
- US Payzone 2: $73,600 - $92,000
- US Payzone 3: $66,400 - $83,000
There are many reasons to join the Sensiba team: generous benefits, competitive compensation, professional advancement opportunities, and above all — our people. If you're looking for an environment that offers you growth, success, and professionalism without compromising your family, passions, and life outside of work, apply today!
- Comprehensive Health Coverage – Medical, dental, and vision.
- Retirement & Financial Planning Support – 401(k) with match, financial wellness programs.
- Generous Paid Time Off – Vacation, sick time, holidays, parental leave and volunteer days.
- Flexible Work Arrangements – Hybrid or remote options, flexible hours.
- Performance-Based Bonus – Recognition for your contributions through discretionary bonuses.
- Professional Development Opportunities – Tuition reimbursement, certifications, mentorship.
- Career Growth & Internal Mobility – Clear paths for advancement and role transitions.
- Inclusive & Supportive Culture – DEI initiatives, employee resource groups, wellness programs.