Roadie Logo

Roadie

GRC Analyst

Posted 26 Days Ago
Easy Apply
Remote
Hiring Remotely in USA
Mid level
Easy Apply
Remote
Hiring Remotely in USA
Mid level
The GRC Analyst at Roadie manages governance, risk, and compliance programs, ensuring HIPAA and SOC2 compliance through audits, risk assessments, and policy development.
The summary above was generated by AI

Roadie, a UPS company, is a leading logistics and delivery platform that helps businesses tackle the complexities of modern retail with unmatched delivery coverage, flexibility and visibility. Reaching 97% of U.S. households across more than 30,000 zip codes — from urban hubs to rural communities — Roadie provides seamless, scalable solutions that meet a variety of delivery needs. 

With a network of more than 310,000 independent drivers nationwide, Roadie offers flexible delivery solutions that make complex logistics challenges easy, including solutions for local same-day delivery, delivery of big and bulky items, ship-from-store and DC-to-door.

 

Under the supervision of the Lead Information Security Engineer, the GRC Analyst is responsible for establishing, maintaining, and continuously improving Roadie’s governance, risk, and compliance program to ensure the confidentiality, integrity, availability, and safety of information systems and data. This role supports compliance efforts for HIPAA and SOC2, performs risk assessments across systems, applications, and vendors, and translates regulatory and security requirements into practical, auditable controls. The GRC Analyst partners closely with Engineering, Product, Legal, Information Security, and Operations teams to embed security and privacy-by-design into processes and application development while supporting audits, evidence management, and ongoing risk remediation.

What You’ll Do

  • Support and conduct audits to ensure compliance with Roadie directives, and regulatory frameworks including HIPAA and SOC2
  • Develop, maintain, and update policies, procedures, and documentation
  • Prepare and manage audit evidence, findings, and remediation tracking
  • Coordinate with external auditors and internal control owners throughout the audit process
  • Identify compliance gaps and support risk treatment and corrective action plans
  • Perform risk assessments across systems, applications, and vendors
  • Advise teams on security and privacy requirements in system and application design
  • Stay current on regulatory standards, compliance requirements, and industry best practices
  • Support security and compliance awareness through training and guidance
  • Communicate compliance status, risks, and mitigation strategies to stakeholders

What You Bring

  • 4+ years of experience in GRC, information security, or compliance, with hands-on audit and risk management experience
  • Working knowledge of HIPAA, SOC2, and applicable federal and state regulatory requirements
  • Experience translating regulatory and contractual requirements into policies, controls, and evidence
  • Strong understanding of risk assessment methodologies, control frameworks, and governance best practices
  • Ability to collaborate with technical teams to embed security and privacy requirements into systems and application design
  • Experience managing audits and working directly with external auditors
  • Excellent analytical, documentation, and stakeholder communication skills
  • Relevant certifications such as CISA, CRISC, CISSP
  • Experience with ISO, Cloud Infrastructure, and Application Development preferred

Why Roadie? 

  • Competitive total rewards package
  • 100% company-paid health insurance for yourself
  • 401(k) with company match
  • Tuition & student loan repayment assistance- yes, we’ll contribute directly to your student loans!
  • Remote-first environment
  • Unlimited PTO
  • Inclusive family leave policy that supports all new parents
  • Paid Wellness Days in addition to Company holidays 
  • Monthly WFH stipend
  • Paid sabbatical leave- tenured Roadies are given extra time to unplug, rest, and explore
  • The technology you need to get the job done

This role is not eligible for Visa sponsorship. Applicants must be authorized to work for any employer in the U.S. 

Top Skills

Application Development
Cloud Infrastructure
Hipaa
Iso
Soc2

Similar Jobs

2 Days Ago
Remote or Hybrid
TX, USA
100K-155K Annually
Senior level
100K-155K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The Cyber GRC Senior Analyst role at CrowdStrike involves managing security policies, conducting risk assessments, collaborating with teams on security issues, and optimizing processes within the Cyber GRC framework.
Top Skills: CismCisspCriscCsa-CcmGdprIso27001Iso27002Iso27031Nist 800-53Nist Risk 800-34Pci-DssServicenowSoc1Soc2
3 Days Ago
Remote
US
87K-186K Annually
Junior
87K-186K Annually
Junior
Artificial Intelligence • Information Technology • Software
The GRC Analyst will evaluate and document security risks, manage controls, support compliance processes, and automate compliance monitoring.
Top Skills: AWSCis ControlsCsa CcmFedrampGrc ToolsHitrustIso 27001Nist 800-171Nist 800-53Nist CsfOciPam ToolsPci DssSIEMSoc 1Soc 2Vulnerability Scanning Solutions
6 Days Ago
Easy Apply
Remote
Arizona, USA
Easy Apply
73K-108K Annually
Junior
73K-108K Annually
Junior
Legal Tech
Assist in risk identification and monitoring, governance support, compliance alignment, and operational support while collaborating with security leadership and cross-functional teams.
Top Skills: CcpaCobitCrq ToolsGdprGrc ToolsIso 27001Nist CsfSoc2

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account