- Company Name
- Cohere
- Job Title
- GRC Analyst
- Job Description
-
**Job title:** GRC Analyst
**Role Summary:**
Drive governance, risk, and compliance for enterprise AI solutions. Manage security and data privacy controls, support audits, and collaborate across engineering, security, legal, and business units to uphold regulatory and industry standards. Act as trusted advisor on risks, documentation, and continuous improvement of the GRC program.
**Expectations:**
- One year or more of GRC experience in technology or SaaS environments.
- Strong ability to write and maintain technical security policies, procedures and standards.
- Familiarity with NIST, ISO 27001, SOC 2, HIPAA, GDPR, CCPA and emerging AI regulations.
- Ability to automate routine GRC tasks using scripting (Python, PowerShell).
- Excellent written and verbal communication, translating complex compliance concepts for all audiences.
- Comfortable operating in ambiguous, fast‑changing regulatory landscapes.
**Key Responsibilities:**
- Design, implement, and continually enhance the organization’s GRC framework.
- Align security controls with industry standards (NIST 800‑171, ISO 27001, SOC 2) and regulatory requirements.
- Develop and implement risk controls specific to AI and data‑processing environments.
- Execute internal audits and control assessments; document findings and remediation plans.
- Conduct third‑party risk evaluations and coordinate risk mitigation across vendors and partners.
- Maintain and update GRC documentation, ensuring policies, standards, and procedures reflect current practices.
- Identify, assess, track, and report risks; strengthen the overall risk management program.
- Respond to inquiries from customers, auditors, and partners regarding security and compliance.
- Monitor emerging regulations and industry trends; recommend adjustments to the GRC program.
- Collect, analyze, and report GRC metrics to leadership, providing actionable insights.
**Required Skills:**
- GRC program development and maintenance.
- Knowledge of security frameworks (NIST, ISO, SOC, HIPAA, GDPR, CCPA, EU AI Act).
- Cloud security concepts and AI/data‑centric threat modeling.
- Technical writing of policies, procedures, and standards.
- Basic scripting (Python or PowerShell) for process automation.
- Strong analytical, problem‑solving, and decision‑making under uncertainty.
- Clear communication with technical and non‑technical stakeholders.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Risk Management, or related field.
- Professional certifications (e.g., CISSP, CISA, CISM, ISO 27001 Lead Implementer) preferred but not mandatory.