Oh My JobFind JobsResources
Company
  • About Us
  • Blog
  • Contact
  • Career Guides
Popular Roles
  • Registered Nurse Jobs
  • Home Health Aide Jobs
  • Software Developer Jobs
  • Project Manager Jobs
  • Part-Time Jobs
Tools
  • Paycheck Calculator
  • Job Market Data
Legal
  • Terms of Service
  • Privacy Policy
  • California Privacy Rights
For Employers
Post a Job
  1. Home
  2. Jobs
  3. Senior GRC Analyst
Illustration - Senior GRC Analyst

Senior GRC Analyst

Gusto
Gusto
San Francisco, CA - Hybrid
Aug 27, 2026
Salary not listed

At a glance

  • Full time
  • Hybrid

Job Description

About Gusto

At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.


All full-time employees receive competitive base pay, benefits, and equity (RSUs) — because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about ourTotal Rewards philosophy.


AI is a fundamental part of how work gets done at Gusto. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process.

About the Role:

Gusto is seeking a Security, Governance, Risk & Compliance professional to join our team managing our security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC and related frameworks, while embedding security-minded practices throughout Gusto. This is a cross-functional role with key touchpoints in every department.

Here’s what you’ll do day-to-day:

  • Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies—particularly supporting SOC 2 and future framework adoption.
  • Own and manage trust management platforms including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it
  • Collaborate with Legal, Enterprise Applications, and Gusto counterparts to establish and maintain data governance policies (e.g., classification, retention, handling).
  • Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams.
  • Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
  • Lead interactions with external auditors and regulatory bodies during compliance assessments (e.g., SOC 2 Type 2) and oversee responses to client security assessments and due diligence requests.
  • Stay current on relevant compliance f

Gusto on Oh My Job

141 open positions right now, including 14 in California.

Apply now
Share: