Security GRC Analyst II
Job Summary
Heres a summary of the role:
Every enterprise deal reaches the moment where someone in security says prove it. Youre the person who answers quickly accurately and with the evidence to back it up.
As an Analyst II on our Trust & Assurance team youll own a live queue of security questionnaires third-party due diligence assessments RFP security sections and customer assurance requests. Youll draft at speed using AI-assisted response tooling then verify every answer against our approved answer library current SOC 2 and ISO 27001 certifications and the underlying evidence before it leaves your hands. Accuracy is the whole game here: a wrong answer in a customer questionnaire is a commitment we didnt mean to make.
The best part is that you wont just work the queue youll shrink it. Every recurring question you turn into a published answer on our trust site is a ticket that never comes back. If youve spent two to four years in security GRC compliance IT audit or customer assurance youre precise under volume and you like being measured on turnaround time and first-pass accuracy youll do well here.
Heres a breakdown of what youll do (not all of it just the important stuff):
- Own a high-volume queue of security questionnaires due diligence assessments RFP security sections and assurance requests delivering accurate responses within SLA.
- Use AI-assisted response tooling to draft at speed then verify every answer against the approved answer library current certifications and underlying evidence before it goes out.
- Triage and route incoming requests using established playbooks resolving the routine independently and escalating anything novel contractual or architecturally complex.
- Maintain and expand the answer library by adding approved answers retiring stale ones and flagging inconsistencies so the same question never has to be researched twice.
- Build out trust site and customer-facing content and show commercial teams how to point customers there turning recurring questions into self-serve answers.
- Package evidence for customer security audits and track quality and throughput metrics (turnaround first-pass accuracy rework deflection) to find and fix friction in the process.
These are the essentials youll need to get an interview:
- 24 years in security GRC compliance IT audit customer assurance or a closely related function.
- Working knowledge of SOC 2 and ISO 27001 and the ability to read a control and understand what it actually requires.
- Demonstrable precision under volume a track record in SLA-driven or queue-based work where accuracy mattered and was measured.
- Strong written English with the ability to answer a security question precisely and concisely without padding.
- Solid organisational habits: you can manage a queue of competing requests without losing track of any of them.
- Comfort working with AI-assisted tooling paired with healthy scepticism you treat generated output as a draft to verify never an answer to forward.
- The discipline to escalate rather than guess and the confidence to say this is outside what I can answer.
It would be great if you had these to but well support you if you dont:
- Experience with a trust centre or trust portal platform for example SafeBase Whistic Conveyor or Vanta.
- Familiarity with questionnaire formats and frameworks such as SIG CAIQ HECVAT or VSAQ.
- Basic working knowledge of AWS Azure or GCP security concepts enough to understand the answers youre verifying.
- Exposure to additional frameworks such as NIST CSF GDPR HIPAA or DORA.
- Early-career certifications or progress toward them ISO 27001 Foundation or Lead Implementer CompTIA Security or CISA.
- Experience with Jira Confluence Salesforce and Microsoft 365.
- Additional language skills particularly for supporting customers across EMEA.
About Us
Diligent is the AI leader in governance risk and compliance (GRC) SaaS solutions helping more than 1 million users and 700000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners the C-Suite and the board a consolidated view of their entire GRC practice so they can more effectively manage risk build greater resilience and make better decisions faster.
Learn more or follow us onLinkedInandFacebook
What Diligent Offers You
- Creativity is ingrained in our culture. We are innovative collaborators by nature. We thrive in exploring how things can be differently both in our internal processes and to help our clients
- We care about our people.Diligent offers a flexible work environment global days of service comprehensive health benefits meeting free days generous time off policy and wellness programsto name a few
- We have teams all over the world. We may be headquartered in New York City but we have office hubs in Washington D.C. Vancouver London Galway Budapest Munich Bengaluru Singapore and Sydney.
- Diversity is important to us. Growing maintaining and promoting a diverse team is a top priority for us. We foster and encourage diversity through our Employee Resource Groups and provide access to resources and education to support the education of our team facilitate dialogue and foster understanding.
Diligent created the modern governance movement. Our world-changing idea is to empower leaders with the technology insights and connections they need to drive greater impact and accountability to lead with purpose. Our employees are passionate smart and creative people who not only want to help build the software company of the future but who want to make the world a more sustainable equitable and better place.
Headquartered in New York Diligent has offices in Washington D.C. London Galway Budapest Vancouver Bengaluru Munich Singapore and Sydney. To foster strong collaboration and connection this role will follow a hybrid work model. If you are within a commuting distance to one of our Diligent office locations you will be expected towork onsite at least 50% of the time.We believe that in-person engagement helps drive innovation teamwork and a strong sense of community.
Diligent is proud to be an equal opportunity employer. We do not discriminate based on race color religious creed sex national origin ancestry citizenship status pregnancy childbirth physical disability mental disability age military status protected veteran status marital status registered domestic partner or civil union status gender (including sex stereotyping and gender identity or expression) medical condition (including but not limited to cancer related or HIV/AIDS related) genetic information or sexual orientation in accordance with applicable federal state and local also consider qualified applicants regardless of criminal histories consistent with legal requirements. See alsoDiligentsEEO PolicyandUS EEOCs Know Your Rights. We are a drug free workplace.
We are committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability you may contact us at
Required Experience:
IC
About Company
Diligent, a modern governance company, is the only comprehensive governance software provider featuring tools to improve and simplify modern day governance.