414,045open jobs
14,190companies
59,924added this week
Browse all
Salary
$111k – $225k per year (Estimated)
Location
In office (Orem)
Seniority
Senior · 6+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Headquartered in Lehi, Utah, RainFocus is an enterprise event marketing and management platform designed to power virtual, physical, and hybrid events. The company provides a unified software suite that enables organizations to streamline event operations, manage registration and content, and capture critical attendee engagement data. By delivering real-time actionable insights and seamless digital workflows, it helps businesses optimize their event portfolios and drive personalized customer experiences worldwide.

RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst.

About RainFocus

RainFocus cares about its employees, customers, and the world in which we live. Our rapidly growing team serves Fortune 500 companies like Adobe, Cisco, IBM, Oracle, VMware, and others to prepare and execute in-person, virtual, and hybrid events across the world. Those events are delivered through our industry-disrupting software platform, with groundbreaking business intelligence, to elevate the attendee experience, streamline event operations, and accelerate marketing results. We are well-funded, growing fast, and building a company that is changing the market - it will be challenging, fun, and exciting.

About the Role

We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program - maintaining our control framework, leading risk assessments, supporting audits, and driving the program's maturity forward rather than simply maintaining the status quo. You will report directly to the CISO and have significant ownership from day one.

Key Responsibilities:

    Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory compliance frameworks, including audit prep, evidence collection, and auditor relationships.

    Manage and mature our control framework, mapping new regulations and conducting gap assessments.

    Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder interviews, risk scoring, and residual risk tracking.

    Maintain and update security policies, standards, and documentation to ensure compliance with industry best practices.

    Partner with Engineering and Security to mature vulnerability management and secrets-scanning practices, moving these from reactive to proactive, pre-deployment controls.

    Help build out and operationalize a Data Loss Prevention (DLP) program, including policy design and rollout across email, endpoint, and cloud storage.

    Grow and mature RainFocus's security awareness training program.

    Drive AI governance efforts - policy, tooling, and monitoring for approved vs. unapproved AI tool usage across the company.

    Identify and help close Shadow IT / unmanaged SaaS visibility gaps in partnership with IT.

    Collaborate with cross-functional teams to implement risk management practices and ensure compliance across the organization.

    Respond to security and privacy inquiries from clients, partners, and employees.

    Prepare and present reports on the organization's security and privacy compliance status, including program maturity and remediation progress.

    Stay abreast of emerging security threats, vulnerabilities, and compliance requirements.

Qualifications:

    Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.

    6+ years of proven experience in GRC, IT audit, information security compliance, or a related field.

    In-depth knowledge of relevant regulations, standards, and frameworks (e.g., SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and others).

    Experience running or contributing heavily to formal risk assessments - not just tracking a compliance checklist.

    Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are highly desirable.

    Familiarity with modern security tooling such as Drata, OneTrust, Vanta, etc.

    Strong analytical and problem-solving skills, with keen attention to detail.

    Excellent communication and interpersonal skills to work effectively with technical and non-technical stakeholders.

    Ability to manage multiple projects and meet deadlines in a fast-paced environment.

    Experience with cloud security and compliance frameworks is a plus.

    Experience with OneTrust or related GRC technologies is a plus.

Personal Characteristics:

    Strong work ethic and commitment to excellence.

    Ability to work independently and as part of a team.

    Excellent problem-solving and analytical skills.

    Strong communication and interpersonal skills.

    Ability to adapt to change and learn quickly.

    Passion for security and privacy.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
414,045 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Orem
$13k per year (net) • In office • Full-Time • 3+ years exp • Moscow
DevOps
VMWare
Chips/EDA
Altium Designer
Design
SolidWorks
AutoCAD
Management
Jira
Apply
In office • Full-Time • 10+ years exp • Bachelor's Degree • Riyadh
DevOps
GCP
OpenShift
VMWare
Datadog
Dynatrace
Azure
AWS
Kubernetes
Platform Engineering
AIOps
GitHub
Management
ServiceNow
Apply
Remote/Hybrid
Python
PowerShell
DevOps
Azure DevOps
Azure
CI/CD
Docker
Kubernetes
Bicep
Azure AKS
Cybersecurity
Microsoft Sentinel
ISO 27001
Apply
$120k – $160k per year • Equity 0.2–0.5% • In office • Full-Time • 1+ year exp • Master's Degree • San Francisco
AI/ML
LLM
LiveKit
Vapi
Voice Agents
DevOps
CI/CD
Cybersecurity
SOC 2
GDPR
HIPAA
Marketing
LinkedIn
Apply
Remote/Hybrid
Cybersecurity
ISO 27001
Microsoft Entra ID
Management
Microsoft Teams
Apply
$72k – $170k per year (Estimated) • In office • Full-Time • Orem
DevOps
VMWare
SLI/SLO/SLA
Apply
$94k – $171k per year (Estimated) • Remote • Full-Time • Master's Degree
DevOps
VMWare
CI/CD
Apply
$95k – $189k per year (Estimated) • In office • Full-Time • 2+ years exp • Orem
JavaScript
Java
TypeScript
SQL
Java
Spring Framework
Databases
MySQL
Oracle
MS SQL
AI/ML
Copilot
Cursor
LangGraph
LangChain
Claude
Claude Code
AI Agents
RAG
Frontend
Vue.js
Angular
React.js
DevOps
VMWare
GitHub
Apply
$120k – $250k per year (Estimated) • In office • Full-Time • Orem
Apply
$84k – $204k per year (Estimated) • In office • Full-Time • Lehi
AI/ML
Claude
DevOps
VMWare
Management
Slack
Jira
n8n
Apply
$56k – $94k per year • In office • Contractor • Orem
Apply
$64k – $74k per year • In office • Contractor • Orem
Apply
$56k per year • In office • Contractor • Orem
Apply
$84k – $94k per year • In office • Contractor • Orem
Apply
$50k – $120k per year • In office • Full-Time • Orem
Apply
See all jobs
This is one of many
414,045 more open roles from verified company boards, updated every day.