GRC Analyst supporting enterprise risk management and compliance at Coupa. Analyzing risk data and maintaining vendor assessments in a collaborative environment.
Responsibilities
Collect, analyze, and interpret risk data from multiple sources (security operations, product, compliance, audits).
Conduct onboarding and periodic risk assessments for suppliers, SaaS vendors, and key third-party partners.
Send and track vendor due-diligence questionnaires, review responses, SOC reports, and certifications to identify gaps.
Maintain and update quarterly Risk Dashboards, KRI/KPI Reports, and decision-support visuals.
Monitor remediation progress across risk owners and functional teams.
Maintain the single source of truth for control and requirement mappings, ensuring alignment with regulatory and industry frameworks (ISO 27001/27701, SOC 2, NIST CSF, PCI DSS, etc.).
Prepare baseline compliance reports and dashboards for management review.
Aggregate data from GRC tools, Jira, spreadsheets, and other systems to build metric packs.
Requirements
1–3 years of experience in risk management, GRC operations, security compliance, vendor management, or audit.
Basic understanding of security and compliance frameworks (NIST CSF, ISO 27001/27701, SOC 2, PCI DSS, or similar).
Strong organizational, analytical, and documentation skills; comfortable working with metrics, spreadsheets, and structured data.
Ability to review and map detailed compliance requirements logically to controls.
Ability to interpret vendor documentation and identify red flags or gaps.
Excellent communication and follow-up skills for coordinating cross-functional reviews.
Benefits
Pioneering Technology: At Coupa, we're at the forefront of innovation, leveraging the latest technology to empower our customers with greater efficiency and visibility in their spend.
Collaborative Culture: We value collaboration and teamwork, and our culture is driven by transparency, openness, and a shared commitment to excellence.
Global Impact: Join a company where your work has a global, measurable impact on our clients, the business, and each other.
Regulatory Compliance Manager at Moneycorp managing compliance oversight and advisory for payments and MiFID - regulated entities. Ensuring compliance with regulations and managing regulatory risks to support the business growth.
Head of Analytics and Portfolio Intelligence at Nium delivering risk and compliance analytics. Shaping governance and proactive risk reporting within a top fintech company.
Regulatory Associate managing US/regional contributions to Global Regulatory Strategies and implementation plans at Pfizer. Collaborating with cross - functional teams ensuring compliance with regulations while advancing patient access.
Graduate role in FinTech focusing on Regulatory Reporting solutions with clients at Suade. Working directly on implementation projects and contributing to regulatory change initiatives.
AVP Enterprise Compliance managing compliance relationships and oversight for financial services. Collaborating with clients and maintaining compliance programs in Sioux Falls.
Seeking a Summer Student Intern for Risk Compliance at Tarion. Engage in multimedia creation while learning risk management skills in a hybrid work environment.
Regulatory Affairs Manager leading regulatory submissions for medical device company. Ensuring compliance with global regulations and facilitating market access for products.
Sales Admin & Compliance Specialist at Zalaris managing sales processes and ensuring contract compliance. Supporting the sales team with document management and CRM development.
Compliance Analyst serving in LendingTree’s Compliance team ensuring effectiveness of internal controls and compliance regulations. Monitoring customer complaints and suggesting process improvements.