Role Overview

IT GRC Analyst in the USA or Canada
Diverse group of professionals walking together in a modern office hallway

Cloud for Good is looking for an IT GRC Analyst to own the day-to-day operation of our security compliance program. This role sits at the center of our security posture coordinating external vendors and auditors, responding to client due-diligence requests, and keeping our policies and controls current. You won’t be doing hands-on penetration testing yourself, but you’ll manage the vendor relationship that does, and you’ll be the person who turns audit findings, questionnaire requests, and policy gaps into action. 

Location: Virtual, home office in the USA or Canada 

Work Authorization: Citizens or Permanent Residents of the USA or Canada. Cannot provide Visa sponsorship. 

Responsibilities 

Penetration Testing Vendor Management 

  • Serve as the primary point of contact for our third-party penetration testing vendor(s) 
  • Coordinate scoping, scheduling, and rules of engagement for pentest engagements 
  • Review vendor findings and reports; translate technical findings into remediation tickets for IT 
  • Track remediation timelines and confirm fixes are validated (retesting, evidence of closure) 
  • Evaluate and, when needed, help select new pentest vendors based on scope, cost, and quality 

SOC 2 Audit Coordination 

  • Own the day-to-day relationship with our SOC 2 auditor and any compliance automation platform (e.g., Vanta, Drata, Secureframe) 
  • Collect, organize, and submit evidence requested by the auditor across control owners and departments 
  • Track audit timelines and deliverables; escalate blockers before they become deadline risks 
  • Manage responses to auditor follow-up questions and any noted exceptions 
  • Maintain a continuous, audit-ready evidence trail between audit cycles (not just during the audit window) 

Security Questionnaires 

  • Own the end-to-end response process for inbound client/prospect security questionnaires and due-diligence requests 
  • Maintain a current library of standard responses, control descriptions, and supporting documentation (e.g., SOC 2 report, pen test summary, policies) to speed up turnaround 
  • Coordinate with sales, legal, and services as needed to answer non-standard or technical questions accurately 
  • Track turnaround times and flag recurring gaps that could be solved with better documentation or new controls 

Security Policy & Posture Management 

  • Maintain and periodically review the company’s information security policies (access control, data handling, incident response, acceptable use, vendor risk, etc.) 
  • Ensure policies stay aligned with SOC 2 requirements and evolving business needs 
  • Track policy acknowledgments and training completion across the company 
  • Monitor overall security posture — identify gaps between documented policy and actual practice, and drive closure
  • Maintain a risk register and support periodic risk assessments 

What You Bring 

Required: 

  • 2+ years of experience in a GRC, IT compliance, or security operations role 
  • Familiarity with SOC 2 (Type I or Type II) and the audit lifecycle 
  • Experience managing vendors or external service providers 
  • Strong written communication — you’ll be writing policies, auditor responses, and client-facing answers 
  • Comfortable coordinating across departments (services, IT, sales, legal) to get information and drive action 
  • Detail-oriented, organized, and able to manage multiple concurrent deadlines (audit cycles, questionnaires, vendor engagements) 

Preferred: 

  • Experience with compliance automation platforms (Vanta, Drata, Secureframe, Tugboat Logic) 
  • Familiarity with additional frameworks (ISO 27001, HIPAA, PCI-DSS, GDPR/CCPA) 
  • Experience responding to enterprise client security questionnaires (e.g., via SIG, CAIQ, or custom formats) 
  • Relevant certifications: Security+, CISA, CRISC, or similar 
  • Basic understanding of penetration testing methodology (enough to read and interpret vendor reports, not perform testing) 

Working Successfully at CFG  

Cloud for Good is a client-service organization, and as a member of our fully remote team, there are a few non-negotiables that enable collaboration, professionalism, and exceptional client outcomes. We succeed when our teams work in partnership with clients, communicate proactively, and uphold the standards that make Cloud for Good a trusted partner. 

  • Travel Requirements 
    • All roles at Cloud for Good include a travel component. Business travel—both domestic and international—may be required based on project and client needs. The amount of travel will vary by role but is generally expected to be up to 30% annually. Travel is considered an essential part of this position and supports effective client engagement, collaboration, and company representation. 
  • Work Environment 
    • Cloud for Good is a fully remote company. Team members are expected to maintain a professional, distraction-free workspace that is camera-ready for video meetings. Collaboration takes place across Zoom, Office 365, Salesforce, and Slack during standard business hours (9:00 a.m. – 5:00 p.m. in your local time zone). 
  • Client Time Zone Alignment 
    • As a team member, you may be required to adjust your work hours to align with your key client’s time zone to support effective communication, collaboration, and project delivery. Flexibility and coordination with your Project Lead (Services) will help ensure success in this client-facing role. 

Disclaimers 

  • Equal Employment Opportunity  
    • At Cloud for Good, we are proud to be an Equal Opportunity Employer and adhere to the principles of Equal Employment Opportunity (EEO). We do not discriminate in employment decisions or practices on the basis of race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, veteran status, or any other legally protected characteristic.  
    • Our commitment to non-discrimination applies across every location in which our company operates, and it encompasses all aspects of employment.  
    • Cloud for Good strongly encourages individuals from diverse backgrounds and identities to apply. Our commitment to diversity not only strengthens our workplace culture but also drives better outcomes for our clients.  We value inclusivity and want applicants who may require special assistance or accommodation during the interview process to know we’re here to assist you. 
  • Use of AI in Interviewing 
    • At Cloud for Good, we believe in conducting interviews that are fair, equitable, and designed to evaluate candidates based on their qualifications and experience, with the organization. To ensure that all candidates are given an equal opportunity to demonstrate their abilities, we prohibit the use of AI or any other type of machine learning tools during the interview process. 
    • Candidates are expected to participate in the interview process remotely using video conferencing. Any attempt to use AI or similar technology to respond to interview questions, analyze or provide feedback on the interview process, or perform any other interview-related tasks is strictly prohibited and will be considered a violation of our policy and may result in disqualification from the interview process. 
    • We understand that some candidates may have disabilities or other circumstances that require accommodation during the interview process. In such cases, we will make reasonable accommodations to enable candidates to participate in the interview process to the best of their ability. However, we do not permit the use of AI or similar technology as a substitute for direct participation in the interview. 

Virtual: Home-based office in the USA or Canada.