mercury
Any Office or Remote · Remote · Full-time
<p>Security failures are rarely caused by a single technical mistake. More often, they stem from gaps in governance, risk management, operational discipline, and accountability. Strong GRC programs help prevent those failures by making security a business priority, not just a technical concern.</p> <p>Mercury is growing rapidly, and as we scale, we need to continue building resilience, strengthening governance, and improving the way we manage risk across the company. We have a strong foundation today, but the next phase of growth will require scalable programs, thoughtful controls, and cross functional partnerships that allow Mercury to move quickly without sacrificing security.</p> <p>We are looking for an Information Security GRC Analyst to help mature Mercury’s security, risk, and compliance programs. This is not a traditional compliance role focused only on audits and evidence collection. You will help build the systems, processes, and guardrails that support business continuity, customer trust, and long term resilience.</p> <h3><strong>In this role, you will:</strong></h3> <ul> <li>Lead and support security risk assessments across products, systems, vendors, and business initiatives.</li> <li>Partner with Engineering, Product, IT, Legal, Operations, and other teams to identify, evaluate, and mitigate risk.</li> <li>Drive audit readiness and compliance initiatives across frameworks such as SOC 2, PCI DSS, NIST, CIS, and ISO 27001.</li> <li>Conduct gap assessments against security and compliance frameworks, then build practical plans to close those gaps.</li> <li>Design, implement, and mature scalable governance processes and security controls.</li> <li>Help improve Mercury’s business continuity, resilience, and third party risk management programs.</li> <li>Translate compliance and risk requirements into clear, actionable guidance for technical and non technical stakeholders.</li> <li>Identify opportunities to automate controls, evidence collection, and recurring GRC workflows.</li> <li>Help ensure Mercury’s security program remains strong, efficient, and aligned with the speed of the business.</li> </ul> <h3><strong>You may be a good fit if you:</strong></h3> <ul> <li>Have experience scaling security, risk, compliance, or governance programs in a high growth SaaS, fintech, or cloud native environment.</li> <li>Understand security frameworks such as SOC 2, PCI DSS, NIST, CIS, and ISO 27001, and can translate them into practical controls.</li> <li>Bring strong ownership and project management skills, with a track record of driving cross functional initiatives from concept to completion.</li> <li>Are comfortable creating structure from ambiguity and building programs or processes from scratch.<
mercury
Posted via Greenhouse_public
Apply Now takes you to Rozgoo, where auto-apply can submit your application for this role. Updated 4 days ago.
Apply Now