Talent Apply
Log in
All jobs
E

GRCT Analyst

Everlaw

About this role

Job title: GRCT Analyst

About the Role

Everlaw is seeking a GRCT Analyst to independently drive moderately complex trust, compliance, and risk workstreams that help the company scale responsibly and earn customer and regulator trust. The role sits at the intersection of customer trust, compliance operations, audit readiness, risk management, documentation quality, and cross-functional execution. You will translate Everlaw’s security and compliance posture into clear, audit-ready, and customer-ready outputs while upholding integrity, discipline, and a high standard for quality.

What You'll Do

  • Compliance Support audit readiness across core frameworks such as FedRAMP, SOC 2, and ISO 27001/27017/27018 by organizing evidence, maintaining documentation quality, and partnering with control owners to close gaps.

  • Manage compliance operations that require structured follow-through, including evidence requests, policy and procedure updates, control narrative maintenance, and recurring review cycles.

  • Partner cross-functionally with Security Engineering, DevOps, IT, Legal, People, Procurement, and other stakeholders to gather inputs, validate implementation details, and produce audit-ready or stakeholder-ready outputs.

  • Help maintain strong execution against defined compliance SLAs, milestones, and recurring obligations, escalating risks early and driving issues through resolution.

  • Translate technical, operational, and regulatory topics into clear written deliverables for internal and external audiences, including concise summaries of requirements, risks, tradeoffs, and recommendations.

  • Support internal risk and governance processes, including security impact analyses, change-related compliance reviews, and other structured review workflows as assigned.

  • Contribute to the on-going operation of the Public Sector Clearance Program, to include guiding new cohorts through the program, maintaining status and tracking open issues, and communication.

  • What We're Looking For

  • A career-core individual contributor who can own work end-to-end with limited oversight, navigate ambiguity, communicate clearly with stakeholders, and improve how trust and compliance work gets done over time.

  • Strong attention to detail and a commitment to high-quality documentation and outputs.

  • Ability to partner with multiple functions (Security Engineering, DevOps, IT, Legal, People, Procurement, etc.) to gather inputs and validate implementation details.

  • Familiarity with or willingness to work across security programs and regulatory frameworks (e.g., FedRAMP, SOC 2, ISO 27001/27017/27018).

  • Excellent written and verbal communication skills, with a track record of translating technical topics into clear deliverables and recommendations.

  • Compensation & Benefits

  • Not disclosed in the posting.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →