
GRC Analyst
Squarespace · New York
Job description
Squarespace is looking for a GRC Analyst to operate and continuously improve our governance, risk, and compliance programs within the Security organization. Our GRC team maintains audit readiness and supports the compliance frameworks — SOX, SOC 2, PCI DSS, NIST, and more — that protect Squarespace and the millions of customers who depend on us. We are a collaborative, detail-oriented team that moves deliberately and takes ownership of outcomes. You will work closely with Engineering, Legal, Finance, Product, and external auditors. This is an opportunity to modernize how GRC works — building automation, continuous monitoring, and data-driven reporting into programs that directly support revenue and customer trust. This is a hybrid role working from our NYC office 3 days per week. You will report to the GRC Manager. You'll Get To... Lead and support audits across SOX, SOC, PCI, and NIST — from scoping through reporting — while maintaining audit-ready documentation and tracking findings to closure. Evaluate control design and operating effectiveness, manage security risk assessments and exception records, and escalate overdue or material risks to the right partners. Conduct vendor security and privacy reviews, assess third-party control maturity, and track remediation through reassessment and closure. Respond to customer security questionnaires and partner assessments by coordinating timely, accurate responses across teams. Support data privacy audits and assessments covering GDPR, CCPA/CPRA, data retention, deletion, access rights, and third-party processing. Improve GRC operations through automation, integrations, AI-enabled workflows, and continuous compliance monitoring that reduce manual effort and strengthen audit readiness. Who We're Looking For 3+ years of experience in GRC, IT audit, security compliance, or privacy compliance, with demonstrated ability to manage audit activities end to end. Proven experience leading or supporting complex compliance programs across frameworks such as SOX, SOC 1/2, PCI, NIST, or ISO — including scoping, control testing, issue management, and reporting. Experience evaluating IT controls and translating requirements into clear, actionable expectations for both technical and non-technical teams. Experience supporting vendor risk programs, including security due diligence and review of independent assurance reports. Working knowledge of SaaS and cloud environments. Experience using GRC or workflow platforms to maintain accurate records and drive repeatable processes. Nice to Haves Experience building or improving GRC automation, continuous control monitoring, or compliance dashboards. Familiarity with privacy engineering concepts and privacy-by-design practices. Benefits & Perks A choice between medical plans with an option for 100% covered premiums Fertility and adoption benefits Access to supplemental insurance plans for additional coverage Headspace mindfulness app subscription Global Employee Assistance Program Retirement benefits with employer match Flexible paid time off 12 weeks paid parental leave and family care leave Pretax commuter benefit Education reimbursement Employee donation match to community organizations 7 Global Employee Resource Groups (ERGs) Dog-friendly workplace Free lunch and snacks Private rooftop Hack week twice per year Cash Compensation Range: $130,000 - $170,000 USD The base salary for this position will vary based on job-related criteria including relevant skills, experience, and location, among other factors. In addition to the cash compensation above (which includes base salary and, where applicable for eligible roles, may include overtime pay), Squarespace employees are eligible to be granted an option to purchase our common stock. Sales positions generally offer a competitive On Target Earnings (OTE) incentive structure in addition to base salary. About Squarespace
Verified and listed by ActiveJobs. Applications are made directly on Squarespace's own career page — we never sit in the middle.