Senior Governance, Risk and Compliance Analyst, Kandji

GRC

$175-200k

+ Equity

AWS
Senior and Expert level
Miami

More information about location

4 days a week in office

Kandji

Apple device management platform

Open for applications

Kandji

Apple device management platform

201-500 employees

B2BEnterpriseComplianceSaaSCyber Security

Open for applications

$175-200k

+ Equity

AWS
Senior and Expert level
Miami

More information about location

4 days a week in office

201-500 employees

B2BEnterpriseComplianceSaaSCyber Security

Company mission

To harmonize technology and security through innovative software that powers secure and productive global work.

Role

Who you are

  • Seven (7) years or more of relevant experience in risk-based technology compliance management programs, or Auditing experience,
  • Experience in performing risk-based testing for control compliance, including the identification, assessment, and mitigation of compliance issues: understanding how to balance the company's risk appetite to compliance needs/requirements
  • Detailed knowledge and experience with technology controls across a variety of industry frameworks and how to assess controls supporting compliance for SOC2, FedRamp, CMMC, ISO 27001, ISO 27701, ISO 42001, CSA Star and global privacy regulations
  • Detailed knowledge of information security, technology compliance management industry frameworks and standards: NIST, OWASP, SANS, ISO-27001/2
  • Experience developing dynamic approaches to the implementation of a technology compliance program utilizing a variety of testing methods, both manual and automated, to provide qualitative and quantitative results where applicable
  • Strong analytical and problem-solving skills
  • Excellent project management, written and verbal communication skills
  • Ability to manage multiple priorities and deadlines
  • Proven track record as a strong cross-teams collaborator and team player, dealing with complex programs and influencing cross-functional audiences
  • Required to work on-site 4 days a week (Monday through Thursday) in Miami. Managers may require additional on-site days

Desirable

  • Experience and familiarity with cloud data security and working with public cloud solutions (AWS)
  • Experience working with a Governance Risk and Compliance technologies
  • Experience implementing Data Privacy technologies
  • Certifications such as CISA, CIPT, CRISC, CISSP, CCSP

What the job involves

  • Kandji is looking for a Senior Governance Risk and Compliance (GRC) Analyst II to add to our growing Security, IT and Trust teams
  • The GRC team is part of the Kandji Security and Trust organization and manages key pillars of the Kandji Risk Management framework
  • The GRC team is responsible for Customer Assurance, Security Compliance, Policy Governance, Information Security Risk Assessment, Third Party Risk Management, Security Compliance training and awareness, and Privacy
  • This opportunity provides the ability to work with various teams to evaluate controls, perform control testing to improve the efficiency and effectiveness of the internal control programs
  • This includes facilitating the development and maintenance of standards, processes, and tooling in order to promote scalability, repeatability and growth of the function
  • You will also facilitate risk assessments and control reviews to accommodate new business areas as well as changes in processes
  • This includes management of information security risk assessment process, defining and creating risk methodology, developing new or expanding product risk analysis
  • The Senior GRC Analyst II will report to the Team Lead, GRC and work collaboratively with other departments across Kandji
  • In support of multiple frameworks (e.g. ISO 27XXX, SOC2) plan, design and execute controls testing, controls assessment and risk management practices
  • Develop and execute on dynamic risk-based information security risk management and third party risk management programs
  • Execute on the risk assessment life cycle including identifying key risks, assessing risks and controls, calculating residual risk, identifying areas of improvement and collaborating with control owners on remediation plans against products, features, datasets, applications, and third parties
  • Collaborate with cross-functional teams to develop and implement privacy policies, procedures, and controls to mitigate data privacy risks
  • Provide expertise and guidance on data privacy laws and regulations, including GDPR, CPRA, EU AI Act and other relevant frameworks
  • Design and execute strategies for ensuring organizational compliance with SOC2, GDPR, Data Privacy, federal, state, and local government compliance, or similar regulations
  • Conduct impact assessments (PIAs, BIAs, AIIAs) and assist in developing strategies to address identified risks
  • Conduct data classification assessments to identify and categorize sensitive information based on its level of confidentiality, criticality, and regulatory implications
  • Be a trusted advisor for internal audit programs to expedite reviews and mitigate operational impacts
  • Assist with the preparation of reports and presentations for management and regulatory agencies
  • Support in the development and implementation of compliance training and awareness programs
  • Participate or lead special ad-hoc projects or initiatives as assigned

Our take

Device and application management is essential for the maintenance of an IT stack, with particular emphasis on frequent updating and compliance. This can be a laborious and repetitive task, so management software exists to automate these processes. However, existing solutions are generally aimed towards IT departments running on Windows.

Kandji provides a mobile device management platform that facilitates the remote maintenance of Apple-based IT stacks. Users can manage IT devices, applications, networking and compliance within a zero-touch automation system. The need for this service in companies using Apple hardware is clear: it has been adopted by major enterprises such as Belkin, Crunchbase and Notion.

Launched in 2019, the company has completed multiple rounds of funding and is continuing to grow at a rapid pace. As the Apple device management market is also expanding at speed, Kandji is well poised to continue its run of success.

Freddie headshot

Freddie

Company Specialist at Welcome to the Jungle

Insights

Top investors

Some candidates hear
back within 2 weeks

-5% employee growth in 12 months

Company

Funding (last 2 of 6 rounds)

Jul 2024

$100m

SERIES D

Nov 2021

$100m

SERIES C

Total funding: $288.4m

Company benefits

  • Health Coverage - 100% individual and dependent medical + dental + vision coverage
  • Flexible Spending Account
  • Equity for full-time employees
  • New MacBook Pro and software setup
  • Exciting opportunities for career growth
  • An outstanding, inclusive culture
  • 4% 401k company match
  • Monthly Uber Eats meal credit
  • $1,000 Home Office Equipment Stipend
  • $50 monthly Internet reimbursement
  • Equipment discounts
  • Week long company shutdown, first week of August
  • 10 Health and Wellness Days
  • 12 weeks of Paid Parental Leave
  • 14 Holidays

Company HQ

Downtown San Diego, San Diego, CA

Leadership

They started their career in Solutions at Apple before working as President of AMP Consulting and spending 9 years as CEO of Interlaced, which they founded. They left to found Kandji in 2018 as CEO.

Salary benchmarks

We don't have enough data yet to provide salary benchmarks for this role.

Submit your salary to help other candidates with crowdsourced salary estimates.

Share this job

View 28 more jobs at Kandji