Remote (Global)

GoTo is hiring a Staff GRC Compliance Analyst

About the Role

GoTo is looking for a Staff GRC Compliance Analyst to serve as a cross-trained expert across Compliance, Audit, and Risk. In this role, you will partner with teams across the business to strengthen trust and operational resilience.

What You'll Do

  • Perform control mapping, gap analysis, and remediation tracking across multiple frameworks to proactively reduce audit risk.
  • Partner with engineering, IT, and security teams to translate regulatory requirements into actionable, testable technical controls.
  • Identify and operationalize improvements to the control framework to align with evolving regulatory demands (e.g., NIS2).
  • Reduce manual audit friction by driving process improvement and leveraging automation (dashboards, workflows, tooling integrations).

What We're Looking For

  • Hands-on experience operating within complex cloud or SaaS control environments across major frameworks (NIST 800-53, ISO 27001, PCI-DSS, HIPAA), including practical control testing.
  • Demonstrated ability to independently map regulatory requirements to technical control execution and identify material gaps using sound risk judgment.
  • Experience managing audit evidence collection and remediation tracking during live audit cycles.
  • Effective verbal and written communication skills with proven ability to engage technical stakeholders effectively.
  • Process improvement and automation mindset, with experience leveraging GRC tooling (e.g., Thoropass, AuditBoard, or similar platforms) to improve audit efficiency.

Benefits & Compensation

  • Salary range: $130,000.00 - $173,000.00.
  • Comprehensive health benefits, life and disability insurance, and fertility and family-forming support programs.
  • Generous paid time off, paid holidays, volunteer time off, and quarterly self-care days and no meeting days.
  • Tuition and reading reimbursement programs to support your continuous learning and professional growth.
  • Thrive Global Wellness Program, confidential Employee Assistance Program (EAP), and One to One Wellness Coaching.
  • Employee programs—including Employee Resource Groups (ERGs), GoTo Gives, and our charitable matching program.

Work Mode

This is a fully remote position. Candidates must be located in the United States within the Eastern or Central Time Zones.

We're committed to creating an inclusive space for everyone, because we know unique perspectives make us a stronger company and community.

Required Skills
GRCComplianceRisk ManagementAuditSecurity FrameworksPolicy DevelopmentVendor Risk ManagementIncident ResponseData PrivacyReportingStakeholder Management GRCComplianceRisk ManagementAuditSecurity FrameworksPolicy DevelopmentVendor Risk ManagementIncident ResponseData PrivacyReportingStakeholder Management
Invoicing holding you back?

Focus on work, not paperwork

Stop worrying about invoicing, taxes, and compliance. Glopay handles the business setup, you handle the client work. Get paid faster and look professional.

Auto-generated compliant invoices
Built-in expense management
Income reports for tax season
95% of earnings stay with you
Try Glopay free
No credit card needed
About company
GoTo
A technology company specializing in remote work solutions, focusing on flexible work technologies and AI-driven platforms to enhance workplace productivity.
All jobs at GoTo Visit website
Job Details
Category security
Posted 2 months ago