GRC Analyst, Security - Provo
Provo, Utah, United States
â ď¸ We'll shut down after Aug 1st - try foođŚ for all jobs in tech â ď¸
Qualtrics
The XM Platform and our specialized AI uncovers insights, prioritizes actions, and empowers everyone to improve customer & employee experiences.Â
When you join one of our teams, youâll be part of a nimble group thatâs empowered to set aggressive goals and move fast to achieve them. Strategic risks are encouraged and complex problems are solved together, by passing the mic and iterating until the best solution comes to light. You wonât have to look to find growth opportunitiesâready or not, theyâll find you. From retail to government to healthcare, weâre on a mission to bring humanity, connection, and empathy back to business. Join over 5,000 people across the globe who think thatâs work worth doing.
Â
GRC Analyst, Security - Provo
Â
Why We Have This Role
We create software that the worldâs best brands use to deliver exceptional frontline experiences, build high-performing teams, and design products people love. Serving over 20,000 clients globally, we are more than a platformâwe are the creators and stewards of the Experience Management category. This GRC Security Analyst role is essential to maintaining and advancing our governance, risk, and compliance posture amid rapid growth and evolving regulatory landscapes. You will collaborate closely with cross-functional teams including legal, security, product, and compliance to identify, assess, and mitigate risks, ensuring Qualtrics meets rigorous security certifications and regulatory requirements. Your work will directly impact how we protect our customers and enable trusted innovation.
How Youâll Find Success
- Manage and maintain compliance with industry standards such as FedRAMP, ISO 27001, SOC 2, HITRUST, and emerging AI governance frameworks.
- Take initiative to understand complex compliance frameworks and work entrepreneurially to implement effective controls.
- Communicate clearly and influence stakeholders across teams to build trust and alignment.
- Apply strong analytical skills to assess risks and develop actionable remediation plans.
- Collaborate effectively with legal, security, product, and customer teams.
- Navigate and support external audits, customer audits and certification processes.
- Demonstrate ownership of governance processes and continuous improvement.
How Youâll Grow
- Deepen expertise in commercial and/ federal security compliance programs which can include ISO 27001, TISAX, FedRAMP High, IRAP and others.
- Expand leadership and project management skills through cross-team initiatives and audit coordination.
- Gain exposure to AI security and privacy compliance aligned with NIST AI Risk Management Framework.
- Develop advanced skills in risk assessment, supplier risk management, and security assurance.
Things Youâll Do
- Lead, assist and coordinate internal and external security audits and assessments to achieve and maintain certifications.
- Analyze and interpret regulatory requirements across multiple frameworks and translate them into actionable compliance programs.
- Partner with product and engineering teams to ensure security controls meet customer and regulatory expectations.
- Monitor and report on remediation progress and compliance metrics.
- Support customer security reviews, questionnaires, and risk assessments.
- Drive continuous improvement through automation in GRC processes, tools, and documentation.
What Weâre Looking For On Your Resume
- Bachelorâs degree in IT, Information Systems, or related discipline.
- 1-3 years of experience in governance, risk, and compliance roles within information security.
- Experience with IT security assessments, control testing, and compliance programs such as FedRAMP Moderate/High, PCI and SOC 2.
- Familiarity with other assessments such as ISO 27001, HITRUST, SSAE18, Protected B, SOX, or TISAX is a plus.
- Proven ability to work cross-functionally and influence without direct authority.
- Strong written and verbal communication skills.
- Project management experience managing partner expectations and audit schedules.
- Relevant security certifications are a plus, such as SSCP, Security+, CISSP, CISM, CIPP, or CISA.
- Experience with AI models is a plus.
What You Should Know About This Team
- The GRC team is a collaborative, high-performing group dedicated to protecting Qualtrics and its customers through proactive risk management and compliance.
- We work closely with legal, security, product, and customer success teams, as well as external auditors and partners.
- The team embraces strategic risk-taking and continuous learning.
- You will be positioned as a key enabler of business success through security assurance and compliance excellence.
Our Teamâs Favorite Perks and Benefits
- Access to ongoing professional development, certifications, and security training.
- Hybrid work model with purposeful in-office collaboration days.
- Inclusive culture committed to diversity, equity, and belonging.
- Competitive health, wellness, and financial benefits.
- Frequent team events, creative office spaces, and a strong emphasis on work/life integration.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index đ°
Tags: Audits Automation CIPP CISA CISM CISSP Compliance FedRAMP Governance HITRUST ISO 27001 NIST Polygraph Privacy Risk assessment Risk management RMF Security assessment SOC SOC 2 SOX SSCP TISAX
Perks/benefits: Career development Health care Medical leave Startup environment Team events Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.