Carta Logo

Carta

Senior GRC Analyst

Job Posted 10 Days Ago Reposted 10 Days Ago
Hybrid
3 Locations
105K-130K
Mid level
Hybrid
3 Locations
105K-130K
Mid level
As a GRC Analyst at Carta, you will establish governance and risk frameworks, develop security compliance programs, perform security assessments, and collaborate with cross-functional teams to ensure data privacy and compliance. You will drive risk management practices and review contracts with a focus on information security.
The summary above was generated by AI
The Company You’ll Join

Carta connects founders, investors, and limited partners through world-class software, purpose-built for everyone in venture capital, private equity and private credit. 

Carta’s fund administration platform supports nearly 7,000 funds and SPVs, representing  $150B in assets under administration in venture capital and private equity. Trusted by more than 40,000 companies, Carta also helps private businesses in over 160 countries manage their cap tables, valuations, taxes, equity programs, compensation, and more.

Together, Carta is creating the end-to-end ERP platform for private markets. Traditional ERP solutions don’t work for Private Funds. Private capital markets need a comprehensive software solution to replace outdated spreadsheets and fragmented service providers. Carta’s software for the Office of the Fund CFO does just that - it’s a new category of software to make private markets look more like public markets - a connected ERP for private capital. 

For more information about our offices and culture, check out our Carta careers page.

The Problems You'll Solve

At Carta, our employees set out on a mission to unlock the power of equity ownership for more people in more places. We believe that the problems we solve today unlock the opportunities of tomorrow.

As a Senior GRC Analyst,  you’ll work to assess regulatory requirements and accordingly establish and maintain  governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance metrics, and build and manage policies and standards.

Here are some problems we’d love for you to help us solve: 

  • Manage and continually improve the Carta Governance, Risk, and Compliance  program, ensuring it is aligned with our security strategy and business objectives.
  • Develop, maintain, and lead the adoption of security policies, standards, and guidelines to ensure compliance with applicable regulatory requirements.
  • Lead and coordinate internal and external security audits.
  • Perform security assessments of vendors, third parties, and applications.
  • Partner with cross functional teams to review initiatives that could impact compliance requirements
  • Manage risk program activities including risk identification, tracking, and prioritization.
  • Collaborate with engineering and product teams to assess risk posture and compliance status, and support remediation activities.
The Team You'll Work With

You will be part of a security-minded team that believes in progress over perfection and where security culture and mindset is key. Our team is rethinking how GRC activities can be accomplished in innovative ways. We do not focus on building processes, but instead how to solve business problems while minimizing and managing risk exposure for Carta.

About You

We are looking for candidates who have:

  • A strong understanding and working knowledge of information security and compliance frameworks, such as SOC 1  and 2, ISO 27001, NIST CSF, GDPR, CCPA, FINRA, SOX and SEC cybersecurity requirements.
  • Excellent judgment and the ability to make balanced  decisions when working with complex situations.
  • Proven understanding of public cloud infrastructure and services in AWS and GCP including knowledge of cloud-native security protection measures, tools, and techniques
  • Proven  ability to collaborate with cross-functional teams and affect change to accomplish goals.
  • Excellent written and verbal communication skills, including the ability to effectively communicate business and cybersecurity risk.
  • 5+ years of experience in developing  and executing governance, risk and compliance functions.
Salary

Carta’s compensation package includes a market competitive salary, equity for all full time roles, exceptional benefits, and, for applicable roles, commissions plans. Our minimum cash compensation (salary + commission if applicable) range for this role is:

  • $148,750 - $175,000 in San Francisco, CA; Santa Clara, CA; New York City, NY
  • $141,313 - $166,250 in Seattle, WA

Final offers may vary from the amount listed based on geography, candidate experience and expertise, and other factors.

Disclosures:

  • We are an equal opportunity employer and are committed to providing a positive interview experience for every candidate. If accommodations due to a disability or medical condition are needed, please connect with the talent partner via email. 
  • Carta uses E-Verify in the United States for employment authorization. See the E-Verify and Department of Justice websites for more details.
  • For information on our data privacy policies, see Privacy, CA Candidate Privacy, and Brazil Transparency Report.
  • Please note that all official communications from us will come from an @carta.com or @carta-external.com domain. Report any contact from unapproved domains to security@carta.com.

Carta Seattle, Washington, USA Office

821 2nd Ave, Seattle, WA, United States, 98104

Similar Jobs

10 Hours Ago
Seattle, WA, USA
141K-197K Annually
Senior level
141K-197K Annually
Senior level
Aerospace
The Senior Cybersecurity GRC Analyst will manage risk assessments, compliance audits, and improve cybersecurity effectiveness by leveraging automation and metrics.
Top Skills: CmmcIso 27001Iso 28000NistSoc
12 Days Ago
Seattle, WA, USA
141K-197K Annually
Senior level
141K-197K Annually
Senior level
Aerospace
The Senior Cybersecurity GRC Analyst will lead risk management, ensure compliance with cybersecurity standards, and support audits and policy maintenance to safeguard Blue Origin's systems.
Top Skills: Ai SecurityCloud SecurityIso 27001Iso 28000NistSocVulnerability Scanning Technologies
17 Days Ago
4 Locations
103K-186K Annually
Senior level
103K-186K Annually
Senior level
Other • Utilities
Seeking a Senior Engineer for Cybersecurity Incident Response to analyze and mitigate threats, develop response plans, and enhance security practices.
Top Skills: EdrHTMLIds/IpsPerlPHPPythonShellSIEM

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account