Governance, Risk, Compliance & Trust Analyst
The Role You'll independently drive trust, compliance, and risk workstreams that help Everlaw scale responsibly and earn long-term confidence from customers and regulators. Sitting at the intersection of customer trust, compliance operations, audit readiness, and vendor risk, you'll translate Everlaw’s security posture into clear, audit-ready, and customer-facing deliverables while streamlining how compliance work gets done. This is a full-time, exempt position based in our Oakland, CA office with a hybrid work schedule: in office M/W/Th with the option to work from home on Tu/Fr. What you'll do Drive audit readiness across core compliance frameworks (FedRAMP, SOC 2, ISO 27001/27017/27018) by organizing evidence, maintaining documentation quality, and partnering with control owners to resolve gaps. Own end-to-end customer trust workflows and security questionnaires, researching technical answers and synthesizing evidence into clear, customer-ready responses. Conduct third-party security and vendor risk evaluations, assessing documentation, controls, and architecture against Everlaw standards in partnership with Procurement, Legal, and Security Engineering. Maintain and improve security training programs, ensuring content stays current, audit-ready, and aligned with policies and regulatory frameworks like FedRAMP and CJIS. Support governance workflows and public sector initiatives, including security impact analyses, change-related compliance reviews, and the ongoing operation of the Public Sector Clearance Program. About You You have 5+ years of experience working as an individual contributor within a Governance, Risk, Compliance, and Trust (GRCT) team. You have strong working knowledge of customer trust operations, risk management, and the control evidence required to support audits such as SOC 2, FedRAMP, or ISO 27001. You've led customer security questionnaire workflows and operated within GRC tools, trust portals, or evidence repositories. You bring a track record of using operational metrics, dashboards, or workflow data to maintain SLAs and streamline compliance processes. You can independently research technical topics, navigate ambiguity, and produce concise, clear written deliverables for both technical and non-technical stakeholders. You are authorized to work in the United States. Please note that at this time, Everlaw is not sponsoring U.S. employment visas for this role. Think you're missing some of the skills and are hesitant to apply? We do not believe in the 'perfect' candidate and encourage you to apply if you feel you can bring value to our team. We often revisit candidates who may have applied for a different role if something comes up that's a better fit. The Team — IT & Security The IT & Security team builds and protects the systems a high-trust company runs on. Across corporate technology, security operations, risk, compliance, trust, facilities, and strategic programs, the team creates dependable foundations that...