Zip

GRC Analyst

San Francisco, California, United StatesFull timePosted 14 days ago
Apply on Zip →

Sign into see who you know at Zip.

ABOUT ZIP

Zip is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before.

The world’s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together they’ve saved over $8 billion and processed over $500 billion in spend. Zip’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA.

Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups.

YOUR ROLE

The Security & Compliance team at Zip is committed to providing a high level of security assurance to customers, aligning security goals with business objectives and customer requirements. As a GRC Analyst at Zip, you’ll be a key driver for ensuring the success of compliance programs at a fast-growing company. Your contributions will be pivotal to the overall growth and competitive edge of Zip’s GRC program. You’ll ensure we can securely and compliantly build new features, help design and scale the compliance programs that power our expansion. You’ll help maintain our existing SOC and ISO certifications while supporting new certifications, from AI products to entry into new markets like the EU and highly-regulated industries.

RESPONSIBILITIES

- Drive and perform periodic compliance-related activities, such as user access reviews, internal audits, and vendor risk assessments

- Lead conversations and curate responses for customers’ security, compliance, and governance teams in due diligence and security questionnaires

- Gu...