Peregrine Technologies
Governance, Risk & Compliance (GRC) Analyst
Peregrine Technologies, San Francisco, California, United States, 94199
The Role
We’re looking for a Governance, Risk, and Compliance (GRC) Analyst to help strengthen and scale our security and compliance program. In this role, you’ll support the development and maintenance of frameworks that ensure our organization meets key regulatory, contractual, and operational standards across data protection, privacy, and security. You’ll work closely with engineering, product, and leadership teams to maintain compliance with frameworks like SOC 2, CJIS, HIPAA, ISO 27001, NIST 800-53, and FedRAMP as our business expands across new markets and government sectors. This position is ideal for someone who’s detail-oriented, collaborative, and excited to build structured compliance practices that make a real impact on security and trust. What You’ll Do
Support the implementation, tracking, and continuous improvement of compliance frameworks (SOC 2, CJIS, HIPAA, ISO 27001, FedRAMP, NIST 800-53). Manage and organize compliance documentation, internal audits, and evidence collection for both internal and external stakeholders. Collaborate with internal teams to update policies, procedures, and controls related to data protection, access management, and incident response. Maintain strong awareness of security best practices in cloud environments - particularly AWS - including services like GuardDuty, SecurityHub, Amazon Inspector, and AWS Config. Use compliance management tools such as Vanta, Drata, SecureFrame, or HyperProof to streamline reporting and evidence collection. Partner with technical teams to ensure that identity and access management (IAM), MFA, and least-privilege principles are properly applied. Contribute to audit readiness and help respond to customer and vendor compliance inquiries. Be based in one of our SF, NYC, or Washington, D.C. hubs with a 4 days/week in office requirement. About You
Experience: 5-10 years of experience in information security, compliance, or risk management within regulated industries (e.g., healthcare, finance or government). Framework Familiarity: Working knowledge of SOC 2, HIPAA, CJIS, FedRAMP, ISO 27001, NIST 800-53, or similar frameworks. Technical Knowledge: Understanding of cloud-native SaaS environments, microservices, VPCs/VPNs, and identity management concepts such as RBAC and MFA. Detail-Oriented: You thrive on structure, accuracy, and organization - especially when managing documentation and multiple compliance tasks. Collaborative & Curious: You enjoy learning from others, contributing to shared goals, and improving processes along the way. Clear Communicator: You can translate complex security concepts into simple, actionable language for different audiences. Preferred Certifications
Governance & Compliance: CGRC, CISSP, CISA, CIPP/US, HCISPP, CompTIA Security+. Cloud Security: CCSP, CCSK, AWS Security – Specialty, AWS Solutions Architect – Associate, or CompTIA Cloud+. Bonus Points
Experience working with public safety, justice, or government agencies, or other highly regulated data environments. Familiarity with CJIS, SOC-2 or overlapping control frameworks. Passion for building scalable, user-friendly compliance systems in a fast-growing organization. Salary Range: $140,000 - $170,000 Annually + Benefits + Equity (if applicable) + Bonus (if applicable) Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, and specific work location. Information on the benefits offered is here. Peregrine Technologies is committed to creating an inclusive environment for all employees. We celebrate diversity and are a proud equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. Voluntary Self-Identification For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file. Disability Status Select... PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.
#J-18808-Ljbffr
We’re looking for a Governance, Risk, and Compliance (GRC) Analyst to help strengthen and scale our security and compliance program. In this role, you’ll support the development and maintenance of frameworks that ensure our organization meets key regulatory, contractual, and operational standards across data protection, privacy, and security. You’ll work closely with engineering, product, and leadership teams to maintain compliance with frameworks like SOC 2, CJIS, HIPAA, ISO 27001, NIST 800-53, and FedRAMP as our business expands across new markets and government sectors. This position is ideal for someone who’s detail-oriented, collaborative, and excited to build structured compliance practices that make a real impact on security and trust. What You’ll Do
Support the implementation, tracking, and continuous improvement of compliance frameworks (SOC 2, CJIS, HIPAA, ISO 27001, FedRAMP, NIST 800-53). Manage and organize compliance documentation, internal audits, and evidence collection for both internal and external stakeholders. Collaborate with internal teams to update policies, procedures, and controls related to data protection, access management, and incident response. Maintain strong awareness of security best practices in cloud environments - particularly AWS - including services like GuardDuty, SecurityHub, Amazon Inspector, and AWS Config. Use compliance management tools such as Vanta, Drata, SecureFrame, or HyperProof to streamline reporting and evidence collection. Partner with technical teams to ensure that identity and access management (IAM), MFA, and least-privilege principles are properly applied. Contribute to audit readiness and help respond to customer and vendor compliance inquiries. Be based in one of our SF, NYC, or Washington, D.C. hubs with a 4 days/week in office requirement. About You
Experience: 5-10 years of experience in information security, compliance, or risk management within regulated industries (e.g., healthcare, finance or government). Framework Familiarity: Working knowledge of SOC 2, HIPAA, CJIS, FedRAMP, ISO 27001, NIST 800-53, or similar frameworks. Technical Knowledge: Understanding of cloud-native SaaS environments, microservices, VPCs/VPNs, and identity management concepts such as RBAC and MFA. Detail-Oriented: You thrive on structure, accuracy, and organization - especially when managing documentation and multiple compliance tasks. Collaborative & Curious: You enjoy learning from others, contributing to shared goals, and improving processes along the way. Clear Communicator: You can translate complex security concepts into simple, actionable language for different audiences. Preferred Certifications
Governance & Compliance: CGRC, CISSP, CISA, CIPP/US, HCISPP, CompTIA Security+. Cloud Security: CCSP, CCSK, AWS Security – Specialty, AWS Solutions Architect – Associate, or CompTIA Cloud+. Bonus Points
Experience working with public safety, justice, or government agencies, or other highly regulated data environments. Familiarity with CJIS, SOC-2 or overlapping control frameworks. Passion for building scalable, user-friendly compliance systems in a fast-growing organization. Salary Range: $140,000 - $170,000 Annually + Benefits + Equity (if applicable) + Bonus (if applicable) Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, and specific work location. Information on the benefits offered is here. Peregrine Technologies is committed to creating an inclusive environment for all employees. We celebrate diversity and are a proud equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. Voluntary Self-Identification For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file. Disability Status Select... PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.
#J-18808-Ljbffr