
51 - 200 employees
đ Security
âď¸ SaaS
Security ⢠SaaS ⢠Cloud Security
Upwind Security is a next-generation cloud security company that specializes in providing comprehensive protection for multi-cloud infrastructures. Their platform consolidates various security tools, offering cloud security posture management (CSPM), runtime vulnerability management, and API security, among other features. Upwind Security focuses on delivering real-time threat detection and vulnerability prioritization to enhance team efficiency and reduce organizational risks. With a strong emphasis on empowering DevOps and Security teams, Upwind Security simplifies cloud security management, offering solutions that address critical infrastructure and application security needs.
đĽ 1 hour ago
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
đ Security
âď¸ SaaS
Security ⢠SaaS ⢠Cloud Security
Upwind Security is a next-generation cloud security company that specializes in providing comprehensive protection for multi-cloud infrastructures. Their platform consolidates various security tools, offering cloud security posture management (CSPM), runtime vulnerability management, and API security, among other features. Upwind Security focuses on delivering real-time threat detection and vulnerability prioritization to enhance team efficiency and reduce organizational risks. With a strong emphasis on empowering DevOps and Security teams, Upwind Security simplifies cloud security management, offering solutions that address critical infrastructure and application security needs.
⢠Operate and improve Upwind's GRC and security compliance programs ⢠Support compliance work across SOC 2, ISO 27001, NIST, and FedRAMP, including control implementation, evidence collection, documentation, remediation tracking, continuous monitoring, and audit readiness ⢠Coordinate audit and compliance evidence from Engineering, IT, Security, Legal, and HR ⢠Translate compliance requirements into clear actions for technical and business teams ⢠Perform control assessments, gap analyses, and risk assessments, and recommend remediation ⢠Work with process owners to build sustainable, evidence-based remediation ⢠Track vulnerabilities, risks, audit findings, and POA&Ms through completion ⢠Handle customer security questionnaires, due diligence requests, and security documentation ⢠Support third-party risk management and vendor security assessments ⢠Write and maintain policies, standards, procedures, and control documentation ⢠Maintain GRC systems, evidence repositories, and risk registers ⢠Research new regulatory and customer requirements and determine their applicability ⢠Use AI and automation to accelerate research, documentation, evidence organization, and workflow with appropriate validation and data handling ⢠Raise gaps and issues early with proposed fixes
⢠3 to 5 years in GRC, cybersecurity, risk management, compliance, or audit ⢠Familiarity with NIST 800-53, SOC 2, ISO 27001, NIST CSF, or similar frameworks ⢠Experience supporting audits, assessments, security questionnaires, or evidence collection ⢠Strong written communication and documentation skills ⢠Technical fluency to work effectively with Engineering, IT, and Security ⢠Ability to turn audit findings into adoptable remediation plans ⢠Comfort working in a fast-moving environment where priorities shift ⢠Demonstrated use of technology to improve GRC work, including risk analysis, evidence collection, control monitoring, remediation tracking, research, customer trust, or workflow automation ⢠Organized and detail-oriented ⢠Nice-to-have: FedRAMP, NIST 800-53, or other U.S. government compliance experience, including POA&Ms, continuous monitoring, or assessment activities ⢠Nice-to-have: Experience working with external assessors on formal readiness or assessment activities ⢠Nice-to-have: Cloud security experience, particularly AWS or AWS GovCloud ⢠Nice-to-have: Background in SaaS, cloud security, or a high-growth technology company ⢠Nice-to-have: Experience with a global, distributed workforce across time zones ⢠Nice-to-have: Hands-on experience with cloud-based GRC, compliance automation, or AI-enabled workflow platforms ⢠Nice-to-have: Experience building GRC automations, integrations, or dashboards ⢠Nice-to-have: Familiarity with Jira, GitHub, or similar tools ⢠Certifications such as Security+, CISA, CRISC, CISM, CGRC, or ISO 27001 are nice to have
⢠Full-time employment ⢠Remote work in the United States
Apply NowđĽ 1 hour ago
Insurance and Risk Specialist supporting New York Blood Centerâs blood services enterprise-wide. Managing insurance programs, claims, renewals, analytics, and risk management processes.
đşđ¸ United States â Remote
đľ $51 - $56 / hour
â° Full Time
đĄ Mid-level
đ Senior
đ˛ Risk
đŚ H1B Visa Sponsor
đĽ 2 hours ago
Senior Risk Analyst managing insurance programs, claims, and enterprise risk for a prepared-meals company. Analyzing exposures, compliance, renewals, and risk reporting.
đĽ 7 hours ago
Risk & Controls Manager maintaining MetaMaskâs Web3 risk register, control evidence, and GRC tooling. Coordinating ISO 27001, SOC 2, audits, assessments, and risk reporting.
đşđ¸ United States â Remote
đľ $150k - $206k / year
â° Full Time
đĄ Mid-level
đ Senior
đ˛ Risk
đĽ 8 hours ago
GRC Analyst managing security controls, audits, and risk assessments. Supporting ExamWorksâ innovative healthcare services and insurance-sector clients.
đşđ¸ United States â Remote
đľ $60k - $90k / year
â° Full Time
đĄ Mid-level
đ Senior
đ˛ Risk
đĽ 8 hours ago
GRC Analyst managing security controls, audits, and risk assessments for ExamWorks, a healthcare services provider. Supporting HITRUST, SOC 2, HIPAA, and related compliance programs.
đşđ¸ United States â Remote
đľ $60k - $90k / year
â° Full Time
đĄ Mid-level
đ Senior
đ˛ Risk