GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsCaliforniaSan Francisco Bay AreaSenior GRC Analyst

Senior GRC Analyst

Gusto
GovernanceOn-siteFull-timeSan Francisco, CA$183,000

Gusto is hiring for the job of Senior GRC Analyst, San Francisco, CA (On-site). This is a Governance job in the governance, risk, and compliance field, with a posted range of $183,000. Review the full details below and apply directly with Gusto.

Organization: GustoLocation: San Francisco, CAWorkplace: On-siteFocus: GovernanceSalary: $183,000Posted: Sep 7, 2026
Gusto is hiring for this Governance job in San Francisco, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC jobs in San Francisco →

1.2;

About Gusto

At Gusto, we re on a mission to grow the small business economy. We handle the hard stuff, payroll, health insurance, 401(k)s, and, so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.

All full-time employees receive competitive base pay, benefits, and equity (RSUs), because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about our a Total Rewards philosophy.

AI is a fundamental part of how work gets done at Gusto. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process.

About the Role:

Gusto is seeking a Security, Governance, Risk and Compliance professional to join our team managing our security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk and Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing compliance with SOC 2 Type 2, IT General Controls, ICOC and related frameworks, while embedding security-minded practices throughout Gusto. This is a cross-functional role with key touchpoints in every department.

Here’s what you’ll do day-to-day:

Develop, maintain, and ensure adherence to security and compliance SOPs, internal documentation, and company-wide policies, particularly supporting SOC 2 and future framework adoption.
Own and manage trust management platforms including documentation of controls, risks, vendors, and exceptions, and lead the implementation of AI agents to automate and improve the implementation of our controls framework and evidence collection to support it
Collaborate with Legal, Enterprise Applications, and Gusto counterparts to establish and maintain data governance policies (e.g., classification, retention, handling).
Conduct ongoing internal risk assessments to identify exposure and control gaps; coordinate remediation plans with functional teams.
Manage the third-party vendor risk program, including onboarding reviews, monitoring, and renewal assessments.
Lead interactions with external auditors and regulatory bodies during compliance assessments (e.g., SOC 2 Type 2) and oversee responses to client security assessments and due diligence requests.
Stay current on relevant compliance frameworks, laws, and regulations to ensure appropriate coverage and adaptability.
Partner cross-functionally (e.g., Security, Legal, Engineering, Sales, IT) to implement scalable GRC processes, harmonize systems, and foster GRC understanding through employee enablement programs and KPI-driven insights.

Here’s what we re looking for:

8+ years of experience in governance, risk, and compliance within SaaS, ideally in the HCM, payroll, or fintech sectors.
Bachelor’s degree in Business, Information Systems, or a related field.
Strong understanding of SaaS business models, with experience implementing controls and policies in fast-paced, product-driven environments.
Proven experience leading or supporting a SOC 2 Type 2 compliance initiative, including collaboration with auditors and cross-functional teams.
Familiarity with compliance tools and platforms such as Optro, Vanta, Drata, Viso Trust, or similar.
Demonstrated ability to translate complex GRC requirements into actionable, scalable processes.
Excellent written and verbal communication skills, including the ability to educate and influence cross-functional stakeholders.
A data-informed mindset, with the ability to use analytics to assess GRC performance and maturity.
One or more relevant professional certifications:
CISA, CRISC, or GRCP preferred
CGEIT, CRMA, or PMI-RMP are a bonus

Our cash compensation amount for this role is targeted at $183,000-205,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

span 400; Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately strong 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, Gusto s subsidiary, whose physical office is in Scottsdale.

Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.

When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required. This includes non-office days for hybrid employees.

span 400; Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it s the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at Gusto.

span 400; Gusto is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Gusto considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gusto is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. We want to see our candidates perform to the best of their ability. If you require a medical or religious accommodation at any time throughout your candidate journey, please fill out a this form and a member of our team will get in touch with you.

Gusto takes security and protection of your personal information very seriously. Please review our a Fraudulent Activity Disclaimer.

Personal information collected and processed as part of your Gusto application will be subject to a Gusto s Applicant Privacy Notice.

Location and market context

This job is based in San Francisco on-site. Local candidates benefit from being close to Gusto's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About governance jobs

Governance jobs design the structures, policies, and oversight that keep complex programs accountable, coordinating across legal, risk, compliance, and technology. Jobs like this one are typically evaluated against frameworks such as governance frameworks, policy standards, and oversight and reporting practices.

How to position yourself for this governance job

Strong candidates emphasize policy and standard-setting, committee and stakeholder coordination, oversight reporting, and translating strategy into durable operating structures. In your resume and outreach, tie your experience to how Gusto would apply governance frameworks, policy standards, and oversight and reporting practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More jobs at Gusto

More GRC jobs in San Francisco

Hiring for Governance?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like Senior GRC Analyst in San Francisco, CA open regularly. Be first to know, privately. No current employer ever sees you looking.

New Governance jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.