We are looking for a Senior GRC Analyst to join our globally distributed, remote-first team. As a Senior GRC Analyst, you will report to the Security Engineering Manager – GRC and own the buildout and operation of Docker's risk management program. You will design and implement enterprise risk management processes, including security risk assessments, third-party risk management, and the risk register.
Requirements
- Own and drive the compliance program roadmap, aligning framework requirements (SOC 2, ISO 27001, ISO 27701, ISO 42001) with business objectives and product strategy
- Lead cross-functional compliance initiatives with Engineering, Product, Legal, and IT, serving as the authoritative voice on governance and risk matters
- Design and maintain Docker’s unified control framework, including cross-mapping to NIST 800-53 and identifying control gaps across multiple standards
- Plan and execute internal audits end-to-end: scoping, evidence collection, control testing, findings management, and external auditor coordination
- Advise GRC Engineering on correct integrations to configure and controls that require automated monitoring
- Perform and lead risk assessments across systems, processes, third-party tools, and cloud configurations, translating findings into actionable risk treatment plans
- Own the vendor risk management program, evaluating third-party vendors against compliance and security standards and driving remediation of identified gaps
- Draft, review, and maintain corporate security policies and map them to relevant control standards, ensuring alignment across frameworks
- Establish and report on compliance metrics and KPIs, providing data-driven visibility into program maturity to leadership
Benefits
- Freedom & flexibility
- Designated quarterly Whaleness Days plus end of year Whaleness break
- Home office setup
- 16 weeks of paid Parental leave (after 6 months of employment)
- Technology stipend equivalent to $100 USD net/month
- PTO plan that encourages you to take time to do the things you enjoy
- Training stipend for conferences, courses and classes
- Equity
- Docker Swag
- Medical benefits, retirement and holidays vary by country
