HimalayasHimalayas logo
Zone & CoZC

GRC Analyst

Zone & Co provides ERP-native software solutions designed to enhance back-office operations for finance teams, focusing on automation and scalability within the NetSuite ecosystem.

Zone & Co

Employee count: 51-200

Uruguay only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About Zone & Co:

Zone & Co is on a mission to empower finance professionals to drive strategic growth through seamless, intelligent operations. We build cloud-native software solutions on Oracle NetSuite, automating complex financial processes like billing, accounts payable, reporting, and reconciliation. Our vision is to unlock the full strategic potential of finance by infusing the ERP with the intelligence and automation needed for truly transformative operations. Join our rapidly growing team as we redefine financial efficiency for scaling businesses worldwide.

The Role: We are seeking a meticulous and proactive Security and Privacy Compliance Analyst to help safeguard our organization and our customers' data. Reporting directly to the Director of IT, Security and Compliance, you will play a critical role in maturing our governance, risk, and compliance (GRC) programs. In this position, you will bridge the gap between technical security controls and regulatory requirements, ensuring that Zone & Co's rapidly expanding suite of financial software maintains the highest standards of data protection and privacy.

This role requires a strong foundational knowledge of major security frameworks and privacy regulations, a keen eye for detail in auditing internal processes, and the ability to clearly communicate compliance postures to both internal engineering teams and enterprise customers.

Essential Job Functions:

  • Compliance Framework Governance: Lead the management and continuous scaling of Zone & Co’s core security compliance frameworks, specifically SOC 2 Type II and ISO 27001.
  • Privacy Operations Leadership: Govern global data privacy operations to ensure strict, ongoing alignment with GDPR, CCPA/CPRA, and other emerging data protection laws.
  • Customer Trust & Revenue Enablement: Serve as the primary security liaison for enterprise customers, directly supporting the sales cycle by demonstrating and communicating a robust, mature security posture.
  • Risk & Audit Management: Manage the organization's internal audit program and oversee the third-party vendor risk lifecycle to proactively identify and mitigate vulnerabilities.

Responsibilities, Duties, and Tasks:

  • Audit Coordination: Coordinate evidence collection, manage project timelines, and partner directly with external auditors during annual compliance assessments.
  • Privacy Assessments: Conduct Data Privacy Impact Assessments (DPIAs) for new products and process Data Subject Access Requests (DSARs) within mandated SLAs.
  • Questionnaires & Trust Center: Accurately and efficiently complete incoming vendor security questionnaires from prospects and maintain up-to-date documentation in our customer-facing Trust Center.
  • Internal Control Testing: Design and execute internal audits to test whether technical and administrative controls are operating effectively. Track control gaps and drive engineering/IT remediation efforts.
  • Vendor Risk Reviews: Evaluate the security and privacy postures of prospective and existing third-party vendors and sub-processors through comprehensive risk assessments.
  • Policy & Training Development: Draft, update, and publish internal security policies, standard operating procedures (SOPs), and incident response plans. Develop and administer engaging company-wide security and privacy awareness training.

What You'll Bring (Qualifications and Experience):

  • Experience: 3+ years of direct experience in IT Audit, Information Security, Privacy Operations, or GRC (Governance, Risk, and Compliance), preferably within a B2B SaaS, FinTech, or cloud technology environment.
  • Deep Domain Expertise: Hands-on experience working with established compliance frameworks (SOC 2, ISO 27001) and navigating global privacy legislation (GDPR, CCPA).
  • SaaS/Cloud Acumen: A solid understanding of cloud computing architectures (AWS, Azure, GCP) and enterprise software environments. Familiarity with ERP systems (like NetSuite) is a strong plus.
  • Analytical & Problem-Solving Skills: Proven ability to translate complex regulatory requirements into actionable, practical controls for IT and engineering teams without stifling innovation.
  • Exceptional Communication: Outstanding written and verbal communication skills. You must be able to write clear policies, translate technical risks for business leaders, and confidently answer complex customer security questions.
  • Education & Certifications: Bachelor’s degree in Information Systems, Cybersecurity, Business, or a related field. Relevant industry certifications such as CISA, CISM, CIPP/E, CIPP/US, or Security+ are highly preferred.

Benefits

At Zone, our benefits are designed to enrich your life beyond the workplace. Recognizing that work is just a fraction of your overall life experience, we are dedicated to providing robust support. As a fully remote company, we prioritize flexibility and balance. Explore our comprehensive list of benefits at Zoneandco.com.

Zone and Co is an Equal Opportunity Employer committed to diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, age, national origin, disability, protected veteran status, gender identity, or any other factor protected by applicable federal, state, or local laws. We strongly encourage candidates of all different backgrounds and identities to apply. This is an opportunity for us to bring in a different perspective and we’re eager to further diversify our company. Zone & Co is committed to building an equitable, inclusive, and supportive place for you to do some of the greatest work of your career.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Education

Bachelor degree

Experience

3 years minimum

Location requirements

Hiring timezones

Uruguay +/- 0 hours

About Zone & Co

Learn more about Zone & Co and their company culture.

View company profile

Zone & Co is dedicated to reinventing how companies approach back-office excellence, empowering finance leaders and their teams to scale and thrive in today's dynamic business landscape. Many businesses find themselves grappling with disparate platforms, developing proprietary billing systems, or managing countless spreadsheets for their lead-to-revenue processes. This often leads to wasted resources and inefficiencies. Our customers face these challenges, which is why we've developed a highly flexible platform that enhances out-of-the-box ERP capabilities, offering maximum visibility and control over company operations. Our mission is to unleash the potential of finance and accounting teams so they can grow without limitations, transforming NetSuite into a limitless software solution for companies at any scale.

Our suite of solutions, known as Zone Apps, are built as native extensions of users' cloud-ERP instances, specifically Oracle NetSuite. This approach effectively enhances its out-of-the-box capabilities and efficiencies, maximizes platform value, and prevents data disparity. From complex billing and revenue recognition to AP automation, advanced FP&A reporting, payroll, and more, Zone's unified platform integrates seamlessly with leading ERP software, adapting precisely to evolving needs. We understand that modern monetization software can be broken, and our goal is to provide solutions that allow businesses to deliver on their strategies without being held back by software limitations. Trusted by over 3,000 customers worldwide, Zone & Co is committed to delivering real-world solutions that provide tangible results. We partner with our customers throughout their growth journey, ensuring our platform of unified end-to-end products continues to evolve as their needs do. We're creating a world where businesses are freed from the limitations of clunky technology, enabling finance and accounting teams to scale their ERP instances for enhanced flexibility, speed, and accuracy.

Employee benefits

Learn about the employee benefits and perks provided at Zone & Co.

View benefits

Paid sick days

Offers paid sick days.

Paid holidays

Provides paid holidays.

Generous PTO

Offers generous paid time off.

Generous parental leave

Offers generous parental leave.

View Zone & Co's employee benefits
Claim this profileZone & Co logoZC

Zone & Co

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

2 remote jobs at Zone & Co

Explore the variety of open remote roles at Zone & Co, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Zone & Co

Remote companies like Zone & Co

Find your next opportunity by exploring profiles of companies that are similar to Zone & Co. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan