Search...

GRC Analyst

Paxos logo
Paxos

Paxos is a regulated blockchain infrastructure platform offering settlement, liquidity, and tokenization services.

Maintainer signals as of 8/14/2026

Distributed
About Paxos

Paxos is a financial technology company that provides blockchain-based infrastructure solutions for the financial industry. It offers a platform for secure, fast, and cost-effective settlement of financial transactions and assets, enabling financial institutions to streamline operations and unlock new revenue opportunities. Paxos aims to modernize financial market infrastructure and make financial services more accessible.

View jobs by Paxos

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You support governance, risk management, and compliance programs by assessing security risks, monitoring compliance with policies and regulations, coordinating audits, maintaining security documentation, managing risk registers and control matrices, tracking remediation, and conducting third-party security risk assessments.

Requirements

  • Experience in governance, risk, and compliance, information security, IT risk management, or cybersecurity compliance roles
  • Hands-on experience performing security risk assessments, control assessments, compliance reviews, and privacy reviews
  • Experience with ISO 27001, NIST CSF, SOC 2, PCI DSS, GDPR, or similar regulatory requirements
  • Experience supporting internal and external audits through evidence collection, control validation, and remediation tracking
  • Experience developing, reviewing, and maintaining security policies, standards, procedures, and compliance documentation
  • Experience managing risk registers, control matrices, audit findings, and corrective action plans
  • Experience conducting third-party and vendor security risk assessments and reviewing supplier compliance documentation

Responsibilities

  • Support governance, risk management, and compliance programs
  • Assess security risks and controls
  • Monitor compliance with internal policies and external regulations
  • Coordinate internal and external audits
  • Ensure appropriate controls protect business information and technology assets
  • Identify risks with cross-functional teams
  • Track remediation activities
  • Improve the organization’s risk and compliance posture
  • Maintain security policies, standards, procedures, and compliance documentation
  • Manage risk registers, control matrices, audit findings, and corrective action plans
  • Conduct third-party and vendor security risk assessments