GRC (Governance, Risk, and Compliance) Analyst
About Us:
YipitData is the leading market research and analytics firm for the disruptive economy and most recently raised $475M from The Carlyle Group at a valuation of over $1B. Every day, our proprietary technology analyzes billions of alternative data points to uncover actionable insights across sectors like software, AI, cloud, e-commerce, ridesharing, and payments.
Our data and research teams transform raw data into strategic intelligence, delivering accurate, timely, and deeply contextualized analysis that our customers—ranging from the world’s top investment funds to Fortune 500 companies—depend on to drive high-stakes decisions. From sourcing and licensing novel datasets to rigorous analysis and expert narrative framing, our teams ensure clients get not just data, but clarity and confidence.
We operate globally with offices in the US, APAC, and India. Our award-winning, people-centric culture—recognized by Inc. as a Best Workplace for three consecutive years—emphasizes transparency, ownership, and continuous mastery.
What It’s Like to Work at YipitData :
YipitData isn’t a place for coasting—it’s a launchpad for ambitious, impact-driven professionals.
From day one, you’ll take the lead on meaningful work, accelerate your growth, and gain exposure that shapes careers.
Why Top Talent Chooses YipitData :
-
Ownership That Matters : You’ll lead high-impact projects with real business outcomes
-
Rapid Growth : We compress years of learning into months
-
Merit Over Titles : Trust and responsibility are earned through execution, not tenure
-
Velocity with Purpose: We move fast, support each other, and aim high—always with purpose and intention
If your ambition is matched by your work ethic—and you're hungry for a place where growth, impact, and ownership are the norm— YipitData might be the opportunity you’ve been waiting for.
About The Role:
YipitData is looking for a GRC Analyst who likes asking good questions, finding the gaps others miss, and turning complicated requirements into work people can actually complete.
You will help us answer some important questions: Are our security controls working the way we say they are? Can we prove it? Where are we taking on risk? What needs to change as our products, technology, and use of AI continue to grow?
Your work will span audits, risk assessments, control testing, vendor reviews, customer questionnaires, policies, and compliance programs. You will partner with teams across Security, IT, Engineering, Legal, Finance, and People to understand how the business operates, identify where improvements are needed, and keep the work moving through completion.
This is not a role where success means uploading documents to an audit platform. We want someone who is curious enough to understand the evidence, thoughtful enough to challenge it when it does not make sense, and organized enough to make sure nothing important gets lost in the follow-up.
This is a remote-friendly opportunity that can sit in NYC (where our headquarters is located), one of our office hubs, or anywhere else in the US. However, depending upon where the remote work is performed, income could be subject to New York State tax withholding.
The work hours are flexible on this team, but most employees work East Coast hours.
As a GRC Analyst You Will:
- Take ownership of GRC workstreams and drive them from the initial request through evidence collection, testing, remediation, and completion
- Help keep YipitData audit-ready throughout the year
- Test security controls and determine whether they are actually working, rather than simply confirming that a document exists
- Conduct risk assessments, identify meaningful gaps, and help teams develop remediation plans that are realistic and effective
- Map controls across SOC 2 and other frameworks so one strong control can satisfy multiple requirements
- Coordinate recurring work such as access reviews, control testing, policy reviews, risk up