
Vercel · Remote - United States
ABOUT VERCEL: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the w...
Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.
For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products
that help builders move from idea to production with speed, security, and exceptional developer experience.
Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built,
extended, and operated by agents.
We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers
worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll
help define what comes next.
We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and
maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO
27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically,
responsibly, and in accordance with regulatory requirements.
You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization
and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices.
You will report to the Head of GRC and will be located ((remote, onsite, hybrid)).
Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you
think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and
ethics.
If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes
in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please
connect with our recruiting team.
completion with clear documentation of progress.
and track completion to ensure audit success.
GRC operations, and contribute to controls maturity scoring and reporting
and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
understanding of compliance, ethics, and regulatory requirements within the organization.
PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
execute projects across various business units and levels.
The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills,
experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation
package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on
the role. Your recruiter can share more details during the hiring process.
WHO WE ARE The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy — a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn’t coming; it’s here, and we need builders, innovators and problem solvers to help us create it. WHO YOU ARE Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security policies, drive employee security awareness, and pioneer our AI governance framework. You will partner across Technology, Legal, Internal Audit, Procurement, and People Operations to safeguard customer trust and support operational excellence. WHAT YOU'LL DO * Author, update, and enforce corporate security policies to guarantee cross-departmental compliance * Deploy and manage required information security training campaigns as the platform owner * Transform static policies into interactive modules with comprehension quizzes for mandatory sign-offs * Establish and enforce an internal AI governance framework with Data, Legal, and Tech teams * Conduct structured risk assessments on emerging tools and internal AI models to maintain behavioral guardrails * Report training metrics, policy exceptions, and risk postures directly to senior management * Review vendor security profiles and software pipelines to mitigate security risk WHAT WE'RE LOOKING FOR * 3+ years of experience in information security GRC, cybersecurity training, or technology compliance * Proven track record of managing required security awareness programs and driving cross-functional accountability * Experience with modern training orchestration platforms and understanding of AI and machine learning data security * Working knowledge of standard industry frameworks, specifically SOC 2 and PCI-DSS * Communication skills with the ability to explain complex regulatory needs to non-technical employees * Bachelor’s degree in Cybersecurity, Information Systems, or an equivalent technical discipline WHILE NOT REQUIRED, THESE ARE A PLUS: * GRC certifications such as CISA or CRISC ---------------------------------------------------------------------------------------------------------------------------------- 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $100,000.00 USD to $135,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis’s total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. #LI-CM1 #LI-Onsite Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate’s application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
ABOUT LENDABLE Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world’s leading fintech companies and are off to a strong start: * One of the UK’s newest unicorns with a team of just over 700 people * Among the fastest-growing tech companies in the UK * Profitable since 2017 * Backed by top investors including Balderton Capital and Goldman Sachs * Loved by customers with the best reviews in the market (4.9 across 10,000s of reviews on Trustpilot) So far, we’ve rebuilt the Big Three consumer finance products from scratch: loans, credit cards and car finance. We get money into our customers’ hands in minutes instead of days. We’re growing fast, and there’s a lot more to do: we’re going after the two biggest Western markets (UK and US) where trillions worth of financial products are held by big banks with dated systems and painful processes. JOIN US IF YOU WANT TO 1. Take ownership across a broad remit. You are trusted to make decisions that drive a material impact on the direction and success of Lendable from day 1 2. Work in small teams of exceptional people, who are relentlessly resourceful to solve problems and find smarter solutions than the status quo 3. Build the best technology in-house, using new data sources, machine learning and AI to make machines do the heavy lifting ABOUT THE ROLE We are looking for a proactive Security GRC Analyst to join our Information Security team. You will play a pivotal role in scaling our security posture in a fast-paced, AI driven, cloud-native environment. You will be part of a growing team, where your voice will be heard, and your ability to take ownership and drive initiative will directly shape our security culture and operational resilience. Your approach to GRC starts with the risk, not the checklist. Rather than chasing compliance for its own sake, you will identify and assess the risks first, then collaborate with stakeholders to design pragmatic mitigations. You understand that compliance doesn't drive the business; rather, it is the natural outcome of a mature security posture that actively works for the organisation. WHAT YOU’LL BE DOING * Framework & Regulatory Alignment: Help maintain, improve, and scale our security compliance programmes, ensuring ongoing alignment with standards such as SOC 2, ISO 27001, and PCI-DSS, as well as regulator expectations and UK GDPR. * Risk & Mitigation: Collaborate on identifying security risks across the business - including emerging risks from AI-driven and agentic threats - and support the team in driving practical, risk-first mitigation strategies. * Compliance Automation: Utilise our security compliance platform (e.g., Vanta/Drata) to orchestrate automated evidence collection, reducing manual overhead and moving the company toward a state of continuous audit readiness. * Third-Party Risk Management (TPRM): Conduct vendor and third-party security risk assessments to evaluate the security posture of partners and critical outsourced service providers. * Translating Risk & Governance: Work with the team to bridge the gap between engineering and business governance by turning technical security metrics into clear, risk-based narratives for internal stakeholders and external auditors. * Security Culture & Awareness: Support the delivery and promotion of security awareness initiatives to help drive a strong culture of shared security responsibility across the organisation. * Technical Collaboration: Actively engage in conversations with engineers, developers, and IT teams - understanding their technical language and workflows to help align security controls with engineering realities. * Audit & Assessment Support: Participate in external audits and assessments by gathering evidence, preparing documentation, and helping to ensure a smooth, successful audit cycle. WHAT YOU WILL BRING Essential: * Experience: 5+ years of experience in a related role (ideally within a regulated, cloud-native business or FinTech). * Compliance & Risk Expertise: A strong, foundational understanding of security risk management principles and hands-on experience working with compliance frameworks (e.g. ISO 27001, PCI-DSS, or SOC 2). * Risk-First & Pragmatic Mindset: A natural tendency to start with the "why" (the risk) rather than the checklist. You possess the ability to balance strict financial regulations with the operational agility of a fast-paced FinTech, ensuring security controls protect the business without slowing it down. * Communication & Collaboration: Outstanding communication skills with a proven ability to comfortably converse with technical stakeholders, understand their challenges, and translate them into business risks. * Drive & Initiative: A highly proactive and self-motivated mindset - someone who actively looks for ways to improve our security posture and drive change. Deisrable: * Tooling: Direct, practical experience working with modern security compliance and automation platforms (such as Vanta or Drata). * Programming and automation: Experience with Python or a similar programming/scripting language, and/or using AI to improve productivity through automation. INTERVIEW PROCESS 1. Initial Chat all with a Recruiter 2. 15 minute Cognitive Assessment 3. 30 minute Hiring Manager call 4. 60 minute Technical Interview 5. 60 Culture-Add Interview LIFE AT LENDABLE * Winning team: the opportunity to scale up one of the world’s most successful fintech companies * Flexible working: flexible approach tailored to each role. Hybrid roles require three days in-office weekly; fully remote roles include regular opportunities for in-person connection through socials and off-sites * Socials & connection: opportunities and events to come together, socialise, and get to know each other beyond the office walls * Health coverage: support for your physical and mental wellbeing, including private health cover * Retirement & savings: long-term financial wellbeing through retirement savings plans * Employee referral programme: earn a competitive bonus when you refer successful new team members * Office meals & snacks: enjoy a fully stocked kitchen, plus complimentary lunches prepared by in-house chefs on in-office days at select locations * Sustainable commuting: cycle-to-work and electric vehicle salary sacrifice schemes available in select locations Please note: The availability and details of specific benefits vary by location and role. For more information, please speak to your Talent Partner. Check out our blog!
WHO WE ARE ABOUT STRIPE Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career. ABOUT THE TEAM Bridge Building S.A. (BBSA) is the Luxembourg regulated entity of Bridge, a Stripe company. We operate as an EMI and future CASP in one of Europe's most demanding regulatory environments (CSSF, DORA, MiCA). BBSA is building a local regulated platform powered by a global-first technology model. WHAT YOU'LL DO In this context, we're looking for an IT GRC Analyst to act as the bridge between strict European regulations and high-velocity global engineering. This role is the control and risk right hand of the Bridge Global CISO. While our global teams build the tech, you ensure it is compliant, resilient, and audit-ready. You'll translate requirements like DORA and MiCA into tangible IT controls, oversee third-party risks, and maintain the integrity of our governance framework. This is not a tick-the-box compliance role. It is an operational position for a professional who understands technology well enough to govern it effectively. You'll have high visibility, owning the frameworks that allow us to scale securely. RESPONSIBILITIES IT governance and risk management • Maintain and evolve the IT Risk Register, ensuring risks are identified, assessed, and treated in line with the company's risk appetite. • Drive the local implementation of the DORA (Digital Operational Resilience Act) framework, including ICT risk management and incident classification. • Bridge the gap between technical reality and policy by drafting, reviewing, and updating IT policies and procedures. • Perform periodic control testing to ensure global engineering practices align with local regulatory requirements. • Act as the primary support to the local Head of IT. Third-party risk management (TPRM) • Support ICT due diligence and risk assessments of critical vendors and service providers, while assisting with Developer and Customer Oversight. • Monitor service level agreements and performance metrics of critical vendors, challenging performance where necessary. • Act as the primary support to the outsourcing manager regarding technical vendor oversight. Access governance and control (IAG) • Oversee the identity and access governance strategy, including adherence to Segregation of Duties, principle of least privilege, and others. • Conduct periodic user access reviews for critical systems. Regulatory compliance and audit readiness • Act as the primary liaison for internal audit regarding IT topics. • Prepare technical inputs and evidence for CSSF notifications and regulatory reporting. • Monitor compliance with GDPR and data privacy controls (e.g., DLP oversight, data residency). • Coordinate business continuity (BCP) and disaster recovery (DR) testing documentation and reporting. Incident governance • Oversee the IT incident management process to ensure proper classification, reporting, and root cause analysis (RCA). • Ensure major incidents are reported to regulators within mandated timeframes, in collaboration with Compliance. WHO YOU ARE MINIMUM REQUIREMENTS * Bachelor's or Master's degree in Information Systems, Cybersecurity, or Business Administration, with a strong IT focus. * 3–6 years of experience in IT audit, IT risk, GRC, or information security. • High professional fluency in English. PREFERRED QUALIFICATIONS * Experience in a regulated sector (Banking, Fintech, or Insurance). * Experience at a large-scale public accounting firm in IT risk advisory. * Experience with CSSF circulars, EBA guidelines, or DORA. * Strong understanding of ISO 27001, NIST, or COBIT. * Understanding of cloud fundamentals (AWS).