Stop applying to remote jobs that are already dead.
Every listing shows the evidence: when we last checked it, how, and when it was posted and closed.

All listings

Tessera Labs via Ashby

Technical GRC Analyst (Compliance & Assurance)

Brazil Level not stated
still open verified 2d ago posted 39d ago seen just now
Apply at jobs.ashbyhq.com

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 2d ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 39d ago

The date the source published, not the day we noticed it (2026-09-01). Last seen at its source just now.

We have tracked this listing since 5 Oct 2026 (5 days). The employer's own board has carried it every time we have read it, most recently just now.

Is it remote?

Marked remote on the employer's board

Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.

Who may apply?

Brazil

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay $110k–202.5k/yr

Middle 50% of 557 listings that do state pay — Legal & Compliance · all levels · Americas · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

Regulatory ComplianceRisk Management

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

Technical GRC Analyst (Compliance & Assurance)

As part of the Tessera Lab Compliance & Assurance team, you'll help build and maintain trust by partnering across the business to provide practical, risk-based compliance and assurance that enables the company to scale with confidence.

As a Technical GRC Analyst, you'll partner with Security, Engineering, Product, and business teams to evaluate technical controls, validate evidence, assess risk, and continuously improve the organization's compliance and assurance program.

This is a hands-on role for someone who enjoys understanding how technology works, asking thoughtful questions, solving problems, and helping build a modern compliance program that scales with the business.

Your Focus Areas

  • Technical Control Assurance and Risk Assessments

  • AI Governance & Emerging Technologies (ISO 42001)

  • Technical Customer Assurance

  • Program Intelligence, Metrics & Analytics

  • Compliance Automation & Continuous Improvement

Key Responsibilities

  • Evaluate the design and operating effectiveness of technical controls.

  • Review and validate evidence to assess whether controls are implemented, operating effectively, and appropriately documented.

  • Perform technical risk assessments for new technologies, systems, and business initiatives.

  • Partner with Engineering and Security to ensure technical controls align with compliance requirements and industry best practices.

  • Support and continuously improve the company’s AI governance program — AI policies, acceptable-use standards, risk assessments, vendor evaluations, and security controls aligned with ISO 42001.

  • Transform compliance data into meaningful insights that support business decisions and program maturity.

  • Identify opportunities to automate compliance activities and improve operational efficiency.

  • Support internal assessments, customer due diligence, and external audits.

What You'll Bring

Experience

  • 8+ years of experience in technical security, Security GRC, regulatory compliance, or a related discipline.

  • Experience evaluating technical controls and validating supporting evidence.

  • Experience performing technical risk assessments and working with cross-functional teams.

  • Experience working in technology organizations with modern cloud and enterprise environments.

  • Exposure to FedRAMP authorization activities including NIST 800-53 control implementation, SSP development, evidence collection, POA&M management, or readiness assessments is highly desirable.

Working knowledge in several of the following areas:

  • Cloud and security architecture concepts

  • Vulnerability and risk management

  • Secure software development and DevSecOps concepts

  • Data protection and encryption

  • AI governance and emerging technologies

  • Dashboard development, reporting,analytics and automation

You're someone who:

  • Enjoys understanding how technology works and asking thoughtful questions.

  • Can translate technical concepts into practical compliance conversations

  • Exercise sound judgment when evaluating controls, validating evidence, and balancing compliance requirements with practical business needs.

  • Builds trusted relationships across teams.

  • Takes ownership and enjoys improving processes.

  • Thrives in a fast-paced startup environment.

What Success Looks Like

  • Technical controls are consistently evaluated and continuously improved.

  • Leadership has meaningful visibility into technical risks and control effectiveness.

  • Dashboards and metrics support informed business decisions.

  • Customer and audit activities are well supported through high-quality evidence and strong technical assurance.

Apply at jobs.ashbyhq.com