Senior GRC Analyst

<h2><strong>Why Now</strong></h2><p style="min-height:1.5em">2026 has been a breakout year for Doppler. We’ve helped over 78,000 startups and enterprises manage their secrets at scale, and landed our first million-dollar customer. We've shipped some of our most exciting features yet, expanded our customer base, and sharpened our focus like never before. With a strong foundation in community, we're scaling and monetizing with ambitious goals across product, growth, sales, and hiring. The momentum is real and we’re just getting started.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>About Doppler</strong></p><p style="min-height:1.5em">Doppler's mission is to make it easy and secure for software developers of every experience level and teams of any size to manage their app configuration and secrets. But hasn't this been done?</p><p style="min-height:1.5em"></p><p style="min-height:1.5em">Developers tend to be either <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.doppler.com/blog/the-triumph-and-tragedy-of-env-files">struggling with the manual management of .env files</a>, or <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.doppler.com/blog/doppler-vs-hashicorp-vault">wrestling with an overly complex secrets manager</a> that's not built for software development. The rise of AI tooling has fundamentally expanded who and what has access to your secrets. The stakes have never been higher, and getting it wrong has real consequences. Doppler is the solution to fix this. Simple to adopt, easy to scale, and built for developers, by developers.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em">Our team is entrepreneurial, with a bias for action. We never back down from a spirited debate and believe we are all responsible for exploring the hard questions. We value self-awareness and meaningful impact. We are open to unconventional approaches and have learned not to judge a book by its cover. Your time is your most valuable resource, so you set your hours. We use Slack to communicate and default to zero meetings. We aim to document everything. We also recommend you invest your time in <a target="_blank" rel="noopener noreferrer nofollow" href="https://medium.com/accelerated-intelligence/why-successful-people-spend-10-hours-a-week-on-compound-time-79d64d8132a8">10% compounding time</a>.</p><p style="min-height:1.5em"></p><h2><strong>Who We Are</strong></h2><p style="min-height:1.5em">Doppler is a developer-first secrets management platform that enables engineers and security teams to securely store their secrets across any cloud infrastructure or deployment environment at scale.</p><p style="min-height:1.5em"></p><h2><strong>The Role</strong></h2><p style="min-height:1.5em"></p><p style="min-height:1.5em">At Doppler, security is core to what we ship, not an afterthought - it's woven into our product. Customers come to us to be the trusted custodian of their most sensitive credentials: API keys, database passwords, service tokens. That means our compliance posture is something prospects scrutinize during procurement and something customers depend on to justify their trust. This role owns all of it.</p><p style="min-height:1.5em">As our Senior GRC Analyst, you'll be the owner of Doppler's security and compliance program; maintaining our SOC 2 Type II and ISO 27001 certifications, driving our next compliance initiatives, and acting as the internal expert and external face of security for enterprise customers. You'll work closely with engineering, product, sales, and customer success, and you'll bring an automation-first mindset to everything, building systems that reduce manual toil and move us toward continuous compliance rather than point-in-time audits.</p><p style="min-height:1.5em">This is an individual contributor role with meaningful company-wide impact. The person who thrives here is equally comfortable diving into a pen test report with engineers and presenting risk posture to leadership.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><strong>What you’ll do:</strong></p><p style="min-height:1.5em"></p><p style="min-height:1.5em"><em><strong>Compliance program ownership</strong></em></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Maintain Doppler's SOC 2 Type II and ISO 27001 certifications end-to-end: evidence collection, control monitoring, audit coordination, and deficiency remediation</p></li><li><p style="min-height:1.5em">Lead the compliance work for our next certifications, including gap assessments, policy updates, and required documentation</p></li><li><p style="min-height:1.5em">Evaluate additional certifications and attestations on an ongoing basis as customer and market requirements evolve</p></li><li><p style="min-height:1.5em">Own day-to-day administration of our GRC platform (Vanta), including control mapping, evidence workflows, and audit readiness</p></li></ul><p style="min-height:1.5em"><em><strong>Risk and controls</strong></em></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Lead our security working group: facilitate regular risk identification sessions, policy updates, maintain the threat register, track remediation progress, and drive accountability across teams</p></li><li><p style="min-height:1.5em">Design and maintain security controls mapped to our chosen frameworks (SOC 2, ISO 27001, etc.), ensuring they're practical and consistently operating</p></li><li><p style="min-height:1.5em">Coordinate penetration testing cycles and work directly with engineering to track and close findings</p></li><li><p style="min-height:1.5em">Author and maintain security policies that are enforceable and grounded in regulatory requirements (GDPR, PCI, and others relevant to a secrets management provider)</p></li><li><p style="min-height:1.5em">Support business continuity and disaster recovery governance</p></li></ul><p style="min-height:1.5em"><em><strong>Customer and sales enablement</strong></em></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Respond to security questionnaires and RFPs promptly and accurately. Doppler's customers are technical and expect precision</p></li><li><p style="min-height:1.5em">Participate in customer security reviews and calls; represent our compliance posture credibly to security teams, procurement, and compliance officers</p></li><li><p style="min-height:1.5em">Maintain public-facing trust documentation that reflects our actual program</p></li><li><p style="min-height:1.5em">Partner with sales on security-sensitive enterprise deals, especially in regulated industries or where compliance is a gating factor</p></li></ul><p style="min-height:1.5em"><em><strong>Enablement and communication</strong></em></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Translate compliance status and risk posture into clear, non-jargon updates for leadership and cross-functional stakeholders</p></li><li><p style="min-height:1.5em">Lead security awareness and compliance training for internal teams</p></li><li><p style="min-height:1.5em">Influence engineering and product roadmaps where security controls intersect with product decisions</p></li></ul><p style="min-height:1.5em"><br><strong>What you’ll bring to the table:</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">5+ years in security, compliance, or GRC, with direct ownership of SOC 2 Type II and ISO 27001 programs in a cloud product environment where you've run audit cycles, not just supported them</p></li><li><p style="min-height:1.5em">Hands-on experience with Vanta (or a comparable GRC platform) and a genuine interest in automating compliance workflows rather than relying on spreadsheets</p></li><li><p style="min-height:1.5em">Technical fluency: you can read a pen test report, understand cloud architecture decisions, and have substantive conversations with engineers about control design and risk tradeoffs</p></li><li><p style="min-height:1.5em">Strong understanding of how auditors think, ideally from having been on the auditor side, or from running enough cycles that you've internalized their perspective</p></li><li><p style="min-height:1.5em">Familiarity with PCI DSS and GDPR requirements; experience with self-attestation or certification work is a strong plus</p></li><li><p style="min-height:1.5em">Experience supporting enterprise sales cycles where security is a procurement requirement, including responding to complex security questionnaires</p></li><li><p style="min-height:1.5em">Excellent communication skills across audiences. You can brief the CEO on risk posture and turn around and explain the same issue to an engineer in implementation terms</p></li><li><p style="min-height:1.5em">Relevant certifications (CISA, CISSP, CISM, CRISC, or equivalent) preferred</p></li></ul><p style="min-height:1.5em"><br><strong>Preferred experience:</strong></p><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Startup or high-growth environment experience</p></li><li><p style="min-height:1.5em">Experience with developer tools or infrastructure security background</p></li><li><p style="min-height:1.5em">Experience with trust center management</p></li><li><p style="min-height:1.5em">Familiarity with secrets management, credential security, or PKI.</p><p style="min-height:1.5em"></p></li></ul><h2><strong>Benefits </strong></h2><ul style="min-height:1.5em"><li><p style="min-height:1.5em">Equity at an early-stage, fast-growing startup</p></li><li><p style="min-height:1.5em">Premium health insurance (medical, dental, vision)</p></li><li><p style="min-height:1.5em">Guilt Free Unlimited PTO - 3-week minimum strongly encouraged!</p></li><li><p style="min-height:1.5em">Upward Mobility</p></li><li><p style="min-height:1.5em">Learning and Development Stipend</p></li><li><p style="min-height:1.5em">Wealth Advisor</p></li><li><p style="min-height:1.5em">401k</p></li><li><p style="min-height:1.5em">Pregnancy & Family Leave</p></li><li><p style="min-height:1.5em">Fertility & Adoption Benefits</p></li><li><p style="min-height:1.5em">Equal Compensation (regardless of gender or race)</p></li></ul><p style="min-height:1.5em">For a full list of our benefits check our <a target="_blank" rel="noopener noreferrer nofollow" class="postings-link" href="https://dopplerteam.notion.site/Perks-15eb027f917d4b3bac69d0186115d7de"><u>Perks Notion Page</u></a>.</p><p style="min-height:1.5em"></p><h2><strong>Closing </strong></h2><p style="min-height:1.5em">We've built a great product our customers love. Our churn is low, and active usage continues to rise. We just need to amplify our reach to educate the market that secrets management can be fast, secure, and affordable for teams and organizations of any size. And most importantly, we need to continue encouraging Developers to stop adhering to archaic insecure standards such as manually managing .env file formats.</p><p style="min-height:1.5em"></p><p style="min-height:1.5em">Are you passionate about developer-focused products and ready to join an amazing team? Then we want to hear from you!</p><p style="min-height:1.5em"></p><p style="min-height:1.5em">A final note - we highly encourage you to apply for this role, even if you don't feel entirely qualified, or entirely sure. You never know!</p>

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...