Back to jobs
tags.new

Security GRC Analyst I

Virtual

Job Overview:

As a Security GRC Analyst I, you will play an important role in supporting and strengthening AvidXchange’s information security governance, risk, and compliance program. You will collaborate with teams across the organization to support audits, security awareness initiatives, reporting, risk assessments, and related compliance efforts. This role will contribute to a broad range of operational GRC activities, helping improve cybersecurity visibility, risk management, and program maturity across the organization.

What You’ll Do:

Security Awareness

  • Support administration of AvidXchange’s security awareness and phishing simulation program in KnowBe4, including training assignments, campaign design, and coordination.

  • Assist with building creative cybersecurity awareness communications, campaigns, and recurring outreach activities designed to engage a wide range of teammates and cyber knowledge levels.

  • Monitor participation, phishing, and engagement metrics to measure program effectiveness and identify improvement opportunities.

  • Contribute to ongoing enhancement of awareness content to keep training engaging, relevant, and aligned with emerging threats.

  • Enhance and support our Security Champion Program to empower security-focused individuals to make a difference in their team.

Risk, Assessment & Audit Support

  • Assist with cybersecurity risk assessments, audits, and third-party/vendor reviews.

  • Coordinate assessment and audit efforts through documentation, evidence gathering, and cross-functional collaboration.

  • Track remediation items, risk findings, audit observations, and follow-up efforts across teams.

Metrics, Reporting, & Communications

  • Develop and maintain cybersecurity metrics, dashboards, and reporting tailored to technical teams, leadership, and executive audiences.

  • Create visualizations, presentations, and other deliverables using tools such as Power BI, Excel, and PowerPoint.

  • Coordinate recurring reporting activities related to risk committees, audits, awareness initiatives, and operational metrics.

  • Analyze data to identify meaningful trends, gaps, and opportunities for program improvement.

General GRC Operations

  • Maintain cybersecurity documentation, policies, standards, repositories, and other governance materials.

  • Assist with customer and vendor due diligence activities, including questionnaire responses, customer assurance communications, and trust center maintenance.

  • Coordinate business continuity and incident response preparedness efforts, including tabletop exercises and related operational initiatives.

 

What We’re Looking For:

  • 1 – 3 years of experience in cybersecurity, including exposure to one or more of the following areas:

    • risk management (including third-party/vendor)

    • compliance and control frameworks

    • audit and assessments

    • security awareness programs

    • reporting, analytics, or operational support functions

  • Experience developing reports, dashboards, presentations, or visualizations using tools such as Excel or Power BI.

  • Strong verbal and written communication skills, with the ability to communicate effectively with technical and non-technical stakeholders.

  • Strong analytical and problem-solving skills, with the ability to identify risks, organize information, and support risk and compliance efforts.

  • Excellent organizational skills, with the ability to manage multiple priorities, deadlines, and cross-functional initiatives.

  • Comfortable working collaboratively across technical, operational, and business teams.

  • Familiarity with industry frameworks and regulations (e.g., NIST, NYDFS, SOC 1/2, PCI, ISO 27001) and comfort mapping controls to requirements.

  • Experience with or exposure to LogicGate or other GRC/TPRM tools.

  • Self-motivated and curious, with interest in cybersecurity, risk management, and evolving industry trends.

  • Relevant certifications such as Security+, ISC2 CC, CISA, or similar certifications are preferred.

 

About AvidXchange

AvidXchange is a leading provider of accounts payable (“AP”) automation software and payment solutions for middle-market businesses and their suppliers. By trade, we are a technology company, but if you ask anyone who works here, they’ll tell you our people are at the core of who we are. At AvidXchange, mindset is everything. We are Connected as People, Growth Minded, and Customer Obsessed. These three mindsets represent our culture – who we are, who we’ve always been, and they guide us to improve every day. Since our founding in 2000 in Charlotte, NC, we’ve created a company of over 1,500 teammates working across the U.S., or remotely. AvidXchange is proud to be Certified™ as a Great Place to Work®. The prestigious recognition is based on anonymous data from our teammates and makes official what our teammates have known for years – that AvidXchange is a Great Place to Work®. 

Who you are: 

  • A go-getter with an entrepreneurial mindset – that means you are not afraid of taking risks, winning big or facing the unknown. 
  • Someone who understands that business is people centric. Connecting with others as humans first allows you to develop mutually beneficial working relationships. 
  • Focused on making a difference for our customers. AvidXchange exists to help solve complex problems for our customers so we can all realize our potential. 

What you’ll get:  

AvidXchange teammates (we call them AvidXers) get the perks and prestige of a growing tech company paired with the flexibility of a founder-led startup. We help our AvidXers develop as professionals and as human beings, providing work/life balance, development programs, and competitive benefits. At AvidXchange, we are building more than a tech company – we are building an experience. We remain committed to a culture where you can fully be 'you’ – connected with others, chasing big goals, and making a meaningful impact. If you want to help us grow while realizing your potential and creating stories you’ll tell for years, you’ve come to the right place.

AvidXers enjoy:  

  • 18 days PTO* 
  • 11 Holidays (8 company recognized & 3 floating holidays) 
  • 16 hours per year of paid Volunteer Time Off (VTO) 
  • Competitive Healthcare 
    • High Deductible Heath Plan Option that has $0 monthly premium for teammate-only coverage 
    • 100% AvidXchange paid Dental Base Plan Coverage
    • 100% AvidXchange paid Life Insurance 
    • 100% AvidXchange paid Long-Term Disability 
    • 100% AvidXchange paid Short-Term Disability  
    • Employee Assistance Program (EAP) - Provides counseling services, legal and financial consultations and health advocacy for Teammates and their eligible dependents
    • Onsite Health Clinic with Atrium Health - available to Teammates and their eligible dependents
  • 401(k) Match: 100% match on the first 3% of your salary, plus 50% match on the next 2%
  • Parental Leave: 8 weeks 100% paid by AvidXchange** 
  • Discounts on Pet, Home, and Auto insurance 
  • WeeCare Childcare Service: helps teammates find affordable daycare, childcare, and tutors 40% less expensive than traditional daycare centers 
  • Perks at Work: free discount program that provides teammates the opportunity to save on items from electronics, movie tickets, car buying, vacations, and more 
  • Onsite gym fitness center, yoga studio, and basketball court
  • Tuition Reimbursement up to the federal maximum of $5,250***
  • Hybrid Workplace Flexibility
  • Free parking

*Fully granted from beginning of year, pro-rated if hired mid-year 

**Must be full-time for at least 3 months

***Must be full-time for at least one year 

Equal Employment Opportunity

AvidXchange is an equal opportunity employer. AvidXchange is committed to equal employment opportunity in accordance with applicable federal, state, and local laws. AvidXchange will not discriminate against applicants for employment on any legally recognized basis. This includes, but is not limited to veteran status, race, color, religion, sex, sexual orientation, gender identity, gender expression, national origin, age and physical or mental disability. 

Create a Job Alert

Interested in building your career at AvidXchange, Inc.? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...