Back to jobs
New

Governance, Risk, Compliance & Trust Analyst

Oakland, California, United States

At Everlaw, our mission is to promote justice by illuminating truth. We build technology that helps legal teams find the information they need to achieve their truth-finding goals.

As a GRCT Analyst, you will independently drive moderately complex trust, compliance, and risk workstreams that help Everlaw scale responsibly and earn customer and regulator trust over time. This role sits at the intersection of customer trust, compliance operations, audit readiness, risk management, documentation quality, and cross-functional execution.

You will help translate Everlaw’s security and compliance posture into clear, accurate, audit-ready, and customer-ready outputs. You will also help the GRCT team operate in a way that reflects Everlaw’s long-term philosophy: acting with integrity and discipline, paying attention to detail, improving process over time, setting a high bar for quality, and partnering with others in an egoless and respectful way.

This is a career-core individual contributor role for someone who can own work end to end with limited oversight, navigate ambiguity, communicate clearly with stakeholders, and improve how trust and compliance work gets done over time.

Getting started

  • We want you to feel like part of the team early on! Our onboarding process will integrate you into the company with informative sessions on our product, policies, processes, and team structure and goals. 
  • We’re excited for you to learn, grow, and contribute right away! We trust that you’ll bring experience and knowledge that will uplift and uplevel the team, but we don’t expect you to know everything on Day 1.

In your role, you'll...

Compliance

  • Support audit readiness across core frameworks such as FedRAMP, SOC 2, and ISO 27001/27017/27018 by organizing evidence, maintaining documentation quality, and partnering with control owners to close gaps.
  • Manage compliance operations that require structured follow-through, including evidence requests, policy and procedure updates, control narrative maintenance, and recurring review cycles.
  • Partner cross-functionally with Security Engineering, DevOps, IT, Legal, People, Procurement, and other stakeholders to gather inputs, validate implementation details, and produce audit-ready or stakeholder-ready outputs.
  • Help maintain strong execution against defined compliance SLAs, milestones, and recurring obligations, escalating risks early and driving issues through resolution.
  • Translate technical, operational, and regulatory topics into clear written deliverables for internal and external audiences, including concise summaries of requirements, risks, tradeoffs, and recommendations.
  • Support internal risk and governance processes, including security impact analyses, change-related compliance reviews, and other structured review workflows as assigned.
  • Contribute to the on-going operation of the Public Sector Clearance Program, to include guiding new cohorts through the program, maintaining status and tracking open issues, and communicating program updates to Everlaw stakeholders.

Customer Trust

  • Manage customer security questionnaires, trust inquiries, and related diligence requests with minimal supervision, including researching answers, validating claims, gathering evidence, and producing accurate, customer-ready responses.
  • Maintain and improve customer-facing trust content across repositories, trust portals, knowledge resources, and standard response libraries so that recurring requests can be answered more consistently and efficiently.
  • Partner closely with Security Engineering, DevOps, Legal, GTM, Product, IT, and other stakeholders to collect inputs, resolve ambiguities, and ensure trust responses reflect current implementation and approved positioning.
  • Help maintain strong execution against trust-related SLAs and operating expectations, including turnaround time, response quality, and internal coordination on high-priority or high-visibility requests.
  • Identify gaps, inconsistencies, or stale content in trust materials and proactively drive updates so that customer-facing representations remain accurate, supportable, and easy to reuse.
  • Support broader trust enablement initiatives, including trust center improvements, evidence library maintenance, standardization of response content, and process improvements that reduce manual effort and rework.
  • Use workflow data and request trends to identify recurring customer concerns, bottlenecks, and improvement opportunities, then recommend practical changes to content, process, or tooling.
  • Manage customer security questionnaire and trust inquiry workflows with minimal supervision, including researching answers, synthesizing evidence, improving repository content, and helping stakeholders receive timely and accurate responses.

Vendor Reviews

  • Own end-to-end delivery of moderately complex vendor review workstreams, including intake review, scoping, dependency management, stakeholder coordination, and timely completion with limited oversight.
  • Conduct security and compliance reviews of third parties by gathering and analyzing documentation such as security questionnaires, architecture details, data flow information, attestations, policies, and contractual commitments.
  • Evaluate vendor security posture against Everlaw requirements for confidentiality, integrity, availability, privacy, access control, incident response, change management, and regulatory obligations.
  • Partner with Procurement, Legal, Security Engineering, IT, business owners, and other stakeholders to validate proposed use cases, clarify data access patterns, and ensure risks are understood before onboarding or renewal decisions are made.
  • Help determine whether vendor controls, architecture, access models, and contractual terms are appropriate for the intended use case, and clearly document identified gaps, assumptions, compensating controls, and recommended next steps.
  • Maintain strong execution against vendor review SLAs, queue expectations, and recurring review obligations, escalating blockers and higher-risk issues early.

Security Training

  • Own end-to-end delivery of moderately complex security training program workstreams, including planning, content coordination, stakeholder alignment, rollout tracking, and continuous improvement with limited oversight.
  • Support the design, maintenance, and execution of security and compliance training required for Everlaw personnel, with particular attention to role-based, environment-specific, and regulatory training obligations.
  • Maintain training content so it is accurate, current, and aligned with Everlaw policies, operational practices, and external requirements such as FedRAMP, CJIS, export control, and related obligations where applicable.
  • Partner with GRCT, Legal, HR, Security, IT, and business stakeholders to gather subject matter input, validate training expectations, and ensure training materials reflect approved guidance and current operating reality.
  • Coordinate recurring training cycles, onboarding-related assignments, acknowledgements, re-certifications, and related evidence collection so completion records are reliable, reviewable, and audit-ready.
  • Help maintain strong execution against program deadlines, annual and periodic training obligations, and related audit or assessment requests by tracking status, identifying gaps early, and driving follow-through.
  • Contribute to a training program that reinforces Everlaw principles by promoting disciplined execution, clear communication, respect for users, and a high bar for secure handling of sensitive data.

About you

  • You have 5+ years of experience working as an individual contributor with a Governance, Risk, Compliance and Trust team  
  • You have strong working knowledge of customer trust, compliance operations, risk, and the evidence and control narratives needed to support questionnaires, reviews, and audits
  • You have experience supporting FedRAMP, SOC 2, ISO 27001/27017/27018, or similar compliance frameworks.
  • You have led the completion of customer security questionnaires and have worked within trust portals, evidence repositories, or other GRC tooling software.
  • You have experience using workflow, metrics, or dashboard data to improve trust and compliance operations and to meet defined SLAs.
  • You can independently research moderately complex questions, synthesize inputs from multiple stakeholders, and produce high-quality written deliverables with a high bar for clarity and accuracy.
  • You communicate complex topics simply and concisely, tailor your communication to the audience, and navigate moderate disagreement while keeping focus on shared outcomes.
  • You are organized and reliable, maintain momentum across planned work and ad hoc requests, and escalate thoughtfully before risks become blockers.
  • You think beyond the immediate request and consider how current decisions affect future operations, compliance posture, and stakeholder experience.
  • You are comfortable operating in environments with some ambiguity, shifting priorities, and multiple stakeholders.
  • You bring sound judgment, professional maturity, and a strong sense of accountability when handling sensitive or high-visibility work.

Benefits

  • The expected salary range for this role is between $140,000 - $178,000. The final offered salary will be dependent upon many factors including the candidate’s experience and skills. The base pay range is subject to change in the future.
  • Equity program
  • 401(k) retirement plan with company matching
  • Health, dental, and vision
  • Flexible Spending Accounts for health and dependent care expenses
  • Paid parental leave and approximately 10 days (80 hours) per year of sick leave
  • Seventeen paid vacation days plus 11 federal holidays
  • Membership to Modern Health to help employees prioritize mental health and wellness
  • Annual allocation for Learning & Development opportunities and applicable professional membership dues
  • Company-sponsored life and disability insurance
  • Find out more about our Benefits and Perks

Perks

Pursue Truth While Finding Yours
At Everlaw, we are deeply invested in pursuing the truth, for our clients and for our employees. We know that when you’re empowered to pursue your passions, it is reflected in the work. That’s why we’re committed to the professional growth of all our team members, offering an annual learning and development stipend and regular career check-ins with managers. If you’re looking for a place that values passion, integrity, and a desire to learn, we’d love to hear from you! 
 
We help law firms, government agencies, and corporations sift through millions of documents of evidence in big lawsuits and investigations to find the proverbial smoking gun (or needle in the haystack -- pick your metaphor). It's a multi-billion dollar space typically dominated by service-oriented vendors, and we're coming at it with cutting-edge technology and elegant design. It's working, and we've been growing very rapidly: we host hundreds of terabytes of data and work with all 50 state Attorneys General and hundreds of law firms on some of the most high-profile cases litigated today. 
 
Everlaw is an equal opportunity employer. We pride ourselves on having a diverse workforce and we do not discriminate against any employee or applicant because of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law. We respect the gender, gender identity and gender expression of our applicants and employees, and we honor requests for pronouns. It is our policy to comply with all applicable national, state and local laws pertaining to nondiscrimination and equal opportunity, including the California Equal Pay Act.  Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
 
We collect and process the personal information you provided along with your job application in accordance with our Applicants Privacy Notice and Notice at Collection.
 
When preparing to engage with Everlaw as a candidate, you may use AI tools for research, polishing application materials, and interview prep. However, any assessments (unless explicitly stated), remote interviews or live interviews must be completed independently without AI support. By submitting your application, you agree to adhere to these rules. Here's the link to our full policy, and please reach out with any questions!
 
We use Covey as part of our hiring and/or promotional processes. As part of the evaluation process, we provide Covey with job requirements and candidate-submitted applications. Certain features of the platform may qualify it as an Automated Employment Decision Tool (AEDT) under applicable regulations. For positions in New York City, our use of Covey complies with NYC Local Law 144. We began using Covey Scout for Inbound on the 9th of June, 2025.
 

Create a Job Alert

Interested in building your career at Everlaw? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Please attach a sample (can be an individual file or zip/gzip of multiple files) of some code you've written, along with a README file or comment describing the sample.

Accepted file types: pdf, doc, docx, txt, rtf

Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Everlaw’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.