Back to jobs

GRC Analyst

San Francisco, California
About Rocket Lawyer
 
We believe everyone deserves access to affordable and simple legal services. Founded in 2008, Rocket Lawyer is the largest and most widely used online legal service platform in the world. With offices in North America, South America, and Europe, Rocket Lawyer has helped over 30 million people create over 50 million legal documents, and get their legal questions answered.
 
We are in a unique position to enhance and expand the Rocket Lawyer platform to a scale never seen before in the company’s history, to capture audiences worldwide. We are expanding our team to take on this challenge!

About your role

Rocket Lawyer continues to rapidly grow its business into the legal tech world, leveraging our quickly developing AI technology. As part of this continued growth, more analysis is made by each of our customers on Rocket Lawyer’s security practice from a GRC standpoint. Additionally, as we continue to grow, our risk profile grows and must be managed appropriately.

Rocket Lawyer is looking for a motivated individual with a strong fundamental understanding of GRC to mature our program, along with the continued company growth. In 2025, we established our first proper GRC function on our journey to obtaining our first SOC2 Type II certification as a business. In 2026, we plan to obtain an ISO 27001 certification in addition to streamlining and building out all of our controls, as well as more closely staying on top of company risks.

How you will make a difference day to day

Risk Identification and Monitoring

  • Assist in identifying, assessing, and tracking risks across IT and enterprise functions.

  • Maintain risk register in GRC and CRQ tools, ensuring business understanding of all existing risks.

  • Perform threat modeling across different business applications.

  • Support maintenance of the enterprise risk register and dashboards used by leadership.

Governance and Compliance Support

  • Help draft, organize, and maintain policies, standards, and procedures.

  • Analyze, recommend, and implement security best practices.

  • Support compliance awareness campaigns and training that promote a culture of risk accountability.

Framework Alignment

  • Learn and assist in mapping controls to frameworks such as SOC2, NIST CSF, COBIT, ISO 27001, GDPR, CCPA, and ISO 42001.

  • Crosswalk and harmonize controls across multiple compliance frameworks.

  • Support tracking and validation of control effectiveness through GRC tools or reports.

Collaboration and Reporting

  • Partner with security leadership to prepare reports, metrics, and presentations for management.

  • Contribute to meetings with stakeholders across Legal, Finance, IT, and Operations.

  • Work with sales teams to respond to customer questionnaires for RL Security.

  • Responsible for reviewing vendor risk profiles and approving vendors for use at RocketLawyer.

Operational Support and Learning

  • Provide day-to-day administrative and research assistance to the security team.

  • Demonstrate initiative, curiosity, and a commitment to learning risk and compliance fundamentals.

Cross-Functional Security Responsibilities

  • While GRC is the primary focus of this role, Rocket Lawyer’s security team must be nimble and cross-trained across multiple disciplines.

  • You will likely be asked to learn tools that are not focused on GRC to provide backup if other team members are not around, or to just expand your knowledge and provide additional coverage.

  • All team members are expected to join team calls and contribute to the team’s overall success, regardless of whether a given topic is specific to their titled role.

What you’ll need

  • Bachelor’s or Graduate degree in Cybersecurity, Information Systems, or a related field, or relevant job experience.

  • 1-3 years of relevant experience (cybersecurity, audit, risk, compliance, GRC).

  • Solid understanding of fundamental security and IT concepts (access controls, data retention, change management, etc.).

  • Familiarity with major security and privacy frameworks (ISO, NIST, SOC 2, HIPAA, etc.).

  • Strong critical thinking, organization, and communication skills.

  • Ability to balance multiple projects and deadlines with exceptional follow-through.

  • Technical aptitude — you’re curious, you learn fast, and you don't shy away from new tools.

  • A passion for cybersecurity and a commitment to helping companies build safer, stronger environments.

  • Strong understanding of global data protection laws and regulations (e.g., GDPR, CCPA) and their technical implications.

  • Strong analytical, problem-solving, and communication skills, with the ability to work effectively across cross-functional teams.

  • Industry certifications (e.g., CISSP, CISA, CISM) are a plus.

Not sure if you meet all the qualifications? Apply anyway! We value diverse experiences and encourage you to bring your unique talents to our team!

Benefits & Perks

  • Comprehensive health plans (including Medical, Dental, and Vision insurance for full-time employees)
  • Unlimited PTO
  • Competitive salary packages
  • Life insurance
  • Disability benefits
  • Supplemental Optional Life Insurance Benefits
  • FSA Options Optional
  • HSA with Company Match
  • 401k program with Company Match
  • Wellhub & ClassPass fitness platforms
  • Comprehensive Pet Insurance options
  • Financial Wellbeing & Student Loan Program access
  • Access to additional Mental Health & Wellbeing resources
  • Pre-tax Commuter/Transit Benefits
  • Free Rocket Lawyer account with online access to an extensive legal documents library and brilliant licensed attorneys at discounted rates. 

Interview Process

  • Recruiter Phone Screen
  • Role Assessment(s)
  • Hiring Manager Interview
  • Panel Interviews
  • Final Interview
Rocket Lawyer is proudly committed to recruiting and retaining a diverse and inclusive workforce. As an Equal Opportunity Employer, we never discriminate based on race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, military or veteran status, status as an individual with a disability, or other applicable legally protected characteristics. We particularly welcome applications from veterans and military spouses.
 
All your information will be kept confidential according to EEO guidelines.
You may request reasonable accommodations by sending an email to hr@rocketlawyer.com.
 
Compensation
Base salary range by location:
  • San Francisco Bay Area, CA: $91,800 - $108,000 
  • California (outside of the San Francisco Bay Area) and Colorado: $78,030 - $99,900
  • Utah, Arizona, and North Carolina: $73,440 - $86,400

Actual compensation packages are determined by various factors unique to each candidate, including but not limited to skill set, depth of experience, certifications, specific work location, and performance during the interview process.

$73,440 - $108,000 USD

By applying for this position, your data will be processed as per Rocket Lawyer Privacy Policy

Create a Job Alert

Interested in building your career at Rocket Lawyer? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Rocket Lawyer’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.