Back to jobs

Senior Governance, Risk and Compliance Analyst

Denver, CO

About us

At Udemy, we’re on a mission to transform lives through learning. Through our intelligent skills platform and a global community of instructors, we’ve helped nearly 80 million learners and more than 17,000 organizations achieve their goals. Come join us in ensuring everyone, everywhere has access to the skills they need to unlock their potential and create possibilities for themselves and others. Learn more about us on our company page.

Where we work

Udemy is a global company headquartered in San Francisco, with additional U.S. offices in Denver and Austin, and international hubs in Australia, India, Ireland, Mexico, and Türkiye. This is an in-office position, requiring three days a week in the office (Tuesday, Wednesday, Thursday) and flexibility on Mondays and Fridays.

About your skills

  • Consulting: You see beyond the present problem and identify the fundamental ‘why’. You are a creative thinker and co-design potential solutions with the stakeholders.

  • Influencing: You develop relationships effectively up, down, and across the organization and are able to strategically use these relationships to help move work forward. You scope solutions to  “get to yes” and are capable of pushing back on disagreement if they will not provide the outcome needed for the team or the business. 

  • Decision Making: You use critical thinking to follow a defined decision making process and consider multiple perspectives. Upon making a decision, you are clear in your communication and ensure everyone is aligned in execution.

  • Coaching: You have strong coaching skills allowing you to actively listen and ask the kind of questions to help you diagnose and effectively address issues. 

Preferred Qualifications:

  • Audit Experience: Experience with third-party audits or as an internal auditor, particularly within the technology sector.

  • Certifications: Relevant certifications such as CISA, CISSP, or equivalent are desireable.

About this role 

The GRC Senior Analyst will be responsible for leading the GRC team in achieving and maintaining compliance with key third-party certifications. You will work closely with system and control owners across the organization to document, update, and maintain control language, policies, procedures, and other essential documentation. Your role will involve significant interaction with third-party auditors and internal stakeholders, requiring superior written and verbal communication skills. You will also interface with customers, requiring a professional and positive attitude, particularly under pressure.

\What you’ll be doing 

  • Certification Support: Lead in the preparation, submission, and maintenance of key third-party certifications, including CMMC (Cybersecurity Maturity Model Certification) and assisting in SOC 2, ISO 27001, and other frameworks.

  • Documentation Management: Collaborate with system and control owners to document and update control language, policies, procedures, and other documentation required for certifications and audits.

  • Audit Lead: Serve as a primary point of contact during internal and external audits, effectively communicating with third-party auditors and ensuring audit requirements are met.

  • Cross-Functional Collaboration: Work closely with teams across the organization, including IT, security, and operations, to ensure all compliance-related activities are aligned with business goals and regulatory requirements.

  • Customer Interaction: Interface with customers to address compliance-related inquiries, providing clear and concise information with a professional demeanor.

  • Process Improvement: Continuously evaluate and improve GRC processes, ensuring they are efficient, scalable, and aligned with industry best practices.

  • Risk Management: Lead in identifying, assessing, and mitigating risks related to compliance, working with relevant stakeholders to implement necessary controls.

  • Compliance Monitoring: Maintain up-to-date knowledge of regulatory changes and ensure that the company’s policies and procedures remain compliant.

What you’ll have 

  • Experience: 7+ years of experience in a GRC, compliance, or audit-related role, with a focus on CMMC, NIST, FedRAMP, or similar frameworks.

  • Communication Skills: Superior written and verbal communication skills, with the ability to interact professionally with auditors, customers, and internal teams.

  • Documentation Skills: Excellent attention to detail in documenting controls, policies, and procedures, with the ability to translate complex concepts into clear and actionable language.

  • Calm Under Pressure: Proven ability to remain calm, collected, and professional under pressure, particularly during audits and customer interactions.

  • Collaboration: Ability to work cross-functionally with various departments and teams to achieve compliance objectives.

At Udemy, we strive to be transparent around compensation. Actual compensation for this role is based on several factors, including but not limited to job-related skills, qualifications, experience, and specific work location due to differences in the cost of labor. In addition to a base salary, this role is also eligible for benefits and equity.

Hiring Compensation Range

$133,000 - $166,000 USD

We understand that not everyone will match each of the above qualifications. However, we also realize that everyone has unique experiences that can add value to our company. Even if you think your background might not perfectly align, we'd love to hear from you!

Life at Udemy 

We aspire to be as vibrant and dynamic as the communities we serve, as inquisitive as those who use our platform, and as revolutionary as the future we strive to open for everyone. Here are some of the things we love about life at Udemy:

  • We’re invested in creating an inclusive environment that welcomes a diverse range of backgrounds and experiences. From creating employee resource groups, ensuring we’re a Fair Pay Workplace, and building a flexible work culture, our belonging, equity, diversity, and inclusion (BEDI) initiatives always put our people first. We want you to be able to bring your authentic self to work because when we all do, we’re better for it.

  • Learning is what we do – inside and out. Our Learning & Development team is second to none, helping ensure your journey is one of continuous progression. You’ll also have unlimited access to Udemy courses, monthly UDays (meeting-free professional development days), and a generous annual professional development stipend.

  • Our reason to exist is to revolutionize learning – that calls for taking risks and learning from failures. Whether it’s our hackathons (a company-wide effort to envision new possibilities for our product) or sharing our prototypes, we see experimentation as a crucial step on the path to success.

  • We’re committed to creating world-class employee experiences and are proud of the recognition of this by Great Place to Work. 

Of course, the best thing about being part of Udemy is knowing your work makes a difference for people and organizations around the world. You’ve got the skills; why not use them to help others develop theirs?

At Udemy, we value diversity and inclusion and consider qualified applicants without regard to race, color, religion, sex, national origin, ancestry, age, genetic information, sexual orientation, gender identity, marital or family status, veteran status, medical condition, or disability. 

Our Benefits Start with U

Our benefits start with you and were built to provide you and your family with the protection and care you need, making it easy to access the right coverage when you need it most. Benefits vary by region, and we encourage applicants to review our US Benefits,  Ireland Benefits & Turkiye Benefits pages to get an understanding of some of the benefits we offer. For details on region-specific benefits, please refer to the information provided during the hiring process. 

Benefits outlined are provided as a general overview and may vary depending on the location, role, and employment classification. All benefits are subject to change at the discretion of the organization and in accordance with applicable laws and policies.

Information regarding data privacy is available within the Udemy Careers Privacy Notice.

Apply for this job

*

indicates a required field

Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

We want to understand all of the ways that you have interacted or been exposed to Udemy so that we can continue to invest in efforts that resonate with candidates.

Select...
Select...

Saying "No" to this question indicates you are eligible to working and do not require sponsorship

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in BEDI Partnerships’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.