Root Logo

Root

GRC Analyst II

Reposted Yesterday
Remote
Hiring Remotely in United States
110K-130K Annually
Mid level
Remote
Hiring Remotely in United States
110K-130K Annually
Mid level
The GRC Analyst II will contribute to Root's information security risk management processes, conduct risk assessments, support compliance with regulatory requirements, manage information security policies, and report on the effectiveness of the control environment while fostering a risk-aware culture.
The summary above was generated by AI

CURRENT ROOT EMPLOYEES - Please apply using the career page in Workday. This career site is for external applicants only.


 

The Opportunity

We are looking for a GRC Analyst II to join Root’s Information Security team. Root’s InfoSec team manages information security risk within the organization, while enabling development and product teams to do their cutting-edge work. In this role, you’ll be a key contributor to the execution and continued development of Root’s risk management processes, compliance program, and governance activities to appropriately manage risk and address regulatory requirements.

Root is a “work where it works best” company. This means we will support you working in whatever location that works best for you across the US.

Salary Range: $110,000 - $130,000 (Bonus and LTI Eligible)

How You Will Make an Impact

  • Contribute to the ongoing development and maturation of Root’s information security risk management processes to appropriately manage risk in alignment with the organization's risk appetite and continuously monitor the risk landscape/control environment

  • Aid in conducting risk assessments across the organization, working with a variety of teams/functions to identify, evaluate, and mitigate risks

  • Support compliance with Root’s information security regulatory requirements, performing readiness assessments, ensuring policies and controls adequately address relevant requirements, reporting on Root’s compliance status, and tracking remediation efforts as necessary

  • Assist in the ongoing development and management of Root’s information security control framework

  • Perform analysis of the information security control environment to monitor effectiveness, identify gaps, and inform compliance reporting

  • Coordinate issue management/risk mitigation activities, collaborating with teams across the organization to manage and track remediation efforts to completion

  • Maintain information security policies and standards

  • Support control design and effectiveness testing of information security controls

  • Coordinate the reporting of key metrics related to the control environment

  • Aid in responding to regulatory exams and other third-party audits

  • Contribute to the creation of a risk-aware culture and advocate for applying risk management practices and a risk-based approach to security

What You Will Need to Succeed

  • 3+ years of experience in executing information security risk management activities, including risk assessment, response, and monitoring processes

  • Proficient in information security control frameworks, standards, and regulations (such as NIST CSF, PCI DSS, and insurance data security laws or similar)

  • In-depth experience designing and evaluating controls to reduce information security risk

  • Excellent problem solving skills and attention to detail

  • Experience developing reports and metrics including data analysis and data visualization

  • Self-motivated; naturally collaborative, ability to influence without direct authority

  • Proven ability to balance security with the ongoing needs of the business while maintaining compliance and meeting risk management requirements

  • Active security certification (CISM, CISSP, CIA, CISA, etc.) preferred

  • Familiarity with applying security controls in public cloud environments (e.g. AWS)

As part of Root's interview process, we kindly ask that all candidates be on camera for virtual interviews. This helps us create a more personal and engaging experience for both you and our interviewers. Being on camera is a standard requirement for our process and part of how we assess fit and communication style, so we do require it to move forward with any applicant's candidacy. If you have any concerns, feel free to let us know once you are contacted. We’re happy to talk it through.


 

Don’t meet every single requirement?

Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At Root, Inc., we are dedicated to building a diverse and inclusive workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway!

Join us

At Root, we judge people based on the merit of their work, not who they are. If you are passionate about what this role entails and solving real problems, we encourage you to apply. We want to learn about you and what you can add to our team.

Who we are

We’re harnessing the power of technology to revolutionize insurance. Using machine learning and mobile telematic platforms, we’ve built one of the most innovative FinTech companies in the world. And we’re just getting started.

What draws people to Root

Our success is in large part due to our unwavering standards in hiring. We recognize that our products are only as good as the people building and promoting them. We want individuals who find solutions by going through the cycle of ideation to implementation with curiosity, rigor, and an analytical lens. Ask anyone who works here and you’ll hear similar reasons for why they joined:

Autonomy—for assertive self-starters, the opportunities to contribute are limitless.

Impact—by challenging the way it’s always been done, we solve problems that have a big impact on our business.

Collaboration—we encourage rich discussion and civil debate at every turn.

People—we are inspired by the collection of crazy-smart people around us.

Root Chicago, Illinois, USA Office

Chicago, IL, United States

Similar Jobs

2 Hours Ago
Remote
Hybrid
4 Locations
175K-175K Annually
Mid level
175K-175K Annually
Mid level
eCommerce • Legal Tech • Professional Services • Software • Data Privacy
Responsible for identifying vulnerabilities, creating security reports, communicating with stakeholders, and assisting in security practices and processes.
Top Skills: Cloud ServicesLinuxPenetration Testing ToolsRuby On RailsVue
5 Hours Ago
Remote
USA
135K-215K Annually
Senior level
135K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead malware threat research, analyze and mitigate modern threats, collaborate with engineering for automation, and communicate findings effectively.
Top Skills: AWSMitre Att&CkProgramming Or Scripting Language
5 Hours Ago
Remote
USA
135K-225K Annually
Senior level
135K-225K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Lead and manage compliance programs for CrowdStrike’s GovCloud environments, ensuring adherence to government security standards and driving continuous improvement of compliance efforts.
Top Skills: AWSAzureCmmcDod Srg Il4Dod Srg Il5FedrampGCPIrapIsmapNist 800-53RmfStateramp

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account