Senior Staff Governance, Risk, and Compliance Analyst, Medallia

$134-200k

Senior level
Remote in US
Medallia

Customer experience management

Be an early applicant

Medallia

Customer experience management

1001+ employees

B2BInternal toolsMarket researchSupply ChainSaaS

Be an early applicant

$134-200k

Senior level
Remote in US

1001+ employees

B2BInternal toolsMarket researchSupply ChainSaaS

Company mission

Medallia's mission is to help companies win through customer experience.

Role

Who you are

  • The position requires a strong compliance acumen, business partnering skills, attention to detail, and ability to understand and implement compliance best practices in a complex technology environment
  • 5 years experience working with technology governance, internal controls, and compliance activities such as ISO 27001/17/18, SOC 2, PCI, HIPAA, FedRAMP, HITRUST
  • 2 years of experience working with HITRUST CSF (Common Security Framework) standards and conducting HITRUST assessments, audits, and remediation efforts
  • Proficient with audit testing best practices and relevant documentation standards
  • Demonstrated risk management and compliance experience across a broad range of technical areas relevant to SaaS environments: i.e. access management, software development lifecycle, secure coding principles, security architecture, information security, and network security

Desirable

  • Strong leadership capabilities, collaborative attitude and motivation to work in a fast paced startup-like environment
  • Ability to articulate complex technical and security information into business terms and solutions
  • Ability to analyze, communicate, articulate governance and compliance industry trends and benchmarks into policy
  • Experience managing information security audits and control implementation, strategy and risk within a Fortune 500 company
  • Ability to translate global privacy laws and regulations into recommended actions
  • Highly-organized with proven ability to oversee and manage multiple work streams across diverse stakeholder groups
  • Experience on developing AI policies and implementation
  • Excellent written and oral communication skills with an ability to effectively communicate security topics to a variety of audiences
  • Self-starter with capabilities to lead compliance audits and projects with minimal supervision
  • Industry certifications such as CISA, CISSP, CISM, PMP or CRISC is a plus

What the job involves

  • A phenomenal opportunity exists within Medallia’s Risk & Compliance Team as we are looking for a Senior Staff GRC (Governance, Risk, and Compliance) Analyst to drive compliance maturity and risk management in an ever-evolving SaaS landscape
  • At the forefront of technological advancements and innovation, this role is pivotal in shaping the way we ensure security and compliance across our services
  • As we continue to build and scale, this role’s impact will be critical to our platform, ensuring our growth is matched by the strength of our control environment
  • Act as subject matter expert on compliance and regulatory frameworks
  • Advise key stakeholders and management on best practice control design and implementation
  • Coordinate and lead multiple IT security audits and compliance governance activities across the company
  • Build and maintain Medallia’s unified controls matrix, in alignment with multiple compliance frameworks including SOC 2, ISO 27001/27701/27017/27018, PCI, HITRUST and HIPAA
  • Expertise in HITRUST CSF (Common Security Framework) standards and experience conducting HITRUST assessments, audits, and remediation efforts
  • Develop and maintain Medallia’s policies, procedures, and standards in collaboration with internal teams
  • Collaborate with teams across Medallia, validate that security controls are implemented and develop recommendations to remediate control deficiencies
  • Identify and oversee implementation of scalable security control enhancements that reduce risk and increase performance efficiency across diverse technical environments
  • Develop employee facing technical documentation, internal wiki pages, periodic security oriented communication to spread awareness about Information Security policies and standards
  • Develop and maintain AI policies and collaborate with internal and external teams on implementation
  • Coach more junior members of the team on complex projects and governance, risk and compliance best practices, as needed

Our take

Medallia's SaaS platform, the Medallia Experience Cloud helps with the understanding and management of experience for customers, employees and citizens.

Its software captures experience signals created on daily journeys in person, digital and IoT interactions and applies proprietary AI technology to reveal personalised and predictive insights that can drive action to help businesses.

Medallia has become a leader in the market with over 1,000 customers, including some of the world's leading brands like Samsung, PayPal and Mercedes Benz. In 2021, it was bought out by Thoma Bravo, which helped it to achieve greater flexibility and bolster its leadership and customer team.

Kirsty headshot

Kirsty

Company Specialist

Insights

Led by a woman
Top investors

Few candidates hear
back within 2 weeks

-4% employee growth in 12 months

Company

Funding (last 2 of 5 rounds)

Feb 2019

$70m

SERIES F

Jul 2015

$150m

SERIES D

Total funding: $325m

Company benefits

  • Work from home opportunities

Company values

  • Every Experience Matters: Big or small...we believe that nothing impacts the way someone feels about your company more than a positive or negative experience. That’s why we obsess over the details and will always push to help customers make every experience matter
  • Always Be Innovating: Our infinite signal capture and AI-powered deep learning capabilities coupled with our seamless integration technology has made Medallia the world’s leading platform since day one. But where we are today isn’t nearly as exciting as where we’ll be tomorrow
  • Fiercely Customer First: Customers, employees, users, partners – we believe everyone’s experience must be a stellar reflection of who we are. It guides our decision making and we genuinely know that customers are why we exist today
  • Trust and Respect: Companies trust us with their most precious asset: their reputation. We treat people with respect that honors that trust. We know how critical data security is to our customers — many of whom operate in highly regulated industries. At Medallia we maintain industry-leading practices to protect that data
  • All Belong Here: Everyone brings different life experiences to the table and we embrace them all. It makes us a stronger, smarter company. We encourage people to bring their whole selves to work each day, which is why we founded our Diversity, Inclusion and Belonging (DIBs) practice in 2016
  • Talent Is Everywhere: Our company is brimming with smart, growth-minded people so we develop that talent and promote from within. We encourage our employees to shine in new ways through skills development, mentoring, and creating new opportunities for each and every person to advance
  • Success from Sustainability: Intelligence and integrity dictates that we do all we can to protect the planet. We believe that continuously enacting this mindset we can win both in business and our integrity

Company HQ

Pleasanton, CA

Leadership

Borge Hald

(Executive Chairman)

Previously a Manager at BCG. Has an MBA from Stanford

Leslie Stretch

(CEO, not founder)

Previously President and CEO of CallidusCloud (acquired by SAP). Also Senior VP at Sun Microsystems

Share this job

View 2 more jobs at Medallia