Governance, Risk, Compliance & Trust Analyst
Everlaw
| Company | Everlaw |
| Category | Legal & Compliance |
| Location | Oakland |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Entry |
| Salary | USD 140k–178k |
| Posted | 30 Jun 2026 |
| Last verified | 12 Aug 2026 |
| Source | The employer's own careers page (company_site) |
Description
Everlaw is a legal technology company that helps legal teams discover information and achieve their truth-finding goals. As a Governance, Risk, Compliance & Trust Analyst, you will independently drive moderately complex trust, compliance, and risk workstreams that help Everlaw scale responsibly and earn customer and regulator trust, translating security and compliance posture into clear, audit-ready, and customer-ready outputs.
What You'll Do
• Support audit readiness across frameworks such as FedRAMP, SOC 2, and ISO 27001/27017/27018 by organizing evidence, maintaining documentation quality, and partnering with control owners to close gaps
• Manage compliance operations including evidence requests, policy updates, control narrative maintenance, and recurring review cycles with structured follow-through and defined SLAs
• Manage customer security questionnaires and trust inquiries with minimal supervision, researching answers, validating claims, gathering evidence, and producing accurate customer-ready responses
• Conduct end-to-end vendor security and compliance reviews by analyzing documentation, evaluating vendor security posture, and clearly documenting gaps and recommended next steps
• Own security training program workstreams including planning, content coordination, stakeholder alignment, rollout tracking, and continuous improvement of compliance training for personnel
What You Need
• 5+ years of experience as an individual contributor with a Governance, Risk, Compliance and Trust team
• Strong working knowledge of customer trust, compliance operations, risk, and evidence and control narratives needed to support questionnaires, reviews, and audits
• Experience supporting FedRAMP, SOC 2, ISO 27001/27017/27018, or similar compliance frameworks
• Experience leading the completion of customer security questionnaires and working within trust portals, evidence repositories, or GRC tooling software
• Ability to independently research moderately complex questions, synthesize inputs from multiple stakeholders, and produce high-quality written deliverables with clarity and accuracy
Nice to Have
• Experience using workflow, metrics, or dashboard data to improve trust and compliance operations
• Familiarity with Linux and Unix-like operating systems in security and compliance contexts
$140,000–$178,000 base salary, equity program, 401(k) with company matching, health/dental/vision, flexible spending accounts, paid parental leave, approximately 10 days (80 hours) per year of sick leave, 17 paid vacation days plus 11 federal holidays, Modern Health membership, annual L&D allocation, company-sponsored life and disability insurance