Associate GRC Analyst
KAYAK, part of Booking Holdings (NASDAQ: BKNG), is a leading travel search engine. With billions of queries across our platforms, we help people find their perfect flight, stay, rental car and vacation package. We're also transforming business travel with a new corporate travel solution, KAYAK for Business.
As an employee of KAYAK, you will be part of a travel company that operates a portfolio of global metasearch brands including momondo, Cheapflights and HotelsCombined, among others. From start-up to industry leader, innovation is in our DNA and every employee has an opportunity to make their mark. Our focus is on building the best travel search engine to make it easier for everyone to experience the world.
KAYAK is looking for a motivated Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team! This is an exciting opportunity for an early-career professional to grow within a dynamic cybersecurity and risk management environment. A great candidate has a solid foundational understanding of GRC concepts, some hands-on exposure through internships or academic projects, and a curiosity for modern approaches (such as GRC Engineering) where automation, code, and data-driven workflows are transforming traditional GRC practices.
You will work alongside an experienced team to support risk assessments, compliance activities, policy management, control monitoring, and business continuity and disaster recovery (BC/DR) efforts—while contributing to the modernization of our GRC program.
Note, this position is required to work from our Cambridge or Concord, MA office 3 days per week.
In this role you will:
Support the execution of risk assessments, including identifying, documenting, and tracking risks across business and technology areas
Help maintain and update policies, standards, and procedures aligned with security and compliance frameworks such as NIST CSF, SOC 2, PCI DSS, and GDPR
Help coordinate internal and external audits by gathering evidence, tracking findings, and following up on remediation steps
Contribute to control testing and monitoring, verifying that implemented controls are working as intended
Maintain the risk register and support risk treatment tracking
Assist with customer-facing security reviews, including completing security questionnaires and preparing due diligence documentation
Support the development, maintenance, and testing of Business Continuity and Disaster Recovery plans, including Business Impact Analyses (BIAs) and recovery strategies
Collaborate with engineering, security, and business teams to gather evidence, clarify requirements, and communicate compliance obligations
Contribute to efforts to automate and streamline GRC processes — for example, helping to reduce manual evidence collection through scripts, APIs, or compliance platform integrations
Stay current on regulatory changes, emerging frameworks, and evolving approaches to governance and compliance
Please apply if you have:
A bachelor's degree in a relevant field (such as cybersecurity, information systems, computer science, risk management, or business) — or equivalent practical experience, training, or transferable skills
A foundational understanding of GRC concepts, including risk management, controls, compliance frameworks, and audit processes
Basic familiarity with Business Continuity and Disaster Recovery principles, including concepts like Business Impact Analyses, recovery time objectives, and recovery point objectives
Some familiarity with at least one major security or compliance framework (such as NIST CSF, SOC 2, or PCI DSS)
Experience in a GRC, cybersecurity, internal audit, IT risk, or business continuity context — paid, academic, capstone, or volunteer experience is all considered
Clear written and verbal communication skills, including the ability to explain risk and compliance concepts to a range of audiences
Strong organizational skills and the ability to manage multiple priorities at once
A curious, analytical mindset and a genuine interest in learning and asking questions
It would be a plus if you also have:
Exposure to or interest in treating GRC processes as code — for example, automating controls, using APIs, or applying engineering approaches to scale compliance work (no prior coding experience required; we'll support your learning)
Prior experience with a compliance or business continuity platform such as Drata or RiskConnect
Benefits and Perks
Work from (almost) anywhere for up to 20 days per year
Focus on mental health and well-being:
Company-paid therapy sessions through SpringHealth
Company-paid subscription to HeadSpace
Company-wide week off a year – the whole team fully recharges (and returns without a pile-up of work!)
No meeting Fridays
Paid parental leave
Generous paid vacation + time off for your birthday
Paid volunteer time
Focus on your career growth:
Development Dollars
Leadership development
Access to thousands of on-demand e-learnings
Travel Discounts
Employee Resource Groups
Competitive retirement and health plans
Free lunch 2 days per week
Fun quarterly events such as boat trips, arcades, ski trips, Thursday happy hours, and more
There are a variety of factors that go into determining a salary range, including but not limited to external market benchmark data, geographic location, and years of experience sought/required. The range for this Massachusetts based role is $85,000 - 95,000.00, not inclusive of annual bonus.
We offer a competitive base salary and benefits including: health benefits; flexible spending account; retirement benefits; life insurance; paid time off (including PTO, paid sick leave, medical leave, bereavement leave, floating holidays and paid holidays); and parental leave benefits.
Inclusion
At KAYAK, we want everyone to have the space to grow, share ideas and do great work. That's why we're focused on hiring the best talent from all walks of life and experiences, supporting them well and making sure no one feels like they have to fit a mold to belong here.
Need any adjustments for the interview, application or on the job? No problem - just give us a heads-up. We've got you.
#LI-EI1