Remote job
Staff Security Analyst - GRC
Job details
About this role
Role overview
This Staff-level Security Analyst position sits within the Governance, Risk, and Compliance (GRC) team of the Information Security organization, serving as a senior contributor who designs, builds, and operates compliance programs at scale. The role blends deep technical security expertise with policy mastery, helping engineering and business teams maintain delivery velocity while meeting rigorous certification and audit requirements. It spans both commercial and federal regulatory frameworks with a strong emphasis on automation.
Responsibilities
- Design, implement, and continuously monitor commercial compliance controls for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA environments, partnering with engineering teams on scoping and security - Build GRC automation solutions, including automated control testing, continuous compliance checks integrated into CI/CD pipelines, and streamlined reporting - Support federal compliance initiatives and frameworks such as FedRAMP Moderate+, CMMC, DoD Impact Levels, and FedRAMP 20x as the public sector footprint expands - Support customer trust by reviewing contracts for security and privacy requirements, completing detailed customer security questionnaires, and maintaining the customer trust portal - Identify, track, and mitigate compliance risks, including supply chain security and vendor risk management - Engage with external suppliers, auditors, assessors, and prospects, clearly communicating security capabilities to enterprise customers and regulatory auditors
Requirements
- 8-10+ years of relevant industry experience across security, compliance, and GRC program management - Strong command of commercial compliance frameworks: SOC 2, SOC 1, ISO 27k, HIPAA, and PCI-DSS - Hands-on GRC engineering and automation capabilities, including integrating compliance into CI/CD pipelines - Customer trust experience, including security questionnaire completion and contract review - Familiarity with federal compliance frameworks such as FedRAMP, CMMC, DoD IL, and NIST 800-53 - Demonstrated ability to collaborate cross-functionally with engineering, product, and business teams
Nice to have
- Experience contributing to public sector or federal compliance expansion efforts - Ability to translate complex security concepts for diverse audiences, from engineers to enterprise buyers
Benefits and work setup
- Anticipated base salary range: $150,000–$164,000 USD annually, with the range varying by location, experience, and skills - Compensation package may include equity and additional benefits - Monthly internet reimbursement