Remote job
Security GRC Analyst
Job details
About this role
Role overview A senior individual contributor is needed to strengthen the security governance, risk, and compliance program of a large, cloud-based consumer technology company. Reporting into security GRC leadership, the role partners across Security, Engineering, IT, Legal, and Internal Audit to maintain a mature control environment and support recurring assurance activities.
Responsibilities - Administer and maintain the security risk register, tracking identified risks, remediation activities, owners, and reporting outputs. - Draft, review, and manage the lifecycle of security policies, standards, and supporting procedures. - Support planning, evidence collection, coordination, and follow-up for the annual SOC 2 Type 2 audit. - Execute security control testing activities aligned to CIS Controls and document outcomes, findings, and remediation recommendations. - Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions. - Conduct and support risk assessments with internal Security colleagues and relevant business stakeholders. - Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit, and awareness program status. - Support remediation tracking for control gaps, audit findings, and risk treatment actions.
Requirements - 4+ years of experience in security governance, risk, compliance, audit, or security assurance roles. - Working knowledge of core security and compliance frameworks such as SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar. - Experience supporting audits, assessments, or control testing programs in a technology or SaaS environment. - Demonstrated ability to write clear, practical security policies, standards, and process documentation. - Strong organizational skills with the ability to manage multiple workstreams and deadlines. - Comfort working cross-functionally with both technical and non-technical stakeholders. - Bachelor's degree in a relevant field such as Computer Information Systems or Cybersecurity, or equivalent experience.
Nice to have - Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology setting. - Familiarity with security awareness program administration and reporting. - Working knowledge of enterprise security domains including identity and access management, logging and monitoring, vulnerability management, endpoint security, and third-party risk. - Relevant certifications such as Security+, CISA, CRISC, or CISSP.
Benefits and work setup - Remote-first role with in-person collaboration 1–2 times per quarter; can be situated anywhere in the country. Position is not eligible for relocation assistance. Base salary range $123,696–$254,667 USD plus equity, dependent on location, experience, and skills.