Staff Security Analyst - GRC
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Analyst - GRC based in United States.
This is a senior-level role within an Information Security organization, focused on building and operating security and compliance programs at scale. You will lead commercial compliance initiatives across frameworks including SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA. The role combines GRC expertise with hands-on engineering and automation to make compliance processes more efficient and scalable. You will also contribute to federal compliance initiatives while helping expand public-sector security capabilities. Working across engineering, product, business, customers, auditors, and external suppliers, youβll provide practical guidance that balances security requirements with business velocity. This position offers significant ownership in a fast-paced, cloud-native environment where automation, technical depth, and clear communication are highly valued.
Accountabilities:
- Design, implement, and continuously monitor commercial security and compliance controls across environments supporting SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA requirements.
- Partner with engineering teams to ensure systems and environments are appropriately scoped, secured, and aligned with applicable compliance obligations.
- Develop and implement GRC engineering and automation solutions that scale compliance activities, automate control testing, and integrate continuous compliance checks into CI/CD pipelines.
- Streamline compliance reporting and improve the efficiency and reliability of security and compliance processes through automation.
- Support federal compliance initiatives involving frameworks and programs such as FedRAMP Moderate+, CMMC, DoD IL, FedRAMP 20x, and NIST 800-53.
- Support customer trust activities by reviewing contracts for security and privacy requirements, completing detailed security questionnaires, and maintaining the customer trust portal.
- Provide precise, actionable security and privacy guidance to engineering, product, and business teams, helping incorporate security and privacy by design.
- Build and maintain effective relationships with external suppliers, auditors, assessors, and enterprise prospects.
- Identify, track, and mitigate risks associated with compliance programs and projects while continuously monitoring supply chain security and vendor risk.
- Clearly communicate security capabilities, controls, and compliance practices to enterprise customers and regulatory auditors.
- Build new programs and initiatives from the ground up while managing multiple priorities in a complex, fast-moving environment.
- Share knowledge and help junior colleagues develop their understanding of security, compliance, and automation practices.
Requirements
- 8β10+ years of relevant industry experience in security, compliance, GRC, or security program management.
- Extensive experience with commercial security frameworks, regulations, and certifications, including ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA.
- Experience working with GRC tools and building automation for security and compliance controls in cloud-native environments such as AWS, GCP, or Azure.
- Working knowledge of or exposure to federal compliance frameworks including NIST 800-53, FedRAMP, and CMMC, with an interest in expanding federal compliance programs.
- Strong cybersecurity knowledge and technical proficiency with enterprise SaaS applications and cloud infrastructure.
- Strong project management and organizational skills, with the ability to manage multiple priorities and establish new programs.
- Excellent written and verbal communication skills, with the ability to work effectively with both technical engineering teams and non-technical stakeholders.
- Ability to navigate ambiguity, create clarity, and make sound decisions in complex and rapidly changi
This role requires you to be in the United States. If that means relocating or flying in, it is worth checking fares before you commit to a start date.
Compare flights and hotels βGet remote it jobs like this by email
10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.
Similar for you
Get 10 hand-picked remote jobs like this one in your inbox every morning. One email a day, matched to what you browse. No spam, one-click unsubscribe.
No thanks β continue to the application β