Staff Security Analyst - GRC
Core
Lead security efforts to acquire and maintain crucial compliance certifications across Commercial sectors while assisting with Federal initiatives.
Role type
Staff Security Analyst (GRC)
Builds
Automation solutions for compliance tasks, continuous compliance checks in CI/CD pipelines, and customer trust portals.
Domain
AI Software Delivery / Cloud Security / GRC
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Commercial Compliance mastery (SOC 2, SOC 1, ISO 27001, HIPAA, PCI-DSS), GRC Engineering & Automation, Federal Compliance frameworks (FedRAMP, NIST 800-53), Cloud-native infrastructure (AWS, GCP, Azure), Risk Management, Stakeholder Engagement
Preferred skills
FedRAMP Moderate+ experience, Defense/federal environment familiarity (CMMC, DoD IL), Kubernetes/SBOM/SLSA/DLP knowledge, AI security assessment
Technologies
AWS, GCP, Azure, CI/CD pipelines, Kubernetes, SBOM, SLSA, DLP
Responsibilities
Design and monitor commercial compliance controls for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA; Develop automation solutions to scale compliance tasks and integrate checks into CI/CD; Contribute to Federal compliance initiatives (FedRAMP, CMMC); Support customer trust initiatives via contract reviews and questionnaires; Manage relationships with external suppliers, auditors, and enterprise prospects; Identify and mitigate compliance and supply chain risks.
Seniority
Staff, hands-on IC with strategic oversight