Staff Security Analyst
Core
Lead and scale the organization's compliance architecture, managing ISMS operations, coordinating audits, and automating compliance workflows to eliminate manual friction.
Role type
Staff Security Analyst (Compliance & GRC)
Builds
Automated compliance workflows, centralized evidence repositories, and unified control frameworks.
Domain
Information Security Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
Multi-framework compliance management (PCI DSS, SOX, ISO 27001, ISO 42001, SOC 1/2), ISMS operations, audit coordination, risk assessment, control automation, policy development, executive reporting, cross-functional collaboration, cloud security architecture, GRC platform management, evidence collection automation.
Preferred skills
Big Four consulting experience, FedRAMP/GovRAMP/CMMC authorization processes, NIST SP 800-171/DFARS compliance, Unified Control Framework (UCF) design, specialized security certifications.
Technologies
Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, AWS, Azure, GCP, SIEM platforms, vulnerability scanners, configuration management tools.
Responsibilities
Lead multi-framework compliance programs (PCI DSS, SOX, ISO 27001, ISO 42001, SOC 1/2), manage ISMS operations including risk treatment and internal audits, serve as primary contact for external auditors, perform risk assessments and develop treatment plans, partner with control owners to implement automation and continuous monitoring, develop and maintain security policies and documentation, prepare executive compliance reports and dashboards, collaborate with engineering, finance, and legal teams to bridge control gaps, deliver security compliance training.
Seniority
Staff, hands-on IC with strategic scope