Paranoids Senior Security GRC Analyst
Core
Senior Security GRC Analyst responsible for exception management, security risk assessment, and policy/standards management to guide cyber risk-conscious decisions.
Role type
Senior Security GRC Analyst
Builds
Actionable cyber risk insights, security policies, standards, and exception governance programs for Yahoo's global technology portfolio.
Domain
Information Security / Governance, Risk, and Compliance (GRC)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security risk assessment, policy and standards development, exception management, executive communication, regulatory compliance knowledge, AI tool utilization, process improvement
Preferred skills
GRC platform configuration (ServiceNow, Archer, Jira), AI/ML security governance, professional security certifications (CRISC, CISSP, CISA, CISM)
Technologies
NIST CSF, ISO 27001, FAIR, SOC 2, PCI DSS, GDPR, ServiceNow GRC, Archer, Jira, generative AI tools (Claude, ChatGPT, Gemini, Copilot)
Responsibilities
Evaluate and document known security risks for executive review; manage end-to-end lifecycle of risk exceptions; conduct property-level security risk assessments; draft and maintain security policies and standards; partner with stakeholders to socialize standards; identify and implement AI-assisted workflows for GRC tasks
Seniority
Senior, hands-on IC
