Staff Security Analyst - GRC
Core
Lead commercial compliance initiatives and build automated GRC engineering solutions to scale security and compliance programs.
Role type
Staff Security Analyst - GRC (hands-on IC with program ownership)
Builds
Automated compliance controls, continuous compliance checks in CI/CD pipelines, and customer trust portals
Domain
Information Security / GRC / Cloud Infrastructure
Deliverable
production ML models | product features | dashboards & analysis | infrastructure
Required skills
GRC frameworks (SOC 1, SOC 2, ISO 27001, PCI-DSS, HIPAA), cloud-native automation (AWS/GCP/Azure), security program management, risk mitigation, contract/privacy review, stakeholder communication
Preferred skills
FedRAMP Moderate+/CMMC/DoD IL experience, Authority to Operate (ATO) delivery, Kubernetes/SBOM/SLSA/DLP knowledge, AI in secure environments
Technologies
AWS, GCP, Azure, CI/CD pipelines, Kubernetes, SBOM, SLSA, DLP
Responsibilities
Design and monitor commercial security controls; partner with engineering to align systems with compliance obligations; develop GRC automation solutions; streamline compliance reporting; support federal compliance initiatives; review contracts and complete security questionnaires; provide security guidance to technical and business teams; manage external supplier and vendor risk; communicate compliance practices to customers and auditors; build new programs from the ground up; mentor junior colleagues
Seniority
Staff, hands-on IC with significant program ownership