Staff Security Analyst - GRC
$150k - $164kjobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Analyst - GRC based in United States.
This is a senior-level role within an Information Security organization, focused on building and operating security and compliance programs at scale. You will lead commercial compliance initiatives across frameworks including SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA. The role combines GRC expertise with hands-on engineering and automation to make compliance processes more efficient and scalable. You will also contribute to federal compliance initiatives while helping expand public-sector security capabilities. Working across engineering, product, business, customers, auditors, and external suppliers, you’ll provide practical guidance that balances security requirements with business velocity. This position offers significant ownership in a fast-paced, cloud-native environment where automation, technical depth, and clear communication are highly valued.
Accountabilities:
- Design, implement, and continuously monitor commercial security and compliance controls across environments supporting SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA requirements.
- Partner with engineering teams to ensure systems and environments are appropriately scoped, secured, and aligned with applicable compliance obligations.
- Develop and implement GRC engineering and automation solutions that scale compliance activities, automate control testing, and integrate continuous compliance checks into CI/CD pipelines.
- Streamline compliance reporting and improve the efficiency and reliability of security and compliance processes through automation.
- Support federal compliance initiatives involving frameworks and programs such as FedRAMP Moderate+, CMMC, DoD IL, FedRAMP 20x, and NIST 800-53.
- Support customer trust activities by reviewing contracts for security and privacy requirements, completing detailed security questionnaires, and maintaining the customer trust portal.
- Provide precise, actionable security and privacy guidance to engineering, product, and business teams, helping incorporate security and privacy by design.
- Build and maintain effective relationships with external suppliers, auditors, assessors, and enterprise prospects.
- Identify, track, and mitigate risks associated with compliance programs and projects while continuously monitoring supply chain security and vendor risk.
- Clearly communicate security capabilities, controls, and compliance practices to enterprise customers and regulatory auditors.
- Build new programs and initiatives from the ground up while managing multiple priorities in a complex, fast-moving environment.
- Share knowledge and help junior colleagues develop their understanding of security, compliance, and automation practices.
Requirements
- 8–10+ years of relevant industry experience in security, compliance, GRC, or security program management.
- Extensive experience with commercial security frameworks, regulations, and certifications, including ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA.
- Experience working with GRC tools and building automation for security and compliance controls in cloud-native environments such as AWS, GCP, or Azure.
- Working knowledge of or exposure to federal compliance frameworks including NIST 800-53, FedRAMP, and CMMC, with an interest in expanding federal compliance programs.
- Strong cybersecurity knowledge and technical proficiency with enterprise SaaS applications and cloud infrastructure.
- Strong project management and organizational skills, with the ability to manage multiple priorities and establish new programs.
- Excellent written and verbal communication skills, with the ability to work effectively with both technical engineering teams and non-technical stakeholders.
- Ability to navigate ambiguity, create clarity, and make sound decisions in complex and rapidly changing situations.
- Hands-on experience building, delivering, or managing a FedRAMP-compliant service offering or achieving an Authority to Operate (ATO) is a plus.
- Familiarity with federal and defense environments such as Platform One, Iron Bank, CMMC, or DoD IL is a plus.
- Understanding of AWS or GCP environments and cloud configuration and management best practices is a plus.
- Relevant certifications such as ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials are a plus.
- Experience assessing or applying AI in secure environments is a plus.
- Exposure to Kubernetes, SBOMs, SLSA, and/or DLP is a plus.
- A strong interest in automation and a willingness to share knowledge with junior team members are valued.
Benefits
- $150,000–$164,000 annual base salary, with compensation determined by location, level, relevant experience, and skills.
- Potential equity as part of the overall compensation package.
- Comprehensive healthcare benefits.
- Flexible Spending Account (FSA).
- Flexible work schedule.
- Employee Assistance Program (EAP).
- Flexible Time Off and parental leave.
- Monthly internet reimbursement.
- Monthly, quarterly, and annual social and team-building events.
- Remote work within the United States, with a hybrid option available from designated offices.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
$130k - $135k
CorporateThe Security GRC Analyst II supports the organization’s data protection and governance programs by implementing security tools, maintaining compliance with data protection requirements, and assisting in the investigation of incidents involving sensitive information...SuggestedMinimum wageOngoing contractFull timeH1bLocal areaRemote workWorldwide$114k - $139k
Reno, NV / Remote - USAdministration - Enterprise Information Security /Full-Time /RemoteAs a GRC Security Analyst, you will serve as a fully qualified, experienced professional responsible for ensuring Clear Capital adheres to all relevant security standards, regulations...SuggestedFull timeTemporary workWork experience placementRemote work- Valon is seeking a Sr. Security Analyst to join its Security team in a pivotal role managing security governance, risk, and compliance across... ...You will leverage AI-assisted processes to automate and scale GRC workflows, support audits, and drive proactive risk remediation...Suggested
- A technology solutions company is seeking a remote SAP Security Analyst. The role involves troubleshooting SAP security, supporting projects... ...concepts. Candidates should have experience with SAP security, GRC access control, and S/4 Hana, along with excellent communication...SuggestedRemote job
$13 per hour
Regent University is seeking a student intern to assist with GRC activities and vendor risk assessments within the Information Security Department. You will monitor security dashboards, review tool outputs, and help maintain SharePoint documentation. You will participate...SuggestedHourly payInternship- ...SAP GRC Analyst / SAP Security Analyst Location: Monday - Friday - Onsite in Richardson, TX Position Overview We are seeking an experienced SAP GRC Analyst to serve as the critical link between IT and business stakeholders, ensuring a secure...Monday to Friday
$172.5k - $215.63k
...seamlessly integrating cutting-edge technology, compassionate service, and world-class user experience design.As our Lead Security Analyst - GRC, you’ll lead initiatives that address the company’s—and some of our industry’s—most sophisticated and meaningful security engineering...Hourly payWork at officeFlexible hours2 days per week- ...Our client is seeking a Senior Information Security GRC Analyst to support and advance their Information Security Governance, Risk, and Compliance (GRC) program. In this role, the selected candidate will assess and strengthen IT and security controls across the organization...
- ...Job Description Job Description Information Security Analyst (GRC & Microsoft 365 Security) ~ Location: On-site in Danvers, MA Who We Are Samsung HME America (Healthcare and Medical Equipment) is Samsung’s U.S. medical imaging organization, delivering...Temporary workWorldwide
- Monarch Money is seeking a Senior Security GRC Analyst to lead our compliance and customer security assurance efforts in a fully remote fintech setting. You will partner with People, Legal, IT, Operations, and Engineering to mature our program and automate evidence collection...Remote job
- Metropolis Technologies seeks a Governance, Risk, and Compliance (GRC) Analyst to join our Security team. You will mature information security policies, drive employee security awareness, and shape our AI governance framework. You will partner across Technology, Legal,...
- Yahoo is seeking a Senior Security GRC Analyst to join The Paranoids Cyber Risk team in a fast-moving security landscape. You will collaborate with business leaders, engineers, and security teams to identify, assess, document, and communicate security risks, guiding risk...
$128.25k - $266.88k
Paranoids Senior Security GRC Analyst (Finance) Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions...Work at officeFlexible hours- Dorsey & Whitney LLP is seeking a Senior GRC Information Security Systems Analyst to safeguard client and firm data. You will drive ISMS audits, maintain policies aligned to ISO 27001, and oversee authorization services and NetDocuments reviews. The role partners with...
- ...business needs. This is not a remote position. The GRC (Governance Risk & Compliance) Senior Security Analyst will be responsible for safeguarding Kura’s IT (... ...provide cybersecurity training and awareness to staff. DUTIES: Key responsibilities include but not limited...Work at office1 day per week
$94.1k - $164.8k
Job Summary: The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities... ...risk to support vendor risk management activities Engage staff and/or vendors to develop information security risk mitigation...Hourly payTemporary workWork experience placementWork at office$109.99k - $142.34k
Join Dorsey's Information Security team as a Senior GRC Information Security Systems Analyst to help safeguard our firm and clients by driving high-impact security initiatives across audits, risk, governance, and compliance. Reporting directly to the Information Security...Contract workTemporary workCurrently hiringWork at officeWorldwideFlexible hours- Dorsey & Whitney LLP is seeking a Senior GRC Information Security Systems Analyst to safeguard the firm and clients through governance, risk, and compliance initiatives. You will drive ISMS audits, maintain policies aligned with ISO 27001, and oversee authorization services...
- ...RSA Archer Administration/Configuration), Preferred 10+ Years (Enterprise/Government GRC Environments) Job Description: Seeking an experienced RSA Archer GRC Security Analyst to support enterprise governance, risk, and compliance initiatives through the...
$117.2k - $176.7k
...emerging technologies to enhance delivery of your work product. Additionally, accountable for advising business partners on adopting new security requirements.This candidate must be a U.S. citizen (U.S. born or naturalized) operating on U.S. Soil who does not hold dual...Full time$117.2k - $176.7k
...Salesforce leadership has the information needed to make strategic, risk-based decisions. The GCC team is a division within the Product Security Organization, and you'll play a pivotal role in partnering with engineering to translate complex mandates into actionable controls...Full time- Health and Human Services Commission in Austin, Texas, seeks a Cybersecurity Analyst II to strengthen cloud security, web app protection, and GRC activities across on‑premises and cloud environments. The role develops SSPs, documents vulnerabilities, and delivers security...
$148k - $203.5k
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted... ...customers so they can effectively manage their risk. As a Senior level analyst of Customer Assurance, you will support prioritizing and...Work experience placementLocal areaWorldwideFlexible hours$123.2k - $154k
## Staff Security AnalystApplylocations: US Remotetime type: Full timeposted on: Posted Yesterdayjob requisition id: JR-000823Alkami is the... ...Title.Follow us on Glassdoor and LinkedIn!The Staff Security Analyst is an advanced security operations professional who leads the...Full timeRemote workShift work$145.6k - $209.3k
...can count on, and a team that succeeds together. Because at UKG, your work matters—and so do you. Description: As a Senior Staff Security Analyst - Incident Commander, you will be part of UKG’s Global Security Operations team. This global team is responsible for detecting...Local area$90k - $115k
...position due to Department of Defense restrictions. Our Senior Security Policy Analyst is responsible for developing, implementing, and... ...with hands-on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high-quality...Full timeContract workFor contractorsWork at officeLocal areaImmediate startRemote work3 days per week- A leading energy company is seeking an SAP Security support professional to manage security applications across multiple SAP environments. You will ensure compliance with security guidelines, advocate for standard solutions, and maintain user security management. Ideal...Flexible hours
- ...background in threat detection, incident response, and the Microsoft security suite. This role requires a blend of technical expertise,... ...technical teams. ~ Proficiency with compliance tracking tools, GRC platforms, and project management tools a plus. ~ Willingness...Permanent employmentFull timeContract work
- ...Summary of Purpose: The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority, providing oversight and guidance... ...management tools (e.g. Qualys) and Governance, Risk and Compliance (GRC) platforms (e.g. ServiceNow GRC, X-Analytics) Performs other...Full timeWork experience placement
- Ultra Clean Technology in Austin, TX is seeking an Analyst III for IT Information Security. This role involves enhancing the company's security posture through various compliance, risk management, and governance tasks. The ideal candidate will have a strong background in...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Analyst - GRC. Be the first to apply!
- entry level information security analyst United States
- junior security analyst United States
- application security analyst United States
- IT security analyst United States
- network security analyst United States
- information security compliance analyst United States
- security analyst remote United States
- information security analyst United States
- work from home security analyst United States
- national security analyst United States




