Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Analyst - GRC

$160k - $190k
Full-time

Harness

Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for $3.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, Citi Ventures, and more. As AI accelerates code creation, the real bottleneck has shifted to everything after the code – testing, deployments, application security, reliability, compliance, and cost optimization. Harness brings AI and automation to this “outer loop,” helping teams ship software faster while maintaining security and governance throughout the entire software delivery lifecycle.

Powered by Harness AI and the Software Delivery Knowledge Graph, the Harness Platform applies deep context and intelligent automation across the software delivery lifecycle with governance and policy-driven controls embedded throughout the platform.

Over the past year, Harness powered over 185M deployments, 82M builds, 18T flag evaluations, 8M security scans, 9.1B optimized tests, 3T protected API calls, and helped manage $2.8B in cloud spend — enabling customers like United Airlines, Morningstar, and Choice Hotels to accelerate releases by up to 75%, reduce cloud costs by up to 60%, and achieve 10x DevOps efficiency.

With a global team across 26 offices and 27 countries, Harness is shaping the future of AI software delivery — and we’re looking for exceptional talent to help us move even faster.

Position Summary

A Staff Security Analyst will be a critical member of the GRC team working within the Information Security organization and across the business to advise, build, and operate security and compliance programs at scale. Utilizing in-depth expertise across multiple disciplines, you will be responsible for executing various components of Harness' security posture and overseeing end-to-end solutions to complex compliance problems.

As a Staff Security Analyst, you will lead security efforts to acquire and maintain crucial compliance certifications across Commercial sectors while assisting with Federal initiatives. You will design solutions that enable Harness' security goals and collaborate directly with business and engineering teams to preserve velocity while ensuring top-tier security. This role requires a strong core in Commercial Compliance mastery (SOC 2, SOC 1, ISO 27k, HIPAA, PCI), Customer Trust experience, and hands-on GRC Engineering and Automation capabilities, complemented by familiarity with Federal Compliance (FedRAMP, NIST 800-53).

About the role

  • Commercial Compliance Management: Design, implement, and continuously monitor commercial compliance controls, collaborating with engineering teams to ensure environments are properly scoped and secured for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA.
  • GRC Engineering & Automation: Develop and implement automation solutions to scale compliance tasks, automate control testing, integrate continuous compliance checks into the CI/CD pipeline, and streamline reporting.
  • Federal Compliance Support: Contribute to Federal compliance initiatives and frameworks (such as FedRAMP Moderate+, CMMC, DoD IL, and FedRAMP 20x) as Harness expands its public sector footprint.
  • Customer Trust & Advisory: Support customer trust initiatives by reviewing contracts for security and privacy requirements, completing detailed customer security questionnaires, and maintaining the customer trust portal.
  • Cross-Functional Collaboration: Contribute precise and actionable guidance to ensure security and privacy by design for engineering, product, and business initiatives.
  • Stakeholder Engagement: Manage relationships and facilitate engagement with external suppliers, auditors, assessors, and enterprise prospects.
  • Risk Management: Identify, track, and mitigate risks related to compliance projects, continuously monitor supply chain security, and manage vendor risk.
  • Evangelism: Articulate Harness's security capabilities and controls clearly to enterprise customers and regulatory auditors

About you

  • You have a minimum of 8-10 years of relevant industry experience in security, compliance, and GRC program management.
  • Extensive exposure to commercial industry regulations, frameworks, and compliance certifications (ISO 27001, SOC 1, SOC 2, PCI-DSS, HIPAA).
  • Previous experience with GRC tools and a demonstrated ability to build automation for security and compliance controls in a cloud-native environment (AWS, GCP, or Azure).
  • Working knowledge or exposure to Federal compliance frameworks (e.g., NIST 800-53, FedRAMP, CMMC) and are interested in expanding these programs.
  • You possess strong cybersecurity acumen and solid technical proficiency with enterprise SaaS applications and infrastructure.
  • Excellent project management and organizational skills, with the ability to handle multiple priorities and build new programs from scratch.
  • Clear, concise communication skills, both written and verbal, and can effectively partner with technical engineering teams as well as non-technical stakeholders.
  • You are comfortable navigating ambiguity and driving clarity in complex, fast-paced situations.

Bonus Points!

  • You have hands-on experience building, delivering, or managing a FedRAMP-compliant service offering (FedRAMP Moderate+) or achieving an ATO.
  • Familiarity with specialized defense/federal environments like Platform One, Iron Bank, CMMC, or DoD IL.
  • You are familiar with what is going on under the hood of the AWS or GCP console and can speak to best practices for configuration and management.
  • You hold relevant security or technical certifications (ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials).
  • Previous experience assessing and utilizing AI in a secure environment.
  • You have exposure to or experience with Kubernetes, SBOMs, SLSA, and/or DLP.
  • You like to "automate the boring stuff" and are eager to share your knowledge with junior colleagues

Work Location

  • Remote within the U.S or Hybrid from one of our offices.

What you will have at Harness

  • Competitive salary
  • Comprehensive healthcare benefits
  • Flexible Spending Account (FSA)
  • Flexible work schedule
  • Employee Assistance Program (EAP)
  • Flexible Time Off and Parental Leave
  • Monthly, quarterly, and annual social and team building events
  • Monthly internet reimbursement

The anticipated base salary range for this position is between $160,000 and $190,000 annually. Salary is determined by a combination of factors including location, level, relevant experience, and skills. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. The compensation package for this position may also include equity, and benefits. More details about our company benefits can be found at the following link:

Pay transparency

$160,000—$190,000 USD

Harness in the news:

  • Accelerating Our Mission to Bring AI to Everything After Code
  • Goldman Sachs leads investment in software delivery startup Harness at $5.5 billion valuation
  • How Harness runs 16 “startups within a startup” at scale | Jyoti Bansal
  • Harness Research Shows AI Visibility Crisis Fueling Security Nightmare
  • Harness has been named to the Inc. Power Partner list for software delivery success

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.

At Harness, we care about your privacy and are committed to protecting your personal data. For additional information on this topic, you can visit our privacy Portal:

Note on Fraudulent Recruiting/Offers

We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers.

Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations.

If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at View email address on aiapply.co. You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission’s website ( or you can contact your local law enforcement agency.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Staff Security Analyst - GRC in Remote vacancy
  • $150k - $164k

     ...position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Analyst - GRC based in United States. This is a senior-level role within an Information Security organization, focused on building... 
    Suggested
    Full time
    Remote work
    Flexible hours

    Jobgether

    Remote
    3 days ago
  • A technology solutions company is seeking a remote SAP Security Analyst. The role involves troubleshooting SAP security, supporting projects...  ...concepts. Candidates should have experience with SAP security, GRC access control, and S/4 Hana, along with excellent communication... 
    Suggested
    Remote work

    Knack Solutions

    Chicago, IL
    4 days ago
  • $130k - $135k

    CorporateThe Security GRC Analyst II supports the organization’s data protection and governance programs by implementing security tools, maintaining compliance with data protection requirements, and assisting in the investigation of incidents involving sensitive information... 
    Suggested
    Minimum wage
    Ongoing contract
    Full time
    H1b
    Local area
    Remote work
    Worldwide

    ZOLL Medical Corporation

    Chelmsford, MA
    4 days ago
  • $114k - $139k

    Reno, NV / Remote - USAdministration - Enterprise Information Security /Full-Time /RemoteAs a GRC Security Analyst, you will serve as a fully qualified, experienced professional responsible for ensuring Clear Capital adheres to all relevant security standards, regulations... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Remote work

    Clear Capital

    Reno, NV
    4 days ago
  • Monarch Money is seeking a Senior Security GRC Analyst to lead our compliance and customer security assurance efforts in a fully remote fintech setting. You will partner with People, Legal, IT, Operations, and Engineering to mature our program and automate evidence collection... 
    Suggested
    Remote job

    Monarch Money

    Covina, CA
    3 days ago
  • Join Dorsey's Information Security team as a Senior GRC Information Security Systems Analyst to help safeguard our firm and clients by driving high-impact security initiatives across audits, risk, governance, and compliance. Reporting directly to the Information Security... 
    Contract work
    Temporary work
    Currently hiring
    Work at office
    Worldwide
    Flexible hours

    Dorsey & Whitney LLP

    Phoenix, AZ
    3 days ago
  •  ...Summary of Purpose: The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority, providing oversight and guidance...  ...management tools (e.g. Qualys) and Governance, Risk and Compliance (GRC) platforms (e.g. ServiceNow GRC, X-Analytics) Performs other... 
    Full time
    Work experience placement

    Inpo External

    Remote
    28 days ago
  • $90k - $115k

     ...position due to Department of Defense restrictions. Our Senior Security Policy Analyst is responsible for developing, implementing, and...  ...with hands-on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high-quality... 
    Full time
    Contract work
    For contractors
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Wps Health Solutions New

    Madison, WI
    more than 2 months ago
  •  ...background in threat detection, incident response, and the Microsoft security suite. This role requires a blend of technical expertise,...  ...technical teams. ~ Proficiency with compliance tracking tools, GRC platforms, and project management tools a plus. ~ Willingness... 
    Permanent employment
    Full time
    Contract work

    Re:build Manufacturing

    Remote
    more than 2 months ago
  • $97.59k - $142.99k

     ...opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the...  ...support of clients; risk management and other GRC responsibilities within a large...  ...organization.NYU Langone Health provides its staff with far more than just a place to work.... 
    Full time

    NYU Langone Medical Center

    New York, NY
    2 days ago
  •  ...environment that is respectful and inclusive for everyone.As a Security Analyst at Lucid Software, you will protect our corporate assets,...  ...and employees. You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk... 
    Remote work

    Lucidchart

    Salt Lake City, UT
    1 day ago
  • $10 - $15 per hour

     ...SAP Security Analyst Chicago, Illinois, United States Position: SAP Security Analyst Rate: $10-15 (Depending on your experience)...  ...security troubleshooting and end user support Experience in GRC access control, mitigation and remediation Experience with... 
    Remote work

    Knack Solutions

    United States
    3 days ago
  •  ...Security Analyst II The Security Analyst II is responsible for building and maturing PBS's governance, risk, and compliance programs, including...  ...vulnerability management, policy and procedure development, GRC tool configuration, automation, AI governance, and business... 
    Remote work

    PBS

    United States
    1 day ago
  •  ...SAP Security Analyst Salary: Confidential Location: Apex, North Carolina Relocation Assistance: Available Job Description No...  ...supporting global SAP security operations across ECC (primary), GRC, and BW environments Heavily focused on SAP production support... 
    Work at office
    Work from home
    Relocation
    Relocation package
    Flexible hours

    Affinity Executive Search

    Apex, NC
    5 days ago
  • $130k

     ...| |  pawsync.com   The Opportunity:   The Information Security Analyst is responsible for supporting the organization’s security posture...  ...). Help track evidence and controls using compliance and GRC tools such as OneTrust, Drata, or similar platforms.... 
    Full time
    Work at office
    Immediate start
    Night shift

    Vesync

    Remote
    20 days ago
  • $149.1k

     ...'re looking for a Principal Information Security Analyst to join the Information Risk Management...  ...information security, risk management, GRC, third-party risk management, or a related...  ...complex security risks to non-technical staff and influence remediation at scaleDemonstrated... 
    Full time
    Contract work
    Immediate start
    Remote work

    Nike

    Beaverton, OR
    14 hours ago
  • $105k - $115k

     ...equivalent AI solution. DSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer in the DC...  ...Leveraging the existing Governance, Risk, and Compliance (GRC) tool, Telos Xacta (or an alternate like CSAM or RSA Archer),... 
    Full time
    Contract work
    Work at office
    Remote work
    Flexible hours

    DSA

    Fairfax, VA
    3 days ago
  •  ...Qualifications: Required ~5+ years of relevant information security experience (or 3+ years in IT systems administration with 2...  ...and tabletop scenarios. Governance, Risk & Compliance (GRC) Draft or revise local policies, standards, guidelines, and... 
    Local area
    Relocation

    Saxon Global

    Philadelphia, PA
    1 day ago
  •  ...across multiple PCI DSS environments, the full-time Senior Security Compliance Analyst will design and execute monitoring activities, support SOC...  ...5+ years of experience in security compliance, audit, or GRC Hands-on experience with PCI DSS and SOC 2 compliance Strong... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    2 days ago
  •  ...customers who demand experience and proven security models to protect their data. We embrace...  ...We are seeking a Security Compliance Analyst to support federal cybersecurity compliance...  ...Experience with Governance, Risk, and Compliance (GRC) tools such as Xacta, CSAM, RSA Archer or... 
    Contract work
    Work at office
    Remote work

    ShorePoint Inc

    Herndon, VA
    5 days ago
  • $70k - $80k

    The IT Security Analyst will support and monitor the University’s cybersecurity systems to ensure...  ...Assist in governance, risk, and compliance (GRC) efforts, supporting documentation for...  ...input on security best practices for IT staff and end-users. Support identity and... 
    Work at office
    Remote work
    Flexible hours

    Regent

    Virginia Beach, VA
    4 days ago
  •  ...position is to support NCF's information security strategy by performing Tier 1 security operations...  ...Senior Security Engineer. The Security Analyst monitors information systems for security...  ...in the governance, risk, and compliance (GRC) platform Governance, Risk,... 
    Work at office
    Local area

    National Christian Foundation

    Alpharetta, GA
    15 days ago
  • $70 - $80 per hour

     ...: Job Overview: We are seeking a skilled SAP Application Security Analyst to support SAP security, GRC, and Identity & Access Management (IAM) within a complex enterprise environment. This role is responsible for managing user access, maintaining compliance controls... 
    Hourly pay
    Contract work
    Temporary work
    Remote work
    Shift work

    V-Tech Solutions

    White Plains, NY
    8 days ago
  •  ...applications and next steps. Our partner is looking for a Senior Security Analyst, Compliance based in the United States. This role will play...  ...process. This is an opportunity to help mature an evolving GRC function and establish scalable processes across the organization... 
    Full time
    Contract work
    Remote work

    jobgether

    United States
    9 days ago
  •  ...Information Security Analyst / Engineer GRC & Customer Assurance – Mid-Level Location: Atlanta, GA Experience: 5+ years in Information Security, GRC, or related IT discipline Level: P18 Role Summary Foxit is seeking a mid-level Information Security... 
    Full time

    Foxit

    Remote
    more than 2 months ago
  • $120k - $140k

    Join to apply for the Consultant - Endpoint Security Analyst role at Kalles Group Join to apply for the Consultant - Endpoint...  ...Sales Consultant - End User - Door Hardware - Tacoma, WA Staff Cyber Security Engineer - GRC (REMOTE) Seattle, WA $85,000.00-$230,000.00 2 days ago... 
    Full time
    Remote work
    Flexible hours

    Kalles Group

    Seattle, WA
    2 days ago
  • $115k - $192.9k

     ...position... The Ford Credit IT Compliance and Information Security Analyst provides oversight of IT compliance and regulatory requirements...  ...technical compliance issues to any audience. ~ Experience with GRC & audit tools. ~ Understanding of AI/LLM technologies and... 
    Full time
    Immediate start
    Flexible hours

    Ford Motor Company

    Dearborn, MI
    2 days ago
  •  ...Job Description Job Description Job43 – EITS Security Risk Analyst B (Engagement) Location: 100% Remote Max Submissions: 5 Proposed...  ...internal risk reviews, assessments, and exceptions using a GRC tool . ???? Governance & Compliance Document and maintain... 
    Immediate start
    Remote work
    Flexible hours

    DELTASOFT SOLUTIONS LLC

    San Francisco, CA
    a month ago
  •  ...Job Description Job Description The Senior Security & Compliance Analyst will provide, but not be limited to, the following activities and tasks...  ...demonstrated experience in both security governance/compliance (GRC) and hands-on security operations. # Demonstrated... 
    Permanent employment
    Contract work
    Work experience placement
    Second job
    Remote work

    TechArmy

    Tallahassee, FL
    a month ago
  • $49.73k - $73.13k

     ...place for you. We're looking for a detail-oriented and curious GRC Analyst to join our Governance, Risk & Compliance team. In this role,...  ...foundation in enterprise risk management and information security compliance, joining a senior, globally distributed team that will... 
    Full time
    Work experience placement
    Internship
    Work at office
    Local area

    Commerce

    Remote
    10 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Analyst - GRC. Be the first to apply!