Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Analyst - GRC

$150k - $164k

Jobgether

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Analyst - GRC based in United States.

This is a senior-level role within an Information Security organization, focused on building and operating security and compliance programs at scale. You will lead commercial compliance initiatives across frameworks including SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA. The role combines GRC expertise with hands-on engineering and automation to make compliance processes more efficient and scalable. You will also contribute to federal compliance initiatives while helping expand public-sector security capabilities. Working across engineering, product, business, customers, auditors, and external suppliers, you’ll provide practical guidance that balances security requirements with business velocity. This position offers significant ownership in a fast-paced, cloud-native environment where automation, technical depth, and clear communication are highly valued. \n

Accountabilities:

Design, implement, and continuously monitor commercial security and compliance controls across environments supporting SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA requirements. Partner with engineering teams to ensure systems and environments are appropriately scoped, secured, and aligned with applicable compliance obligations. Develop and implement GRC engineering and automation solutions that scale compliance activities, automate control testing, and integrate continuous compliance checks into CI/CD pipelines. Streamline compliance reporting and improve the efficiency and reliability of security and compliance processes through automation. Support federal compliance initiatives involving frameworks and programs such as FedRAMP Moderate+, CMMC, DoD IL, FedRAMP 20x, and NIST 800-53. Support customer trust activities by reviewing contracts for security and privacy requirements, completing detailed security questionnaires, and maintaining the customer trust portal. Provide precise, actionable security and privacy guidance to engineering, product, and business teams, helping incorporate security and privacy by design. Build and maintain effective relationships with external suppliers, auditors, assessors, and enterprise prospects. Identify, track, and mitigate risks associated with compliance programs and projects while continuously monitoring supply chain security and vendor risk. Clearly communicate security capabilities, controls, and compliance practices to enterprise customers and regulatory auditors. Build new programs and initiatives from the ground up while managing multiple priorities in a complex, fast-moving environment. Share knowledge and help junior colleagues develop their understanding of security, compliance, and automation practices. Requirements

8–10+ years of relevant industry experience in security, compliance, GRC, or security program management. Extensive experience with commercial security frameworks, regulations, and certifications, including ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA. Experience working with GRC tools and building automation for security and compliance controls in cloud-native environments such as AWS, GCP, or Azure. Working knowledge of or exposure to federal compliance frameworks including NIST 800-53, FedRAMP, and CMMC, with an interest in expanding federal compliance programs. Strong cybersecurity knowledge and technical proficiency with enterprise SaaS applications and cloud infrastructure. Strong project management and organizational skills, with the ability to manage multiple priorities and establish new programs. Excellent written and verbal communication skills, with the ability to work effectively with both technical engineering teams and non-technical stakeholders. Ability to navigate ambiguity, create clarity, and make sound decisions in complex and rapidly changing situations. Hands-on experience building, delivering, or managing a FedRAMP-compliant service offering or achieving an Authority to Operate (ATO) is a plus. Familiarity with federal and defense environments such as Platform One, Iron Bank, CMMC, or DoD IL is a plus. Understanding of AWS or GCP environments and cloud configuration and management best practices is a plus. Relevant certifications such as ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials are a plus. Experience assessing or applying AI in secure environments is a plus. Exposure to Kubernetes, SBOMs, SLSA, and/or DLP is a plus. A strong interest in automation and a willingness to share knowledge with junior team members are valued. Benefits

$150,000–$164,000 annual base salary, with compensation determined by location, level, relevant experience, and skills. Potential equity as part of the overall compensation package. Comprehensive healthcare benefits. Flexible Spending Account (FSA). Flexible work schedule. Employee Assistance Program (EAP). Flexible Time Off and parental leave. Monthly internet reimbursement. Monthly, quarterly, and annual social and team-building events. Remote work within the United States, with a hybrid option available from designated offices. \n

How Jobgether works: We use an

AI-powered matching process

to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice:

By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
Vacancy posted 18 hours ago
Similar jobs that could be interesting for youBased on the Staff Security Analyst - GRC in Remote vacancy
  • $160k - $190k

     ...after the code – testing, deployments, application security, reliability, compliance, and cost optimization....  ...help us move even faster. Position Summary A Staff Security Analyst will be a critical member of the GRC team working within the Information Security... 
    Suggested
    Local area
    Immediate start
    Remote work
    Flexible hours
    Shift work

    Harness

    Oregon State
    18 hours ago
  • A technology solutions company is seeking a remote SAP Security Analyst. The role involves troubleshooting SAP security, supporting projects...  ...concepts. Candidates should have experience with SAP security, GRC access control, and S/4 Hana, along with excellent communication... 
    Suggested
    Remote work

    Knack Solutions

    Chicago, IL
    2 days ago
  • $130k - $135k

    CorporateThe Security GRC Analyst II supports the organization’s data protection and governance programs by implementing security tools, maintaining compliance with data protection requirements, and assisting in the investigation of incidents involving sensitive information... 
    Suggested
    Minimum wage
    Ongoing contract
    Full time
    H1b
    Local area
    Remote work
    Worldwide

    ZOLL Medical Corporation

    Broomfield, CO
    4 days ago
  • $114k - $139k

    Reno, NV / Remote - USAdministration - Enterprise Information Security /Full-Time /RemoteAs a GRC Security Analyst, you will serve as a fully qualified, experienced professional responsible for ensuring Clear Capital adheres to all relevant security standards, regulations... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Remote work

    Clear Capital

    Reno, NV
    3 days ago
  • Monarch Money is seeking a Senior Security GRC Analyst to lead our compliance and customer security assurance efforts in a fully remote fintech setting. You will partner with People, Legal, IT, Operations, and Engineering to mature our program and automate evidence collection... 
    Suggested
    Remote job

    Monarch Money

    Covina, CA
    2 days ago
  • $128.25k - $266.88k

    Paranoids Senior Security GRC Analyst (Finance) Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions... 
    Work at office
    Flexible hours

    Yahoo Holdings Inc. in

    Richardson, TX
    4 days ago
  • $97.59k - $142.99k

     ...opportunity to join our team as a Sr. II Security Analyst - Vulnerabilities. In this role, the...  ...support of clients; risk management and other GRC responsibilities within a large...  ...organization.NYU Langone Health provides its staff with far more than just a place to work.... 
    Full time

    NYU Langone Medical Center

    New York, NY
    1 day ago
  •  ...environment that is respectful and inclusive for everyone.As a Security Analyst at Lucid Software, you will protect our corporate assets,...  ...and employees. You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk... 
    Remote work

    Lucidchart

    Salt Lake City, UT
    13 hours ago
  • $90k - $115k

     ...Our Senior Security Policy Analyst is responsible for developing, implementing, and maintaining security policies, standards, and procedures while...  ...hands-on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high-quality... 
    Contract work
    For contractors
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    WPS Health Solutions

    Detroit, MI
    4 days ago
  •  ...SAP Security Analyst Salary: Confidential Location: Apex, North Carolina Relocation Assistance: Available Job Description No...  ...supporting global SAP security operations across ECC (primary), GRC, and BW environments Heavily focused on SAP production support... 
    Work at office
    Work from home
    Relocation
    Relocation package
    Flexible hours

    Affinity Executive Search

    Apex, NC
    4 days ago
  • $10 - $15 per hour

     ...Applicants outside US are encouraged to apply Position: SAP Security Analyst Rate: $10-15 (Depending on your experience) Work Authorization:...  ...SAP security troubleshooting and end user support Experience in GRC access control, mitigation and remediation Experience with S/4... 
    Remote work

    Knack Solutions

    Chicago, IL
    13 hours ago
  •  ...Description Information Security Analyst About Us At Gifthealth, we're revolutionizing the way people experience healthcare by...  ...using Python, PowerShell, APIs, or similar technologies, and with GRC or IT service management platforms such as Vanta and... 
    Full time
    Remote work

    Gifthealth Inc

    United States
    5 days ago
  •  ...Title Position Title Junior Information Security Analyst Posting Number Posting Number 087-26 Full...  ...of Governance, Risk, and Compliance ( GRC ) principles and applicable security, privacy...  ...; work collaboratively with faculty, staff, students, and information technology... 
    Full time
    Part time
    Internship
    Work at office
    Monday to Friday
    Afternoon shift
    Early shift

    Uog

    Brooklyn, NY
    1 day ago
  • $149.1k

     ...'re looking for a Principal Information Security Analyst to join the Information Risk Management...  ...information security, risk management, GRC, third-party risk management, or a related...  ...complex security risks to non-technical staff and influence remediation at scaleDemonstrated... 
    Full time
    Contract work
    Immediate start
    Remote work

    Nike

    Beaverton, OR
    2 hours ago
  •  ...to support the evolution of our corporate security team. A specific focus will be on...  ...issues to a wide audience, from technical staff to management You have a positive and collaborative...  ...security measures Supporting the GRC and Privacy Programs as needed Staying up... 
    For contractors
    Flexible hours

    Ellation, Inc.

    Brooklyn, NY
    2 days ago
  • $49.73k - $73.13k

     ...place for you. We're looking for a detail-oriented and curious GRC Analyst to join our Governance, Risk & Compliance team. In this role,...  ...foundation in enterprise risk management and information security compliance, joining a senior, globally distributed team that will... 
    Work experience placement
    Internship
    Work at office
    Local area

    Commerce

    Remote
    18 hours ago
  •  ...environment that is respectful and inclusive for everyone. As a security analyst at Lucid you will be helping to protect corporate assets,...  ...field 1+ years experience with third party risk management, GRC, customer due diligence, etc. Understanding of common security... 
    Remote work

    Lucid

    Raleigh, NC
    6 days ago
  • $55 - $60 per hour

     ...pay range $55.00/hr - $60.00/hr Direct message the job poster from Akkodis Sr. Recruiter - GRC (Global Recruitment Center) at Akkodis Akkodis is seeking an IT Security Analyst for a Contract position with a client located in Quincy, MA. Rate Range: $55-$60/hr on W2 without... 
    Contract work
    Temporary work
    Work experience placement
    Local area
    Remote work
    Early shift

    Akkodis

    Quincy, MA
    6 days ago
  • $1,750 - $2,150 per month

     ...leading AI labs to engage experienced cybersecurity professionals — security analysts, penetration testers, incident responders, threat intelligence...  .../GCP), or zero‑trust design Governance, risk, and compliance (GRC) — NIST, ISO 27001, SOC 2, FedRAMP Professional... 
    Remote job
    Hourly pay

    Obsidian

    San Francisco, CA
    3 days ago
  •  ...position is to support NCF's information security strategy by performing Tier 1 security operations...  ...Senior Security Engineer. The Security Analyst monitors information systems for security...  ...in the governance, risk, and compliance (GRC) platform Governance, Risk,... 
    Work at office
    Local area

    National Christian Foundation

    Alpharetta, GA
    14 days ago
  •  ...to work remotely up to 2 days, including Friday. Position: IT Security Analyst II Location: Grafton, Wisconsin Remote Type: Hybrid Reports...  ...follow-up actions. Contribute to continuous improvement of GRC processes, security workflows, vendor review procedures, AI governance... 
    Contract work
    Remote work
    Worldwide
    3 days per week

    Regal Rexnord Corp

    Wisconsin
    3 days ago
  • $70k - $80k

    The IT Security Analyst will support and monitor the University’s cybersecurity systems to ensure...  ...Assist in governance, risk, and compliance (GRC) efforts, supporting documentation for...  ...input on security best practices for IT staff and end-users. Support identity and... 
    Work at office
    Remote work
    Flexible hours

    Regent

    Brooklyn, NY
    3 days ago
  •  ...applications and next steps. Our partner is looking for a Senior Security Analyst, Compliance based in the United States. This role will play...  ...process. This is an opportunity to help mature an evolving GRC function and establish scalable processes across the organization... 
    Full time
    Contract work
    Remote work

    jobgether

    United States
    8 days ago
  • $70 - $80 per hour

     ...: Job Overview: We are seeking a skilled SAP Application Security Analyst to support SAP security, GRC, and Identity & Access Management (IAM) within a complex enterprise environment. This role is responsible for managing user access, maintaining compliance controls... 
    Hourly pay
    Contract work
    Temporary work
    Remote work
    Shift work

    V-Tech Solutions

    White Plains, NY
    7 days ago
  • Network Security Analyst II - System Security & Risk (GRC) Specialist Level Description: 4-7 years of experience in the field or in a related area. Familiar...  ...determine employment eligibility. Contract Type: ITSAC Staff Augmentation Client: Texas Health and Human Services... 
    Contract work
    For contractors
    Work at office
    Remote work

    Lumen Solutions Group Inc.

    Austin, TX
    4 days ago
  • Senior Consultant - Epic Security Analyst - Remote Join to apply for the Senior Consultant - Epic Security Analyst - Remote role at Nordic Global...  ...$64,000.00-$117,000.00 2 weeks ago Principal Consultant - GRC/Security (Remote) Sr. Information Systems Security Manager (59... 
    Remote job
    Full time
    Contract work
    Local area

    Nordic Global

    New York, NY
    6 days ago
  • $120k - $140k

    Join to apply for the Consultant - Endpoint Security Analyst role at Kalles Group Join to apply for the Consultant - Endpoint...  ...Sales Consultant - End User - Door Hardware - Tacoma, WA Staff Cyber Security Engineer - GRC (REMOTE) Seattle, WA $85,000.00-$230,000.00 2 days ago... 
    Full time
    Remote work
    Flexible hours

    Kalles Group

    Seattle, WA
    6 days ago
  •  ...platform architecture, data model, application configuration, and workflow design Strong understanding of GRC processes, risk management, compliance frameworks, and security control assurance Experience integrating Archer with external enterprise platforms using REST APIs... 
    Local area
    Remote work

    Saxon Global

    Austin, TX
    4 days ago
  • $115k - $192.9k

     ...position... The Ford Credit IT Compliance and Information Security Analyst provides oversight of IT compliance and regulatory requirements...  ...technical compliance issues to any audience. ~ Experience with GRC & audit tools. ~ Understanding of AI/LLM technologies and... 
    Full time
    Immediate start
    Flexible hours

    Ford Motor Company

    Dearborn, MI
    1 day ago
  • $105k - $115k

     ...approved equivalent AI solution. DSA is hiring a Senior Information Security Analyst. This is a full-time position supporting a customer in the DC...  .... Leveraging the existing Governance, Risk, and Compliance (GRC) tool, Telos Xacta (or an alternate like CSAM or RSA Archer),... 
    Full time
    Contract work
    Work at office
    Remote work
    Flexible hours

    Data Systems Analysts, Inc.

    Fairfax, VA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Analyst - GRC. Be the first to apply!