Paranoids Senior Security GRC Analyst

Yahoo

Uz

Sur place

EUR 70 000 - 100 000

Plein temps

14 jours+
Générateur de candidature

Démarquez-vous pour ce poste — générez un CV personnalisé et une lettre de motivation en environ une minute.

Passez les filtres ATS

Résumé du poste

Yahoo's Paranoids team is seeking a Senior Security GRC Analyst to guide risk management, policy, and governance across Yahoo properties, coordinating with business leaders, engineers, and security teams.

You will evaluate risks, manage risk exceptions lifecycle, draft policies, and socialize standards, while leveraging AI tools to streamline reviews and ensure compliance with GDPR, SOC 2, and PCI DSS.

Qualifications

  • 5+ years of experience in security governance, risk management, compliance, or a related information security discipline.
  • Experience conducting comprehensive security risk assessments and communicating findings to leadership.
  • Strong written and verbal communication, executive memo drafting, and cross-functional collaboration.
  • Knowledge of security frameworks (NIST CSF, ISO 27001, FAIR) and cloud/web infra.
  • Experience developing or managing security policies and governance programs.
  • Experience using generative AI tools to accelerate productivity.
  • Understanding of GDPR, SOC 2, PCI DSS.
  • Proven track record of continuous process improvement.

Responsabilités

  • Evaluate and document known security risks for executive review with actionable options.
  • Manage end-to-end lifecycle of risk exceptions across Yahoo properties.
  • Conduct risk assessments against policies, frameworks, and architectures.
  • Draft, revise, and maintain security policies and standards.
  • Socialize standards with stakeholders and align cross-functionally.
  • Act as liaison translating security concepts for non-technical stakeholders.
  • Identify and implement AI-assisted workflows to automate GRC tasks.

Connaissances

Security governance
Risk assessment
Compliance
Executive communication
AI tooling awareness
Policies & standards
Stakeholder engagement
Regulatory frameworks (GDPR, SOC 2,PCI

Description du poste

Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.

A Little About Us

When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo, known as “The Paranoids.”

Within the Paranoids, the Cyber Risk team exists to guide Yahoo to make reasonable, compliant, cyber risk-conscious decisions. We position security as a business advantage - surfacing actionable cyber risks, facilitating executive risk decisions, and ensuring that security and compliance are aligned with company goals.

A Lot About You

We are looking for a Senior Security GRC Analyst to join the team. This role sits at the intersection of three critical GRC functions: exception management, security risk assessment, and policy and standards management.

You will work directly with business leaders, engineers, and Paranoids security teams to identify, assess, document, and communicate security risks - and then help the organization make informed decisions about them. Some days that means writing a risk evaluation memo that goes to the CISO. Other days it means assessing a property’s security posture against Paranoids policy, drafting a new standard, or working through the nuances of an exception request with a business unit that’s navigating a hard tradeoff.

We operate in a modern, fast-moving security landscape. We view AI as a force multiplier that allows us to scale governance, synthesize complex technical data faster, and deliver higher-impact risk insights. The work requires that you understand enough about technology to ask the right questions, exercise sound judgment when evaluating AI-generated outputs, and understand enough about the business to frame risk in terms that drive good decisions.

Responsibilities
  • Evaluate and document known security risks for executive review, ensuring risks are described clearly, contextualized for impact, and paired with actionable treatment options.

  • Manage the end-to-end lifecycle of risk exceptions from intake and evaluation through decision, documentation, and periodic reassessment across Yahoo properties.

  • Conduct property-level and initiative-level security risk assessments against Paranoids policies, industry frameworks, and modern architecture patterns.

  • Draft, revise, and maintain security policies and standards that set clear, realistic expectations across engineering and product teams.

  • Partner with stakeholders across the business to socialize new or updated standards, gathering input and building cross-functional alignment before publication.

  • Act as a trusted liaison between business teams, engineering, and security - translating technical security concepts for non-technical stakeholders and ensuring business context informs risk decisions.

  • Identify and implement AI-assisted workflows and automation to eliminate manual GRC tasks, and streamline security exception and policy reviews

Basic Qualifications
  • 5+ years of experience in security governance, risk management, compliance, or a related information security discipline within modern technology environments.

  • Demonstrated experience conducting comprehensive security risk assessments and communicating actionable findings to senior leadership and technical teams.

  • Strong written and verbal communication skills - proven ability to write an executive-ready risk memo, present to leaders, and collaborate effectively with software and infrastructure engineers.

  • Working knowledge of security frameworks and risk methodologies (e.g., NIST CSF, ISO 27001, FAIR) and how they apply to real-world cloud infrastructure, web applications, and identity systems.

  • Proven experience developing or managing security policies, standards, or exception/risk acceptance governance programs.

  • Demonstrated experience using generative AI tools (e.g., Claude, ChatGPT, Gemini, Copilot) to accelerate daily productivity including drafting documentation, structuring risk analyses, or automating repetitive research workflows.

  • Strong critical evaluation skills with the ability to exercise judgment in when to apply AI tools versus manual review, paired with an understanding of AI data confidentiality and risk governance.

  • Understanding of regulatory and compliance frameworks applicable to global technology organizations (e.g., SOC 2, PCI DSS, GDPR).

  • Track record of continuous process improvement-having established or meaningfully upgraded an assessment program, policy lifecycle, or risk tracking mechanism.

Preferred Qualifications
  • Experience working within an information security organization at a large-scale consumer technology or cloud enterprise.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Senior Security GRC Analyst: AI-Driven Risk & Compliance
Senior Security GRC Analyst: AI-Driven Risk & Compliance

Yahoo • Uz

Sur place
EUR 70 000 - 100 000
Paranoids Detection Engineering Senior Manager
Paranoids Detection Engineering Senior Manager

Yahoo • Uz

Hybride
EUR 125 000 - 260 000
Flexible hybrid work options
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst
Paranoids, Weekend Night Shift - Forensic and Incident Response Operations (FIRE) Analyst

Yahoo • Uz

Hybride
EUR 77 000 - 160 000
Senior Manager, Detection Engineering — Paranoids (Hybrid)
Senior Manager, Detection Engineering — Paranoids (Hybrid)

Yahoo • Uz

Hybride
EUR 125 000 - 260 000
Flexible hybrid work options
GRC Manager
GRC Manager

Welcome to the Jungle France • Paris

Sur place
EUR 55 000 - 75 000
Senior Security Engineer
Senior Security Engineer

Adrixis • Paris

Sur place
EUR 90 000 - 130 000
Senior IR Lead — Night Shift, AI-Driven Forensics
Senior IR Lead — Night Shift, AI-Driven Forensics

Yahoo • Uz

Hybride
EUR 110 000 - 230 000
Hybrid work options
Healthcare
401k
+2
Senior Security Analyst - GRC
Senior Security Analyst - GRC

Ivalua • Massy

Sur place
EUR 45 000 - 65 000
Cyber GRC Specialist
Cyber GRC Specialist

Sonepar Canada, Inc. • Paris

Sur place
EUR 65 000 - 90 000
Privacy Counsel
Privacy Counsel

Yahoo • Uz

Hybride
EUR 106 000 - 222 000
CIPP/US
CIPP/E
Privacy certification
+2