GRC Analyst / Product Owner

Allen Recruitment

California (MO)

On-site

USD 110,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Allen Recruitment is seeking a GRC Analyst / Product Owner & Framework Engineer for a security and compliance software company. The role focuses on integrating security frameworks, refining control mappings, and building automation to simplify compliance with SOC 2, ISO 27001, GDPR and other standards.

Ideal candidates will have experience building security programs from scratch, strong knowledge of major frameworks, and scripting skills to automate updates and validate processes within

Qualifications

  • Hands-on experience understanding and working with ISO 27001, SOC 2, GDPR, HIPAA, and ISO 42001 frameworks.
  • Ability to evaluate control frameworks, identify gaps, and craft rationalization strategies.
  • Experience mapping controls across frameworks to spot overlaps and enable automation.
  • Basic scripting to automate updates and validate compliance via code.
  • Comfort with reading and editing JSON/configuration files for control libraries and scripts.

Responsibilities

  • Analyze and integrate multiple cybersecurity frameworks into client platform.
  • Refine and maintain control libraries and mappings for cross-framework compatibility.
  • Develop automation solutions to streamline compliance processes.

Skills

Security compliance knowledge
Framework development
Control mapping
Scripting & automation
JSON & configuration management
Programming (Python)
GRC SaaS experience

Education

Bachelor’s degree in information security, CS or related field

Job description

We’re hiring a GRC Analyst / Product Owner & Framework Engineer for a young, successful andfast-growing,security and compliance software company building a modern platform used by security teams.

Dedicated to simplifying security standards such as SOC 2, ISO 27001, and others. We are seeking a Compliance Product Owner who can develop, refine, and maintain their control mapping library, support new compliance frameworks, and enhance automation features. This role offers an exciting opportunity to contribute to a pioneering product that aims to disrupt the traditional, often complex, compliance industry by integrating control rationalization and automation solutions. Ideal candidates will have a solid understanding of security frameworks, experience with control mapping, and basic scripting skills, all within a collaborative and fast-paced environment.

Important:

for this search, we’re prioritising candidates who have:

  • 1) Experience building security programs from scratch to meet with compliance requirements.
  • 2) Strong working knowledge of major compliance frameworks (ISO 2701, SOC 2, GDPR, HIPAA, PCI DSS).
Must-haves (hard requirements)
  • Security Compliance Framework Knowledge:Practical experience understanding and working with frameworks like ISO 27001, SOC 2, GDPR, HIPAA, and ISO 42001. Ability to interpret and break down these frameworks into actionable requirements.
  • Assessment & Framework Development:Ability to evaluate existing control frameworks, identify gaps, and develop rationalization strategies that enhance compatibility across standards.
  • Control Mapping & Rationalization:Skilled in mapping controls across multiple frameworks to identify overlaps, redundancies, and inefficiencies in control libraries, supporting seamless automation.
  • Scripting & Automation:Basic scripting skills capable of automating control and requirement updates, and validating compliance processes through code.
  • JSON & Configuration Management:Comfortable reading, editing, and manipulating structured configuration files (JSON), crucial for maintaining control libraries and automation scripts.
Technical Nice to Have Skills:
  • Programming Experience:Coding background, especially in Python or related languages, enhancing automation and integration capabilities.
  • GRC SaaS Experience:Prior exposure to security governance, risk, and compliance software, providing context to platform integration.
Educational and Certification Requirements:
  • Educational Background:Bachelor’s degree in information security, computer science, or related field preferred.
  • Certifications:Advantageous include ISO 27001 Lead Implementer, SOC 2 Auditor, or related compliance certifications.
What you’ll do

This role centers on integrating and supporting various cybersecurity frameworks into our client's platform. The successful candidate will focus on analyzing new frameworks, optimizing existing control libraries, and developing automation solutions that streamline compliance processes for clients. Their work directly impacts the effectiveness and usability of the platform, ensuring it remains a leading solution for security and compliance automation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Product Owner & Framework Automation Lead
GRC Product Owner & Framework Automation Lead

Allen Recruitment • California (MO)

On-site
USD 110,000 - 150,000
GRC Analyst – SecOps
GRC Analyst – SecOps

Bright Defense, LLC. • United States

On-site
USD 70,000 - 90,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 95,000 - 116,000
Hybrid work model
Relocation assistance
Certification sponsorship
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
GRC Security Analyst: Automate Compliance & Risk
GRC Security Analyst: Automate Compliance & Risk

Discord • San Francisco (CA)

Hybrid
USD 144,000 - 162,000
Equity
Relocation assistance
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
GRC Analyst
GRC Analyst

Recru • Houston (TX)

Hybrid
USD 90,000 - 120,000
Senior Manager, GRC
Senior Manager, GRC

Jobtailor • California (MO)

On-site
USD 130,000 - 165,000
GRC Security compliance leader
GRC Security compliance leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

duvari group • Fenton (MO)

On-site
USD 83,000 - 131,000