GRC Security Analyst: Risk, Policy & Audit Lead

Pinterest

United States

Hybrid

USD 124,000 - 255,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Pinterest is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance to strengthen governance and assurance programs. You will partner with Security, Engineering, IT, Legal, Internal Audit and cross-functional teams to maintain and improve the security control environment.

The role covers risk management, policy governance, control testing, audit support, and awareness tracking, with opportunities to influence security maturity and process improvements at scale.

Qualifications

  • 4+ years of experience in security governance, risk, compliance, audit, or security assurance roles.
  • Working knowledge of SOC 2, CIS Controls, ISO 27001, NIST CSF or similar.
  • Experience supporting audits, assessments, or control testing in a technology/SaaS environment.
  • Ability to write clear, practical security policies, standards, and procedures.
  • Experience maintaining risk registers and supporting formal risk assessment processes.

Responsibilities

  • Administer and maintain the security risk register with updates, owners, and reports.
  • Partner with stakeholders to identify, document, assess, and monitor security risks.
  • Draft, review, update, and manage the lifecycle of security policies and standards.
  • Support SOC 2 Type 2 audit planning, evidence collection, and follow-up.
  • Track security awareness training metrics and remediation actions.
  • Execute control testing aligned to CIS Controls and document findings and remediation.

Skills

Security governance
Risk assessment
Policy writing
Audit support
Documentation
Cross-functional collaboration
Communication
Attention to detail
Strategic thinking

Education

Bachelor's degree in Computer Information Systems or Cybersecurity
Equivalent experience

Tools

SOC 2
CIS Controls
ISO 27001
NIST CSF

Job description

Pinterest is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance to strengthen governance and assurance programs. You will partner with Security, Engineering, IT, Legal, Internal Audit and cross-functional teams to maintain and improve the security control environment.

The role covers risk management, policy governance, control testing, audit support, and awareness tracking, with opportunities to influence security maturity and process improvements at scale.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Analyst — Risk, Policy & Audit
Security GRC Analyst — Risk, Policy & Audit

Pinterest • San Francisco (CA)

On-site
USD 124,000 - 255,000
Security GRC Analyst
Security GRC Analyst

Pinterest • United States

On-site
USD 124,000 - 255,000
Security GRC Analyst
Security GRC Analyst

Pinterest • San Francisco (CA)

On-site
USD 124,000 - 255,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC Lead for AI Security: SOC 2 & ISO 27001
GRC Lead for AI Security: SOC 2 & ISO 27001

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10
Security GRC Engineer: Risk, Audit & Compliance
Security GRC Engineer: Risk, Audit & Compliance

Whatnot • Seattle (WA)

On-site
USD 175,000 - 230,000
Health Insurance options including US
Work From Home support
Home office setup allowance
+5
GRC Architect & Risk Strategy Leader
GRC Architect & Risk Strategy Leader

Palo Alto Networks, Inc. • Santa Clara (CA)

On-site
USD 168,000 - 271,000
Security GRC Engineer: Risk, Audits and Compliance
Security GRC Engineer: Risk, Audits and Compliance

Whatnot • San Francisco (CA)

On-site
USD 175,000 - 230,000
Health Insurance
Home office setup allowance
Cell phone and internet allowance
+6
Security GRC Engineer — Lead Compliance & Risk
Security GRC Engineer — Lead Compliance & Risk

Whatnot • Los Angeles (CA)

Hybrid
USD 120,000 - 180,000
Health Insurance options
Work From Home Support
Home office setup allowance
+3
Senior GRC Architect: Policy, Risk & Automation
Senior GRC Architect: Policy, Risk & Automation

Palo Alto Networks • California (MO)

On-site
USD 168,000 - 271,000