Information Security Analyst, GRC

Xbow

California (MO)

Hybrid

USD 121,000 - 161,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Stock options
Remote-first

Job summary

XBOW, redefining cybersecurity with an AI-driven autonomous pentester, seeks an Information Security Analyst, GRC to scale security reviews, vendor risk, and regulatory compliance. You will coordinate with Legal on contracts and drive risk management across IT, Security, Engineering, and Sales in a fast-moving environment.

You’ll help shape policies, risk registers, and evidence for SOC 2, ISO 27001, and other frameworks while advocating pragmatic, scalable risk practices across the company.

Qualifications

  • 7+ years of experience in risk, compliance, security assurance, or related roles.
  • Hands-on technical experience in Engineering, IT or security operations.
  • Experience completing or reviewing technical security questionnaires and customer risk assessments.
  • Familiarity with common security frameworks (SOC 2, ISO 27001, NIST, GDPR, HIPAA).
  • Experience conducting or supporting vendor/ third-party risk assessments.
  • Strong written communication; ability to explain complex security concepts clearly.
  • Highly organized and detail-oriented, with pragmatic risk approach.
  • Comfortable in a fast-moving, remote-first startup environment.
  • Familiar with using modern AI tooling to improve productivity whilst managing risk.

Responsibilities

  • Support customers with security questionnaires, risk assessments, and due-diligence requests.
  • Explain XBOW’s security controls, architecture, and compliance posture to Sales and Customer teams.
  • Assess and manage third-party and vendor security risk.
  • Investigate and resolve alerts using the Vanta product.
  • Maintain risk assessment frameworks, methodologies, and documentation.
  • Track remediation of identified risks with internal stakeholders.
  • Contribute to compliance initiatives aligned with SOC 2, FedRAMP, ISO 27001, and ISO 42001.
  • Maintain clear risk registers, policies, and supporting evidence.
  • Coordinate risk management sessions and processes.
  • Identify opportunities to streamline and automate risk and compliance as the company scales.
  • Support audits, customer reviews, and internal assurance activities.

Skills

Risk management
Compliance
Security assurance
Security questionnaires
Vendor risk
Written communication
Regulatory frameworks
Remote work

Tools

Vanta

Job description

About XBOW

At XBOW, we’re redefining the future of cybersecurity by building the world's first autonomous pentester, powered by AI. Today, the gold standard for securing software systems is human pentesters, but with the rise of artificial intelligence, we’re stepping up to scale offensive security to meet the ever-growing demand.

AI is transforming the landscape of both cybersecurity and cyberattacks. While millions of people without security expertise are creating software, bad actors are using AI to launch more effective attacks. XBOW fights back with AI-driven superpowers, enabling security teams to stay one step ahead.

What makes XBOW truly unique? Like human experts, it forges creative attacks, adapts its learnings, and continuously works to find vulnerabilities faster than anyone ever could. We’re not only simulating threats—we’re also finding and responsibly disclosing real-world vulnerabilities, ensuring organizations can fix issues before they’re exploited. XBOW isn't just a tool; it’s a transformative force in the secure development lifecycle.

Backed by Sequoia Capital and a team that includes the creators of GitHub Copilot and GitHub Advanced Security, XBOW is not just keeping up with the times—we’re shaping the future of cybersecurity. Our mission is simple: to defeat the bad actors before they strike, using AI to revolutionize how we approach offensive security.

We’re building something that must be built, and we’re the team to do it. Join us in shaping the next frontier of autonomous security.

Your Role: Information Security Analyst, GRC

We’re looking for a detail-oriented, Information Security Analyst to help scale our security and trust function as we grow. In this role, you’ll play a key part in supporting customer and prospect security reviews, coordinating with legal on reviewing customer contracts, assessing third‑party vendor risk, supporting resolution of compliance alerts and continuously improving how we identify and manage risk across the business.

This is an individual contributor role with no initial people‑management responsibilities. However, as the risk and compliance function matures, there is a clear opportunity for this role to grow in scope and responsibility.

You’ll work closely with IT, Security, Engineering, Legal, Sales, and Customer teams, acting as a trusted partner in communicating our security posture and ensuring we meet customer and regulatory expectations.

What You’ll Do
  • Support customers and prospects by completing technical security questionnaires, risk assessments, and due‑diligence requests

  • Partner with Sales and Customer teams to explain XBOW’s security controls, architecture, and compliance posture

  • Assess and manage third‑party and vendor security risk, including reviews of SaaS providers and service partners

  • Investigate and resolve alerts to stay compliant with our compliance programmes using the Vanta product.

  • Help maintain and improve risk assessment frameworks, methodologies, and documentation

  • Track and support remediation of identified risks in collaboration with internal stakeholders

  • Contribute to compliance initiatives aligned with frameworks such as SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001

  • Maintain clear, well‑structured risk registers, policies, and supporting evidence

  • Coordinate risk management sessions and processes

  • Identify opportunities to streamline and automate risk and compliance processes as the company scales

  • Support audits, customer reviews, and internal assurance activities as needed

Skills and Qualifications
Essential
  • 7+ years of experience in risk, compliance, security assurance, or related roles

  • Experience in hands‑on technical roles for example in Engineering, IT or operational security

  • Hands‑on experience completing or reviewing technical security questionnaires and customer risk assessments

  • Familiarity and experience with common security compliance, and data protection frameworks (e.g. SOC 2, ISO 27001, NIST, GDPR, and HIPAA)

  • Experience conducting or supporting vendor / third‑party risk assessments

  • Strong written communication skills, with the ability to explain complex security concepts clearly

  • Highly organized and detail‑oriented, with a pragmatic approach to risk

  • Comfortable working in a fast‑moving, remote‑first startup environment

  • Familiar with using modern AI tooling to improve productivity whilst managing risk

Advantageous
  • Experience working in a SaaS or security‑focused company

  • Experience handling Subject Access Requests for GDPR

  • Security or risk certifications (e.g. CRISC or CISSP)

  • Knowledge of cloud security best practices

What We Offer
  • Compensation & Equity: Competitive salary and meaningful stock options.

  • Growth: Opportunity to learn from and collaborate with top security and AI experts

  • Impact: Work on complex technical challenges that support the foundation of our company

  • Remote-First:Work from anywhere, with regular opportunities to meet in person

What Else You Should Know
  • Location: Remote UK/EU (all team members are remote but we meet regularly and you’re supported to travel to collaborate with colleagues in person)

  • Contract: Full-time.

  • Hiring Process:

    1. Talent Introduction

    2. GRC & Security Knowledge Interview

      • A conversation about your practical security and GRC knowledge and how you apply it in day‑to‑day compliance work.

    3. Hiring Manager Interview

    4. Final Interview with a member of our leadership team

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer - Platform / Core Infrastructure - Americas
Software Engineer - Platform / Core Infrastructure - Americas

XBOW • United States

Remote
USD 140,000 - 210,000
Competitive salary
Generous equity package
Career growth opportunities
+1
Software Engineer - Platform / Core Infrastructure - EMEA
Software Engineer - Platform / Core Infrastructure - EMEA

XBOW • United States

Remote
USD 100,000 - 150,000
Competitive salary
Generous equity package
Career growth opportunities
Senior Legal Counsel - Commercial
Senior Legal Counsel - Commercial

Xbow • Northern (KY)

Hybrid
USD 180,000 - 260,000
Equity
Remote-friendly
Career growth
Senior Remote GRC & Security Risk Analyst
Senior Remote GRC & Security Risk Analyst

Xbow • California (MO)

Hybrid
USD 121,000 - 161,000
Stock options
Remote-first
Senior GRC & Security Risk Analyst — Remote
Senior GRC & Security Risk Analyst — Remote

XBOW • United States

Remote
USD 120,000 - 190,000
Competitive stock options
Remote-first culture
Enterprise Cybersecurity GRC Governance Analyst
Enterprise Cybersecurity GRC Governance Analyst

Phase2 Technology • McLean (VA)

On-site
USD 99,000 - 225,000
GRC Engineer
GRC Engineer

Apex Fintech Solutions • United States

Hybrid
GBP 70,000 - 110,000
Market-leading salary
Annual bonus
28 days annual leave
+7
GRC Engineer
GRC Engineer

PEAK6 • United States

Hybrid
GBP 65,000 - 95,000
Annual bonus
Leave & holidays
Training budget
+7
Security Analyst
Security Analyst

DigitalXForce Corporation • United States

On-site
USD 70,000 - 110,000
Information Security Lead
Information Security Lead

United States Digital Space LLC • United States

Remote
USD 140,000 - 200,000
Remote work
Equity package
Development budget
+5