Security GRC Analyst

Pinterest

United States

Hybrid

USD 124,000 - 255,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Pinterest is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance to strengthen governance and assurance programs. You will partner with Security, Engineering, IT, Legal, Internal Audit and cross-functional teams to maintain and improve the security control environment.

The role covers risk management, policy governance, control testing, audit support, and awareness tracking, with opportunities to influence security maturity and process improvements at scale.

Qualifications

  • 4+ years of experience in security governance, risk, compliance, audit, or security assurance roles.
  • Working knowledge of SOC 2, CIS Controls, ISO 27001, NIST CSF or similar.
  • Experience supporting audits, assessments, or control testing in a technology/SaaS environment.
  • Ability to write clear, practical security policies, standards, and procedures.
  • Experience maintaining risk registers and supporting formal risk assessment processes.

Responsibilities

  • Administer and maintain the security risk register with updates, owners, and reports.
  • Partner with stakeholders to identify, document, assess, and monitor security risks.
  • Draft, review, update, and manage the lifecycle of security policies and standards.
  • Support SOC 2 Type 2 audit planning, evidence collection, and follow-up.
  • Track security awareness training metrics and remediation actions.
  • Execute control testing aligned to CIS Controls and document findings and remediation.

Skills

Security governance
Risk assessment
Policy writing
Audit support
Documentation
Cross-functional collaboration
Communication
Attention to detail
Strategic thinking

Education

Bachelor's degree in Computer Information Systems or Cybersecurity
Equivalent experience

Tools

SOC 2
CIS Controls
ISO 27001
NIST CSF

Job description

About Pinterest:

Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we're on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product.

Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other's unique experiences and embrace theflexibility to do your best work. Creating a career you love? It's Possible.

At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we're looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we'll explore your foundational skills and how you collaborate with AI.

Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here.

Pinterest's Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively.

Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest's security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessments.

What you'll do:
  • Administer and maintain the security risk register, including tracking identified risks, updates, remediation activities, owners, and reporting outputs.
  • Partner with stakeholders across Security and the business to identify, document, assess, and monitor security risks.
  • Draft, review, update, and manage the lifecycle of security policies, standards, and supporting procedures.
  • Support the planning, coordination, evidence collection, and follow-up activities for Pinterest's annual SOC 2 Type 2 audit.
  • Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions.
  • Execute security control testing activities aligned to CIS Controls and document testing outcomes, findings, and remediation recommendations.
  • Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders.
  • Help monitor control effectiveness and identify opportunities to improve process maturity, consistency, and evidence quality.
  • Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit, and awareness program status.
  • Support remediation tracking for control gaps, audit findings, and risk treatment actions.
  • Contribute to the continuous improvement of Pinterest's GRC framework, documentation, and operating rhythms.
  • Maintain strong working relationships with internal partners to promote a practical, business-aligned approach to security governance and compliance.
What we are looking for:
  • 4+ years experience in security governance, risk, compliance, audit, or security assurance roles.
  • Working knowledge of core security and compliance frameworks such as SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar.
  • Experience supporting audits, assessments, or control testing programs in a technology or SaaS environment.
  • Ability to write clear, practical, and actionable security policies, standards, and process documentation.
  • Experience maintaining risk registers and supporting formal risk assessment processes.
  • Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail.
  • Comfort working cross-functionally and gathering information or evidence from technical and non-technical stakeholders.
  • Strong written and verbal communication skills, including the ability to summarize risk and compliance issues clearly.
  • A pragmatic, collaborative mindset and a desire to help teams meet security requirements in a scalable way.
  • Bachelor's degree in a relevant field such as Computer Information systems or Cybersecurity, or equivalent experience.
Preferred qualifications:
  • Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment.
  • Familiarity with security awareness program administration and reporting.
  • Experience performing or coordinating control testing mapped to recognized frameworks such as CIS Controls.
  • Knowledge of common enterprise security domains, including identity and access management, logging and monitoring, vulnerability management, endpoint security, and third-party risk.
  • Relevant certifications such as Security+, CISA, CRISC, CISSP, or similar are a plus.
In-Office Requirement Statement:
  • We let the type of work you do guide the collaboration style. That means we're not always working in an office, but we continue to gather for key moments of collaboration and connection.
  • This role will need to be in the office for in-person collaboration 1-2 times/quarter and therefore can be situated anywhere in the country.
Relocation Statement:
  • This position is not eligible for relocation assistance. Visit our PinFlex page to learn more about our working model.
Our Commitment to Inclusion:

Pinterest is an equal opportunity employer and makes employment decisions on the basis of merit. We want to have the best qualified people in every job. All qualified applicants will receive consideration for employment without regard to race, color, ancestry, national origin, religion or religious creed, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, age, marital status, status as a protected veteran, physical or mental disability, medical condition, genetic information or characteristics (or those of a family member) or any other consideration made unlawful by applicable federal, state or local laws. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you require a medical or religious accommodation during the job application process, please completethis form for support.

Information regarding the culture at Pinterest and benefits available for this position can be found here.

US based applicants only

$123,696 — $254,667 USD

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Analyst
Security GRC Analyst

Pinterest • San Francisco (CA)

On-site
USD 124,000 - 255,000
Sr. Director, Security Engineering
Sr. Director, Security Engineering

Pinterest • Palo Alto (CA), San Francisco (CA)

On-site
USD 330,000 - 577,000
Senior Security Software Engineer, Security Operations
Senior Security Software Engineer, Security Operations

Pinterest • San Francisco (CA)

Hybrid
USD 156,000 - 320,000
Staff Technical Program Manager, Security
Staff Technical Program Manager, Security

Pinterest • United States

Hybrid
USD 146,000 - 300,000
Security Software Engineer II, Detection and Response
Security Software Engineer II, Detection and Response

Pinterest • United States

Hybrid
USD 123,000 - 255,000
Sr. Security Software Engineer, Application Security
Sr. Security Software Engineer, Application Security

Pinterest • Chicago (IL)

Remote
USD 155,000 - 321,000
Sr. Security Software Engineer, Security Operations
Sr. Security Software Engineer, Security Operations

Pinterest • San Francisco (CA)

On-site
USD 156,000 - 320,000
Equity
Sr. Security Software Engineer, Security Operations
Sr. Security Software Engineer, Security Operations

Pinterest • United States

Hybrid
USD 156,000 - 320,000
Equity
Office visits 1–2 times every 6 months
Staff Technical Program Manager, Security
Staff Technical Program Manager, Security

Socket.dev • San Francisco (CA)

Hybrid
USD 146,000 - 300,000
Sr. Security Software Engineer, Application Security
Sr. Security Software Engineer, Application Security

Pinterest • Chicago (IL)

On-site
USD 155,000 - 321,000