Senior Security GRC Analyst

Turo

San Francisco (CA)

Hybrid

USD 131,000 - 164,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity
In-office lunch
Office snacks
Paid time off
Paid holidays
Volunteer time off
Parental leave

Job summary

Turo is seeking a Senior Security GRC Analyst to own SOC 2 Type II and PCI DSS audit readiness and drive cross-functional security compliance efforts. You will coordinate evidence with Engineering, IT, Finance, Legal, and business owners, manage findings and remediation, and maintain the control framework for ongoing audit readiness.

Ideal candidates bring 5+ years in security compliance, GRC, or IT audit, with hands-on SOC 2/PCI DSS experience, and familiarity with AWS/IAM and encryption

Qualifications

  • 5+ years in security compliance, GRC, or IT audit.
  • Direct ownership of at least one full audit cycle under SOC 2 Type II and/or PCI DSS.
  • Coordinating evidence collection across multiple teams with limited oversight.
  • Knowledge of cloud security (AWS), IAM, and encryption frameworks.

Responsibilities

  • Own the compliance calendar and drive audit readiness for SOC 2 Type II and PCI DSS.
  • Coordinate evidence collection across Engineering, IT, Finance, and business teams.
  • Serve as primary liaison with external auditors and assessors.
  • Maintain and evolve the control framework across SOC 2 and PCI DSS.
  • Lead testing, document results, and manage evidence repositories.

Skills

Security compliance
GRC
IT audit
AWS
IAM
Encryption
Policy writing
Interpersonal communication

Education

Bachelor's degree in Computer Science, Information Security, Information Assurance or equivalent practical experience
CISA
CISM
CISSP

Tools

Vanta
Drata
ZenGRC

Job description

# **About the team**Turo is searching for a highly motivated and versatile Senior Security GRC Analyst under the Enterprise Security team to lead security compliance programs as a senior individual contributor. This role carries primary ownership of SOC 2 Type II and PCI DSS audit readiness and coordination, and serves as the connective tissue between Engineering, IT, Finance, Legal, and business control owners. You will drive complex security compliance workstreams with limited oversight, exercising strong judgment and cross-functional influence to keep Turo audit-ready year-round.# **What you will do**Security Compliance & Audit Readiness* Own the compliance calendar and drive end-to-end audit readiness for SOC 2 Type II and PCI DSS, including scoping, control mapping, and continuous readiness between audit cycles.* Coordinate evidence collection across Engineering, IT, Finance, and business teams; track control owners and close gaps ahead of audit windows.* Serve as the primary day-to-day liaison with external auditors and assessors to manage requests, facilitate walkthroughs, and coordinate remediation of findings.* Maintain and evolve the common control framework: map controls across SOC 2, PCI DSS, and other applicable standards; identify and eliminate redundant testing where possible.* Lead compliance testing activities, document results, and maintain evidence repositories that support both internal review and external audit.Findings, Remediation & Exception Management* Track open audit findings and remediation commitments; provide status reporting to Security leadership and relevant stakeholders.* Manage the security exception process and document risk acceptances, obtain appropriate approvals, and monitor exceptions through expiration or remediation.* Identify control gaps proactively and partner with control owners to design and implement compensating or corrective controls.Policy & Governance* Develop, maintain, and enforce security policies, standards, and procedures; keep them current with regulatory change and evolving business needs.* Partner with Legal on data-privacy obligations, subprocessor reviews, and breach-notification readiness.* Establish and report on compliance metrics - audit readiness scores, open findings aging, exception inventory, and cycle time - to drive accountability and visibility.* Identify and implement process and automation improvements that increase throughput and reduce manual effort across compliance workflows.## **Your Profile*** 5+ years in security compliance, GRC, or IT audit, with hands-on experience running security audit programs from start to finish.* Direct ownership of at least one full audit cycle under SOC 2 Type II and/or PCI DSS - from scoping through final report.* Demonstrated ability to coordinate evidence collection and remediation across multiple engineering and business teams with limited oversight.* Working knowledge of cloud security (AWS), IAM, and encryption frameworks - sufficient to assess controls and evaluate evidence critically.* Strong written and verbal communication skills; able to translate technical compliance requirements into clear guidance for non-security stakeholders.* Comfort operating independently in an ambiguous, fast-moving environment, managing competing deadlines without close supervision.* Bachelor's degree in Computer Science, Information Security, Information Assurance or equivalent practical experience.* Relevant certification: CISA, CISM, CISSP, or equivalent security certification.* Experience scaling a security compliance program through initial certification and into annual renewal cycles.* Familiarity with GRC tooling (e.g., Vanta, Drata, ZenGRC) and security-automation platforms.* Experience in a regulated or high-trust industry - fintech, marketplace, or SaaS handling sensitive personal or financial data.For this role, the target base salary range in San Francisco is $131,000-$164,000 annually. This role is also eligible for equity and benefits. In general, our ranges reflect the market-based target for new hire salaries based on the level and location of the role. Within the range, individual pay is determined by objective factors assessed during the application and interview process, such as job-related skills, experience, and relevant education or training. We encourage you to talk with your recruiter to learn more about the total compensation and benefits available for this role.***Turo highly values having employees working in-office to foster a collaborative work environment and company culture. This is central to how we work, and this role will be subject to our current in-office hybrid schedule that requires Turists to work in the office three days per week on Mondays, Wednesdays, and Thursdays. We expect that employees will meet these required in-office days consistently as part of their role. Your recruiter can share more information about this requirement and the in-office perks Turo offers.***# **Turo Recruiting Scam Alert:***We've learned that there are scammers targeting job candidates by impersonating Turo and its employees. We ask candidates to be careful of fraudulent job postings or suspicious recruiting activity during their job search, especially if they're contacted through unofficial channels (such as Instagram, Telegram, MS Teams, etc.). In general, Turo interacts with candidates through our* *and via turo.com email addresses, and we don't ask candidates for sensitive financial or personal info or request money as part of the hiring process (so an application fee or equipment costs).* *If candidates are not sure whether they're dealing with an impersonator, they can contact Turo's Recruiting Team at* *recruit@turo.com*. *Candidates can also report suspicious activity to the* *or other appropriate authorities.*# **Turo AI Policy:**Turo may use AI-enabled tools to support our recruiting operations, including gathering information from candidates, drafting communications, helping with interview note-taking and assessment, and so on. These tools only supplement our team; all decisions to advance or hire candidates are made by Turo employees. While we welcome candidates to use AI-enabled tools to help prepare for their interviews, the use of such tools, including any AI chatbots or note-takers, is not permitted during live interviews or technical assessments. We want to see how you consider and solve problems in real-time, so interviews and assessments are all you (unless we indicate otherwise and ask you specifically to use an AI-enabled tool to answer a question). If during the application process you require the use of an AI-enabled tool as a reasonable accommodation for a disability, please let us know at PeopleOps@turo.com.## **Benefits*** Competitive salary, equity, benefits, and perks for all full-time employees* Employer-paid medical, dental, and vision insurance (Country specific)* Retirement employer match* Learning & Development stipend to invest in your professional development* Turo host matching program* Turo travel credit* Cell phone and internet stipend* Paid time off to relax and recharge* Paid holidays, volunteer time off, and parental leave* For those who are in the office full-time or hybrid we have in-office lunch, office snacks, and fun activitiesWe are committed to building a diverse team. If you are from a background that's underrepresented in tech, we'd love to meet you.Aside from an award winning work environment and the opportunity to be part of the world's largest car sharing marketplace, we are also growing the team quickly - join us! Even if you don't meet every qualification, we are looking for people with enthusiasm for what we do and we will consider you for this and other possibilities.# ****About Turo****Turo is the world's largest car sharing marketplace where you can book the perfect car for wherever you're
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Enterprise Security
Senior Security Engineer, Enterprise Security

Turo Inc • San Francisco (CA)

On-site
USD 148,000 - 185,000
Employer-paid medical, dental, and vision insurance
Retirement employer match
Learning & Development stipend
+6
Senior Vendor Security Risk Analyst
Senior Vendor Security Risk Analyst

Turo • San Francisco (CA)

Hybrid
USD 131,000 - 164,000
Competitive salary
Equity
Medical, dental, and vision insurance
+4
Senior Software Engineer, Platform Engineering
Senior Software Engineer, Platform Engineering

Turo • San Francisco (CA)

Hybrid
USD 156,000 - 195,000
Equity
Medical insurance
Dental & Vision insurance
+8
Staff Data Engineer, Data Platform
Staff Data Engineer, Data Platform

Turo • San Francisco (CA), Northern (KY)

Hybrid
USD 182,000 - 228,000
Equity
Medical insurance
Hybrid work schedule
+5
Senior Director, Fraud Prevention
Senior Director, Fraud Prevention

Turo, Inc. • Phoenix (AZ), Northern (KY)

On-site
USD 180,000 - 220,000
Competitive salary
Equity and benefits
Hybrid in-office schedule (Phoenix)
+1
Tax Technology & Innovation Manager
Tax Technology & Innovation Manager

Turo • San Francisco (CA), Northern (KY)

Hybrid
USD 128,000 - 160,000
Equity
Benefits
Senior Software Engineer, Frontend, Design Systems
Senior Software Engineer, Frontend, Design Systems

Turo • San Francisco (CA), Northern (KY)

Hybrid
USD 156,000 - 195,000
Senior Manager, Procure-to-Pay Operations
Senior Manager, Procure-to-Pay Operations

Turo Inc • San Francisco (CA)

On-site
USD 152,000 - 190,000
Medical, dental, and vision insurance
Retirement employer match
Paid time off
+1
Senior Software Engineer, Android
Senior Software Engineer, Android

Turo • San Francisco (CA)

Hybrid
USD 156,000 - 195,000
Equity
Medical, dental, vision insurance
Retirement match
+1
Director, Tax
Director, Tax

Turo, Inc. • San Francisco (CA), Northern (KY)

On-site
USD 200,000 - 250,000
Competitive salary
Equity
Employer-paid medical/dental/vision
+7