Senior Security GRC Analyst — Risk, Policy & AI

Yahoo

United States

Hybrid

USD 128,000 - 267,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Healthcare
401(k)
Education stipends
Backup childcare

Job summary

Yahoo is seeking a Senior Security GRC Analyst to guide exception management, risk assessment, and policy standards across Yahoo properties. You will partner with business, engineering, and security teams to translate complex risks for non-technical stakeholders and drive informed decisions in a fast-moving environment.

We leverage AI for governance scale and deliver actionable risk insights, while ensuring compliance with frameworks like NIST, ISO, and GDPR.

Qualifications

  • 5+ years of experience in security governance, risk management, compliance, or a related information security discipline.
  • Demonstrated experience conducting comprehensive security risk assessments and communicating actionable findings to senior leadership and technical teams.
  • Strong written and verbal communication skills - proven ability to write an executive-ready risk memo, present to leaders, and collaborate effectively with software and infrastructure engineers.
  • Working knowledge of security frameworks and risk methodologies (e.g., NIST CSF, ISO 27001, FAIR) and how they apply to real-world cloud infrastructure, web applications, and identity systems.
  • Proven experience developing or managing security policies, standards, or exception/risk acceptance governance programs.
  • Demonstrated experience using generative AI tools (e.g., Claude, ChatGPT, Gemini, Copilot) to accelerate daily productivity—including drafting documentation, structuring risk analyses, or automating repetitive research workflows.
  • Strong critical evaluation skills with the ability to exercise judgment in when to apply AI tools versus manual review, paired with an understanding of AI data confidentiality and risk governance.
  • Understanding of regulatory and compliance frameworks applicable to global technology organizations (e.g., SOC 2, PCI DSS, GDPR).
  • Track record of continuous process improvement—having established or meaningfully upgraded an assessment program, policy lifecycle, or risk tracking mechanism.

Responsibilities

  • Evaluate and document known security risks for executive review, ensuring risks are described clearly, contextualized for impact, and paired with actionable treatment options.
  • Manage the end-to-end lifecycle of risk exceptions from intake and evaluation through decision, documentation, and periodic reassessment across Yahoo properties.
  • Conduct property-level and initiative-level security risk assessments against Paranoids policies, industry frameworks, and modern architecture patterns.
  • Draft, revise, and maintain security policies and standards that set clear, realistic expectations across engineering and product teams.
  • Partner with stakeholders across the business to socialize new or updated standards, gathering input and building cross-functional alignment before publication.
  • Act as a trusted liaison between business teams, engineering, and security - translating technical security concepts for non-technical stakeholders and ensuring business context informs risk decisions.
  • Identify and implement AI-assisted workflows and automation to eliminate manual GRC tasks, and streamline security exception and policy reviews

Skills

Security governance
Risk management
Compliance
Executive communication
Cloud security
AI governance
Policy development

Tools

ServiceNow GRC
Archer
Jira

Job description

Yahoo is seeking a Senior Security GRC Analyst to guide exception management, risk assessment, and policy standards across Yahoo properties. You will partner with business, engineering, and security teams to translate complex risks for non-technical stakeholders and drive informed decisions in a fast-moving environment.

We leverage AI for governance scale and deliver actionable risk insights, while ensuring compliance with frameworks like NIST, ISO, and GDPR.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security GRC Analyst - AI-Driven Risk & Policy
Senior Security GRC Analyst - AI-Driven Risk & Policy

Yahoo Inc. • Northern (KY)

Hybrid
USD 128,000 - 267,000
Paranoids Senior Security GRC Analyst
Paranoids Senior Security GRC Analyst

Yahoo • United States

Hybrid
USD 128,000 - 267,000
Healthcare
401(k)
Education stipends
+1
Paranoids Senior Security GRC Analyst
Paranoids Senior Security GRC Analyst

Yahoo Holdings Inc. • Mountain View (CA)

On-site
USD 128,000 - 267,000
Flexible hybrid work options
Healthcare benefits
401k match
+2
Paranoids Senior Security GRC Analyst
Paranoids Senior Security GRC Analyst

Yahoo Inc. • Northern (KY)

On-site
USD 128,000 - 267,000
Senior GRC Analyst: AI Security & Compliance Leader
Senior GRC Analyst: AI Security & Compliance Leader

Shift Technology • New York (NY)

Hybrid
USD 120,000 - 150,000
Remote and hybrid options
Learning & development opportunities
Generous PTO & holidays
+2
Senior Security Risk & GRC Analyst
Senior Security Risk & GRC Analyst

APCO Holdings, LLC • Ponte Vedra Beach (FL)

On-site
USD 115,000 - 165,000
Competitive compensation
Medical, dental, and vision benefits
401(k) with company match
+2
Senior Security GRC Leader: SOC 2, AI Governance | Hybrid + Equity
Senior Security GRC Leader: SOC 2, AI Governance | Hybrid + Equity

CarGurus • Boston (MA)

Hybrid
USD 135,000 - 168,000
Daily free lunch
Car discount
Wellness programs
GRC Analyst I: AI-Driven Security & Compliance
GRC Analyst I: AI-Driven Security & Compliance

Embedded Shishya • United States

Remote
USD 50,000 - 73,000
Senior AI-Driven Risk & GRC Lead
Senior AI-Driven Risk & GRC Lead

GRC Careers, LLC • United States

Remote
USD 130,000 - 190,000
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000