Staff Security Analyst - GRC

harnessinc

United States

Remote

USD 150,000 - 164,000

Full time

10 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Monthly internet reimbursement

Job summary

Harness is seeking a Staff-level Security Analyst within the GRC team of the Information Security organization to design, build, and operate compliance programs at scale. This role blends deep technical security expertise with policy mastery, helping engineering and business teams maintain delivery velocity while meeting rigorous certification and audit requirements.

You will drive automation, support FedRAMP/CMMC and other federal frameworks, and review contracts for security requirements while

Qualifications

  • 8–10+ years of relevant industry experience across security, compliance, and GRC program management
  • Strong command of commercial compliance frameworks: SOC 2, SOC 1, ISO 27k, HIPAA, and PCI-DSS
  • Hands-on GRC engineering and automation capabilities, including integrating compliance into CI/CD pipelines
  • Customer trust experience, including security questionnaire completion and contract review
  • Familiarity with federal compliance frameworks such as FedRAMP, CMMC, DoD IL, and NIST 800-53
  • Demonstrated ability to collaborate cross-functionally with engineering, product, and business teams

Responsibilities

  • Design, implement, and continuously monitor commercial compliance controls for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA environments, partnering with engineering teams on scoping and security
  • Build GRC automation solutions, including automated control testing, continuous compliance checks integrated into CI/CD pipelines, and streamlined reporting
  • Support federal compliance initiatives and frameworks such as FedRAMP Moderate+, CMMC, DoD Impact Levels, and FedRAMP 20x as the public sector footprint expands
  • Support customer trust by reviewing contracts for security and privacy requirements, completing detailed customer security questionnaires, and maintaining the customer trust portal
  • Identify, track, and mitigate compliance risks, including supply chain security and vendor risk management
  • Engage with external suppliers, auditors, assessors, and prospects, clearly communicating security capabilities to enterprise customers and regulatory auditors

Skills

GRC program mgmt
CI/CD integration
Automation engineering
Security frameworks
Cross-functional collaboration

Tools

Automation tools

Job description

Role overview

This Staff-level Security Analyst position sits within the Governance, Risk, and Compliance (GRC) team of the Information Security organization, serving as a senior contributor who designs, builds, and operates compliance programs at scale. The role blends deep technical security expertise with policy mastery, helping engineering and business teams maintain delivery velocity while meeting rigorous certification and audit requirements. It spans both commercial and federal regulatory frameworks with a strong emphasis on automation.

Responsibilities
  • Design, implement, and continuously monitor commercial compliance controls for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA environments, partnering with engineering teams on scoping and security
  • Build GRC automation solutions, including automated control testing, continuous compliance checks integrated into CI/CD pipelines, and streamlined reporting
  • Support federal compliance initiatives and frameworks such as FedRAMP Moderate+, CMMC, DoD Impact Levels, and FedRAMP 20x as the public sector footprint expands
  • Support customer trust by reviewing contracts for security and privacy requirements, completing detailed customer security questionnaires, and maintaining the customer trust portal
  • Identify, track, and mitigate compliance risks, including supply chain security and vendor risk management
  • Engage with external suppliers, auditors, assessors, and prospects, clearly communicating security capabilities to enterprise customers and regulatory auditors
Requirements
  • 8-10+ years of relevant industry experience across security, compliance, and GRC program management
  • Strong command of commercial compliance frameworks: SOC 2, SOC 1, ISO 27k, HIPAA, and PCI-DSS
  • Hands-on GRC engineering and automation capabilities, including integrating compliance into CI/CD pipelines
  • Customer trust experience, including security questionnaire completion and contract review
  • Familiarity with federal compliance frameworks such as FedRAMP, CMMC, DoD IL, and NIST 800-53
  • Demonstrated ability to collaborate cross-functionally with engineering, product, and business teams
Nice to have
  • Experience contributing to public sector or federal compliance expansion efforts
  • Ability to translate complex security concepts for diverse audiences, from engineers to enterprise buyers
Benefits and work setup
  • Anticipated base salary range: $150,000–$164,000 USD annually, with the range varying by location, experience, and skills
  • Compensation package may include equity and additional benefits
  • Monthly internet reimbursement
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Analyst
Analyst

Insight Security • Northern (KY)

On-site
USD 68,000 - 95,000
Health, dental, and vision insurance
Fully remote work
Unlimited PTO
+2
Staff GRC Engineer
Staff GRC Engineer

turing • United States

Remote
USD 210,000 - 240,000
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
USD 86,450 - 113,750
Employee-owned
Equal opportunity employer