Staff Security Analyst - GRC

Jobgether

United States

Hybrid

USD 150,000 - 164,000

Full time

12 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote work within the United States
Hybrid option with designated offices

Job summary

Jobgether in the United States is seeking a Staff Security Analyst - GRC to lead security and compliance programs at scale. You will drive frameworks including ISO 27001, SOC 1/2, PCI-DSS, and HIPAA, balancing regulatory needs with product velocity in a cloud-native environment.

This senior role combines hands-on engineering with automation and risk management, partnering across engineering, product, and auditors.

Qualifications

  • 8-10+ years of experience in security, compliance, GRC, or security program management.
  • Extensive experience with ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA.
  • Experience building automation for security and compliance in cloud-native environments such as AWS, GCP, or Azure.

Responsibilities

  • Design and implement security controls across SOC 1/2, ISO 27001, PCI-DSS, and HIPAA.
  • Develop GRC automation to scale testing and CI/CD integration.
  • Collaborate with engineering, product, and auditors to manage vendor risk and regulatory requirements.
  • Communicate security capabilities to enterprise customers and regulatory bodies.

Skills

GRC leadership
Automation & CI/CD
Risk management
Communication skills
Cloud security

Education

Bachelor's degree in Information Security or related field

Tools

GRC tools
CI/CD integration
FedRAMP/DoD tooling

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Staff Security Analyst - GRC based in United States.

This is a senior-level role within an Information Security organization, focused on building and operating security and compliance programs at scale. You will lead commercial compliance initiatives across frameworks including SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA. The role combines GRC expertise with hands-on engineering and automation to make compliance processes more efficient and scalable. You will also contribute to federal compliance initiatives while helping expand public‑sector security capabilities. Working across engineering, product, business, customers, auditors, and external suppliers, you’ll provide practical guidance that balances security requirements with business velocity. This position offers significant ownership in a fast-paced, cloud-native environment where automation, technical depth, and clear communication are highly valued.

Accountabilities
  • Design, implement, and continuously monitor commercial security and compliance controls across environments supporting SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA requirements.
  • Partner with engineering teams to ensure systems and environments are appropriately scoped, secured, and aligned with applicable compliance obligations.
  • Develop and implement GRC engineering and automation solutions that scale compliance activities, automate control testing, and integrate continuous compliance checks into CI/CD pipelines.
  • Streamline compliance reporting and improve the efficiency and reliability of security and compliance processes through automation.
  • Support federal compliance initiatives involving frameworks and programs such as FedRAMP Moderate+, CMMC, DoD IL, FedRAMP 20x, and NIST 800-53.
  • Support customer trust activities by reviewing contracts for security and privacy requirements, completing detailed security questionnaires, and maintaining the customer trust portal.
  • Provide precise, actionable security and privacy guidance to engineering, product, and business teams, helping incorporate security and privacy by design.
  • Build and maintain effective relationships with external suppliers, auditors, assessors, and enterprise prospects.
  • Identify, track, and mitigate risks associated with compliance programs and projects while continuously monitoring supply chain security and vendor risk.
  • Clearly communicate security capabilities, controls, and compliance practices to enterprise customers and regulatory auditors.
  • Build new programs and initiatives from the ground up while managing multiple priorities in a complex, fast-moving environment.
  • Share knowledge and help junior colleagues develop their understanding of security, compliance, and automation practices.
Requirements
  • 8-10+ years of relevant industry experience in security, compliance, GRC, or security program management.
  • Extensive experience with commercial security frameworks, regulations, and certifications, including ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA.
  • Experience working with GRC tools and building automation for security and compliance controls in cloud-native environments such as AWS, GCP, or Azure.
  • Working knowledge of or exposure to federal compliance frameworks including NIST 800-53, FedRAMP, and CMMC, with an interest in expanding federal compliance programs.
  • Strong cybersecurity knowledge and technical proficiency with enterprise SaaS applications and cloud infrastructure.
  • Strong project management and organizational skills, with the ability to manage multiple priorities and establish new programs.
  • Excellent written and verbal communication skills, with the ability to work effectively with both technical engineering teams and non-technical stakeholders.
  • Ability to navigate ambiguity, create clarity, and make sound decisions in complex and rapidly changing situations.
  • Hands‑on experience building, delivering, or managing a FedRAMP-compliant service offering or achieving an Authority to Operate (ATO) is a plus.
  • Familiarity with federal and defense environments such as Platform One, Iron Bank, CMMC, or DoD IL is a plus.
  • Understanding of AWS or GCP environments and cloud configuration and management best practices is a plus.
  • Relevant certifications such as ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials are a plus.
  • Experience assessing or applying AI in secure environments is a plus.
  • Exposure to Kubernetes, SBOMs, SLSA, and/or DLP is a plus.
  • A strong interest in automation and a willingness to share knowledge with junior team members are valued.
Benefits
  • $150,000–$164,000 annual base salary, with compensation determined by location, level, relevant experience, and skills.
  • Potential equity as part of the overall compensation package.
  • Comprehensive healthcare benefits.
  • Flexible Spending Account (FSA).
  • Flexible work schedule.
  • Employee Assistance Program (EAP).
  • Flexible Time Off and parental leave.
  • Monthly internet reimbursement.
  • Monthly, quarterly, and annual social and team-building events.
  • Remote work within the United States, with a hybrid option available from designated offices.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
GRC Analyst
GRC Analyst

Fireworks AI • San Mateo (CA)

On-site
USD 110,000 - 150,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000
Director, Governance, Risk & Compliance
Director, Governance, Risk & Compliance

Anomali • Redwood City (CA)

Hybrid
USD 180,000 - 230,000
Staff Security Analyst
Staff Security Analyst

Navan • Palo Alto (CA)

On-site
USD 131,000 - 291,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Global Security Governance, Risk & Compliance Manager (Remote)
Global Security Governance, Risk & Compliance Manager (Remote)

Barnes Aerospace • United States

Remote
USD 140,000 - 190,000