Staff Security Analyst - GRC

Harness

United States

Hybrid

USD 160,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive salary
Comprehensive healthcare benefits
FSA
Flexible work schedule
Employee Assistance Program (EAP)
Flexible Time Off and Parental Leave
Team events
Internet reimbursement

Job summary

Harness is seeking a Staff Security Analyst to join the GRC team and help advance security and compliance efforts across the organization. You will work with engineering and product teams to maintain velocity while enforcing robust controls.

The role emphasizes commercial and federal compliance (SOC 1/2, ISO 27001, HIPAA, FedRAMP, NIST 800-53) and requires strong automation and governance capabilities. Remote US or hybrid office options are supported.

Qualifications

  • Minimum of 8-10 years of relevant industry experience in security, compliance, and GRC program management.
  • Extensive exposure to commercial industry regulations, frameworks, and compliance certifications (ISO 27001, SOC 1, SOC 2, PCI-DSS, HIPAA).
  • GRC tools experience and automation for security and compliance controls in a cloud-native environment (AWS, GCP, or Azure).
  • Familiarity with Federal compliance frameworks (e.g., NIST 800-53, FedRAMP, CMMC) and expanding programs.
  • Strong cybersecurity acumen and proficiency with enterprise SaaS apps and infrastructure.
  • Excellent project management and organizational skills; ability to build new programs from scratch.
  • Clear, concise communication with technical and non-technical stakeholders.
  • Comfort navigating ambiguity and driving clarity in fast-paced environments.

Responsibilities

  • Commercial Compliance Management: Design, implement, and monitor commercial compliance controls with SOC 1/2, ISO 27001, PCI-DSS, HIPAA.
  • GRC Engineering & Automation: Develop automation to scale compliance tasks and CI/CD checks.
  • Federal Compliance Support: Contribute to Federal compliance initiatives (FedRAMP, CMMC, DoD IL).
  • Customer Trust & Advisory: Review contracts, answer security questionnaires, maintain trust portal.
  • Cross-Functional Collaboration: Advise security/privacy by design for engineering, product, and business teams.
  • Stakeholder Engagement: Manage relationships with auditors, suppliers, assessors, and enterprise prospects.
  • Risk Management: Identify, track, and mitigate compliance risks; monitor supply chain security.
  • Evangelism: Communicate Harness security capabilities to enterprise customers and auditors.

Skills

GRC tools
Automation scripting
Security certifications
Cloud security
FedRAMP/CMMC

Job description

Harness is the AI Software Delivery Platform company, led by technologist and entrepreneur Jyoti Bansal (founder of AppDynamics, acquired by Cisco for $3.7B). Harness has raised approximately $570M in funding and is valued at $5.5B, backed by leading investors including Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, Citi Ventures, and more. As AI accelerates code creation, the real bottleneck has shifted to everything after the code – testing, deployments, application security, reliability, compliance, and cost optimization. Harness brings AI and automation to this “outer loop,” helping teams ship software faster while maintaining security and governance throughout the entire software delivery lifecycle.

Powered by Harness AI and the Software Delivery Knowledge Graph, the Harness Platform applies deep context and intelligent automation across the software delivery lifecycle with governance and policy-driven controls embedded throughout the platform.

Over the past year, Harness powered over 185M deployments, 82M builds, 18T flag evaluations, 8M security scans, 9.1B optimized tests, 3T protected API calls, and helped manage $2.8B in cloud spend — enabling customers like United Airlines, Morningstar, and Choice Hotels to accelerate releases by up to 75%, reduce cloud costs by up to 60%, and achieve 10x DevOps efficiency.

With a global team across 26 offices and 27 countries, Harness is shaping the future of AI software delivery — and we’re looking for exceptional talent to help us move even faster.

Position Summary

A Staff Security Analyst will be a critical member of the GRC team working within the Information Security organization and across the business to advise, build, and operate security and compliance programs at scale. Utilizing in-depth expertise across multiple disciplines, you will be responsible for executing various components of Harness’ security posture and overseeing end-to-end solutions to complex compliance problems.

As a Staff Security Analyst, you will lead security efforts to acquire and maintain crucial compliance certifications across Commercial sectors while assisting with Federal initiatives. You will design solutions that enable Harness’ security goals and collaborate directly with business and engineering teams to preserve velocity while ensuring top-tier security. This role requires a strong core in Commercial Compliance mastery (SOC 2, SOC 1, ISO 27k, HIPAA, PCI), Customer Trust experience, and hands‑on GRC Engineering and Automation capabilities, complemented by familiarity with Federal Compliance (FedRAMP, NIST 800-53).

About the role
  • Commercial Compliance Management: Design, implement, and continuously monitor commercial compliance controls, collaborating with engineering teams to ensure environments are properly scoped and secured for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA.
  • GRC Engineering & Automation: Develop and implement automation solutions to scale compliance tasks, automate control testing, integrate continuous compliance checks into the CI/CD pipeline, and streamline reporting.
  • Federal Compliance Support: Contribute to Federal compliance initiatives and frameworks (such as FedRAMP Moderate+, CMMC, DoD IL, and FedRAMP 20x) as Harness expands its public sector footprint.
  • Customer Trust & Advisory: Support customer trust initiatives by reviewing contracts for security and privacy requirements, completing detailed customer security questionnaires, and maintaining the customer trust portal.
  • Cross-Functional Collaboration: Contribute precise and actionable guidance to ensure security and privacy by design for engineering, product, and business initiatives.
  • Stakeholder Engagement: Manage relationships and facilitate engagement with external suppliers, auditors, assessors, and enterprise prospects.
  • Risk Management: Identify, track, and mitigate risks related to compliance projects, continuously monitor supply chain security, and manage vendor risk.
  • Evangelism: Articulate Harness’s security capabilities and controls clearly to enterprise customers and regulatory auditors
About you
  • You have a minimum of 8-10 years of relevant industry experience in security, compliance, and GRC program management.
  • Extensive exposure to commercial industry regulations, frameworks, and compliance certifications (ISO 27001, SOC 1, SOC 2, PCI-DSS, HIPAA).
  • Previous experience with GRC tools and a demonstrated ability to build automation for security and compliance controls in a cloud-native environment (AWS, GCP, or Azure).
  • Working knowledge or exposure to Federal compliance frameworks (e.g., NIST 800-53, FedRAMP, CMMC) and are interested in expanding these programs.
  • You possess strong cybersecurity acumen and solid technical proficiency with enterprise SaaS applications and infrastructure.
  • Excellent project management and organizational skills, with the ability to handle multiple priorities and build new programs from scratch.
  • Clear, concise communication skills, both written and verbal, and can effectively partner with technical engineering teams as well as non-technical stakeholders.
  • You are comfortable navigating ambiguity and driving clarity in complex, fast-paced situations.
Bonus Points!
  • You have hands‑on experience building, delivering, or managing a FedRAMP‑compliant service offering (FedRAMP Moderate+) or achieving an ATO.
  • Familiarity with specialized defense/federal environments like Platform One, Iron Bank, CMMC, or DoD IL.
  • You are familiar with what is going on under the hood of the AWS or GCP console and can speak to best practices for configuration and management.
  • You hold relevant security or technical certifications (ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP‑specific credentials).
  • Previous experience assessing and utilizing AI in a secure environment.
  • You have exposure to or experience with Kubernetes, SBOMs, SLSA, and/or DLP.
  • You like to “automate the boring stuff” and are eager to share your knowledge with junior colleagues
Work Location
  • Remote within the U.S or Hybrid from one of our offices.
What you will have at Harness
  • Competitive salary
  • Comprehensive healthcare benefits
  • Flexible Spending Account (FSA)
  • Flexible work schedule
  • Employee Assistance Program (EAP)
  • Flexible Time Off and Parental Leave
  • Monthly, quarterly, and annual social and team building events
  • Monthly internet reimbursement

The anticipated base salary range for this position is between $160,000 and $190,000annually. Salary is determined by a combination of factors including location, level, relevant experience, and skills. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. The compensation package for this position may also include equity, and benefits. More details about our company benefits can be found at the following link: https://www.harness.io/company/careers.

Pay transparency

$160,000—$190,000 USD

Harness in the news:
  • Accelerating Our Mission to Bring AI to Everything After Code
  • Goldman Sachs leads investment in software delivery startup Harness at $5.5 billion valuation
  • How Harness runs 16 “startups within a startup” at scale | Jyoti Bansal
  • Harness Research Shows AI Visibility Crisis Fueling Security Nightmare
  • Harness has been named to the Inc. Power Partner list for software delivery success

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.

At Harness, we care about your privacy and are committed to protecting your personal data. For additional information on this topic, you can visit our privacy Portal: https://harness-privacy.relyance.ai/

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Analyst - GRC Harness · Full-time · Remote $160,000–190,000 3 hours ago
Staff Security Analyst - GRC Harness · Full-time · Remote $160,000–190,000 3 hours ago

Emploive • Northern (KY)

Hybrid
USD 160,000 - 190,000
Flexible Spending Account (FSA)
Employee Assistance Program (EAP)
Flexible Time Off
+2
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Split Software • United States

Hybrid
USD 150,000 - 164,000
Competitive salary
Healthcare benefits
Flexible Spending Account
+3
Senior IT Systems Administrator I
Senior IT Systems Administrator I

Mosaic.tech • Mountain View (CA)

Hybrid
USD 80,000 - 110,000
Healthcare benefits
FSA
Flexible schedule
+4
Senior IT Systems Administrator I
Senior IT Systems Administrator I

Split Software • Mountain View (CA)

Hybrid
USD 115,000 - 130,000
Competitive salary
Healthcare benefits
Flexible Spending Account (FSA)
+4
Senior IT Systems Administrator I
Senior IT Systems Administrator I

Harness • Mountain View (CA)

Hybrid
USD 100,000 - 120,000
Competitive salary
Healthcare benefits
FSA
+4
Senior Technical Content Strategist
Senior Technical Content Strategist

Mosaic.tech • San Francisco (CA)

Hybrid
USD 150,000 - 165,000
Competitive salary
Comprehensive healthcare benefits
Flexible Spending Account (FSA)
+5
Senior Technical Content Strategist
Senior Technical Content Strategist

B Capital • San Francisco (CA)

Hybrid
USD 150,000 - 165,000
Competitive salary
Comprehensive healthcare benefits
Flexible Spending Account (FSA)
+5
Senior Technical Content Strategist
Senior Technical Content Strategist

Split Software • San Francisco (CA)

Hybrid
USD 150,000 - 165,000
Competitive salary
Comprehensive healthcare benefits
Flexible Spending Account (FSA)
+5
Customer Architect (Forward Deployed Engineer)
Customer Architect (Forward Deployed Engineer)

Mosaic.tech • United States

On-site
USD 160,000 - 180,000
Healthcare benefits
Flexible Spending Account
Flexible work schedule
+4
Senior Technical Content Strategist
Senior Technical Content Strategist

Harness • San Francisco (CA)

Hybrid
USD 150,000 - 165,000
Competitive salary
Healthcare benefits
Flexible Spending Account (FSA)
+5