2 часа назад
Paranoids Senior Security GRC Analyst (AI)
128 250 - 266 875$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Paranoids Senior Security GRC Analyst (AI) (Cybersecurity/GRC): Evaluating and documenting security risks, managing exception lifecycles, and developing policies and standards across Yahoo properties with an accent on executive risk communication, cloud security, and AI-assisted governance. Focus on conducting comprehensive assessments, translating technical risks for business leaders, and automating repetitive GRC workflows while maintaining sound AI risk judgment.
Location: United States of America. Flexible hybrid work is available; occasional in-person events or team sessions may be required, while regular office attendance depends on the specific role.
Compensation: $128,250–$266,875 per year, with potential discretionary annual bonus or commissions.
Company
operates a portfolio of consumer internet and advertising products serving hundreds of millions of people globally.
What you will do
- Evaluate and document security risks for executive review, including business impact and treatment options.
- Manage the full lifecycle of security risk exceptions, from intake and assessment through approval, documentation, and reassessment.
- Conduct property-level and initiative-level assessments against security policies, industry frameworks, and modern architecture patterns.
- Draft, revise, and maintain security policies and standards for engineering and product teams.
- Partner with business, engineering, and security stakeholders to build alignment and translate technical risks into actionable business decisions.
- Implement AI-assisted workflows and automation to streamline GRC, exception, and policy reviews.
Requirements
- 5+ years of experience in security governance, risk management, compliance, or a related information security discipline in modern technology environments.
- Experience conducting comprehensive security risk assessments and presenting actionable findings to senior leadership and technical teams.
- Strong written and verbal communication skills, including the ability to prepare executive-ready risk memos.
- Working knowledge of NIST CSF, ISO 27001, FAIR, and their application to cloud infrastructure, web applications, and identity systems.
- Experience developing or managing security policies, standards, exception programs, or risk acceptance governance.
- Experience with generative AI tools and the ability to evaluate AI-generated outputs, protect confidential data, and apply appropriate risk governance.
Nice to have
- Experience in a large-scale consumer technology or cloud enterprise security organization.
- Experience with ServiceNow GRC, Archer, Jira, or other GRC and risk workflow platforms.
- Familiarity with AI/ML security governance and emerging risk domains.
- CRISC, CISSP, CISA, or CISM certification.
Culture & Benefits
- Flexible hybrid work with advance notice for occasional in-person events or team sessions.
- Healthcare coverage and a 401(k) plan.
- Backup childcare and education stipends.
- Inclusive workplace supported by employee resource groups and accessibility accommodations.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Principal, GRC Cyber Risk Management (Cybersecurity)
108 965 - 185 155$
4 дня назад
Senior Security Analyst (GRC)
115 000 - 145 000$
2 дня назад
Sr. GRC Analyst
105 000 - 135 000$
6 дней назад
Cyber Security Analyst (GRC)
3 дня назад
Senior Security Technical Governance Program Manager
176 400 - 206 168$
4 дня назад
Senior GRC Analyst (FinTech)
114 000 - 163 000$