Назад
Company hidden
5 дней назад

Staff Security Analyst - GRC

160 000 - 190 000$
Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Security Analyst - GRC (Cybersecurity/Compliance): Building and operating commercial security and compliance programs with an accent on GRC engineering, control automation, customer trust, and frameworks including SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA. Focus on designing continuous compliance checks, supporting FedRAMP and other federal initiatives, managing vendor and supply-chain risk, and advising engineering and business stakeholders.

Location: Remote within the U.S. or hybrid from one of hirify.global's U.S. offices

Salary: $160,000–$190,000 USD annually

Company

hirify.global is an AI software delivery platform company that applies automation and governance across the software delivery lifecycle.

What you will do

  • Design, implement, and continuously monitor commercial compliance controls for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA.
  • Build GRC engineering and automation solutions, including automated control testing, continuous compliance checks in CI/CD, and streamlined reporting.
  • Support federal compliance initiatives such as FedRAMP Moderate+, CMMC, DoD IL, and FedRAMP 20x.
  • Advise engineering, product, and business teams on security and privacy by design.
  • Support customer trust activities, including contract reviews, security questionnaires, and maintenance of the customer trust portal.
  • Manage relationships with suppliers, auditors, assessors, and enterprise prospects while tracking compliance, vendor, and supply-chain risks.

Requirements

  • 8–10 years of relevant experience in security, compliance, and GRC program management.
  • Extensive experience with commercial compliance frameworks and certifications, including ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA.
  • Experience with GRC tools and building security or compliance automation in a cloud-native environment using AWS, GCP, or Azure.
  • Working knowledge of federal compliance frameworks such as NIST 800-53, FedRAMP, and CMMC.
  • Strong cybersecurity knowledge, technical proficiency with enterprise SaaS applications and infrastructure, and effective communication with technical and non-technical stakeholders.
  • Must be based in the U.S. for remote work, or able to work hybrid from a U.S. office.

Nice to have

  • Experience building, delivering, or managing FedRAMP-compliant services or achieving an authorization to operate.
  • Familiarity with Platform One, Iron Bank, CMMC, DoD IL, AWS or GCP configuration practices, Kubernetes, SBOMs, SLSA, or DLP.
  • Relevant certifications such as ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP credentials.
  • Experience assessing or using AI in secure environments.
  • Interest in automating repetitive work and sharing knowledge with junior colleagues.

Culture & Benefits

  • Flexible work schedule and flexible time off.
  • Comprehensive healthcare benefits, including a Flexible Spending Account and Employee Assistance Program.
  • Parental leave and monthly internet reimbursement.
  • Monthly, quarterly, and annual social and team-building events.
  • Compensation may also include equity and additional benefits.

Hiring process

  • Interviews are generally conducted via Zoom video conference unless another accommodation is requested.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →