Senior GRC Analyst leading day-to-day cyber, AI, and technology risk assessments, risk register maintenance, and quantitative analysis (FAIR) at WHOOP. Requires 6+ years in cybersecurity/risk management, framework expertise (NIST, ISO), and ability to translate technical risks for executives.
Salary not listed
On-site6+ YOESecurity Engineering
About the role
Responsibilities
Lead cyber, AI, and technology risk assessments across systems, cloud environments, business processes, and major initiatives, evaluating threats, vulnerabilities, control effectiveness, and residual risk.
Maintain and operate the enterprise cyber risk register, including drafting risk statements, tracking mitigation plans, and supporting governance and reporting processes.
Translate technical findings, architectural concerns, and control gaps into clear business risk scenarios that support prioritization and decision-making.
Support and help mature quantitative cyber risk analysis approaches such as FAIR to improve how risk is measured and communicated.
Prepare materials and analysis to support the Cyber Risk Committee and executive risk reporting.
Partner with Security Architecture to assess risk in system designs, cloud architecture, identity models, data flows, and platform changes.
Collaborate with Security Engineering, Product Security, Legal, IT, and business teams to evaluate new initiatives, technology changes, artificial intelligence use cases, and third-party integrations through a risk lens.
Conduct risk assessments for emerging technologies including artificial intelligence and machine learning systems, evaluating data usage, model behavior, external dependencies, and security implications.
Develop dashboards and reporting that provide leadership with visibility into key cybersecurity risks and trends.
Contribute to the continued development of cyber risk management processes.
Qualifications
6+ years of experience in cybersecurity or enterprise risk management, information security, or a related field.
Demonstrated experience conducting structured cybersecurity or IT risk assessments.
Experience maintaining risk registers and tracking risk mitigation or treatment activities.
Deep understanding of security frameworks such as NIST CSF, ISO 27001, or PCI DSS, and familiarity with regulatory environments such as GDPR, HIPAA or other privacy and data protection requirements.
Ability to translate technical findings into clear business risk for non-technical stakeholders.
Strong written and verbal communication skills with experience presenting findings to cross-functional teams.
Experience assessing risks related to artificial intelligence, machine learning systems, or emerging technologies, including familiarity with emerging AI governance frameworks such as NIST AI RMF, ISO/IEC 42001, or similar standards.
Professional certifications such as CRISC, CISSP, CISA, or CGRC are a plus.
Skills
CybersecurityRisk Assessmentrisk registernist csfISO 27001pci dssGDPRHIPAAfairnist ai rmfiso/iec 42001crisccisspcisacgrc
Senior engineer on Trust and Safety team building and maintaining abuse prevention systems, anomaly detection, and agentic AI tools for the GitLab SaaS platform. Requires strong Ruby/Rails software engineering background; security experience preferred but not required.
139k – 196k/yr
Remote5+ YOESecurity Engineering
Senior Detection Engineer
FluidstackNew York, NY +3
Own end-to-end detection engineering program including threat modeling, detection-as-code pipelines, threat hunting, SIEM/EDR tuning, alert triage and incident response for rapidly scaling AI compute infrastructure. Requires 5+ years in detection engineering or threat hunting with deep SIEM/EDR and scripting experience.
176k – 218k/yr
On-site5+ YOESecurity Engineering
Senior Security Engineer, Bug Bounty
MozillaUnited States
Own and scale Mozilla's web bug bounty program. Triage and validate reports from HackerOne/Bugzilla, drive vulnerability remediation with engineering teams, perform code reviews, and collaborate with SIRT on incidents. Requires 3+ years security engineering experience and bug bounty or bug hunting background.
116k – 183k/yr
Remote3+ YOESecurity Engineering
Senior Security Engineer, Bug Bounty
MozillaUnited States
Own and scale Mozilla's web bug bounty program as the primary interface with external researchers. Lead triage, validation, remediation of reports, collaborate with SIRT on incidents, perform code reviews, and drive secure development improvements. Requires 3+ years security engineering experience and bug bounty or bug hunting background.
Salary not listed
Remote3+ YOESecurity Engineering
Regional Site Security Lead, Deployment & Ops
FluidstackAustin, TX +1
Lead physical security operations and teams across multiple data center sites in a region. Own end-to-end posture, standardize procedures, support customer audits, and integrate security into facility growth for frontier AI compute infrastructure.