Skip to content
MetropolisMetropolisLos Angeles, CA

GRC Analyst II

GRC Analyst responsible for authoring security policies, managing company-wide security awareness training programs, establishing AI governance frameworks, conducting risk assessments on AI tools and models, and ensuring compliance with frameworks like SOC 2 and PCI-DSS. Requires 3+ years in information security GRC or compliance plus a Bachelor's degree.

100k – 135k/yr
On-site3+ YOESecurity Engineering

About the role

What you'll do

  • Author, update, and enforce corporate security policies to guarantee cross-departmental compliance
  • Deploy and manage required information security training campaigns as the platform owner
  • Transform static policies into interactive modules with comprehension quizzes for mandatory sign-offs
  • Establish and enforce an internal AI governance framework with Data, Legal, and Tech teams
  • Conduct structured risk assessments on emerging tools and internal AI models to maintain behavioral guardrails
  • Report training metrics, policy exceptions, and risk postures directly to senior management
  • Review vendor security profiles and software pipelines to mitigate security risk

What we're looking for

  • 3+ years of experience in information security GRC, cybersecurity training, or technology compliance
  • Proven track record of managing required security awareness programs and driving cross-functional accountability
  • Experience with modern training orchestration platforms and understanding of AI and machine learning data security
  • Working knowledge of standard industry frameworks, specifically SOC 2 and PCI-DSS
  • Communication skills with the ability to explain complex regulatory needs to non-technical employees
  • Bachelor’s degree in Cybersecurity, Information Systems, or an equivalent technical discipline

Nice-to-haves

  • GRC certifications such as CISA or CRISC

Compensation

  • Anticipated base salary: $100,000 - $135,000 USD annually
  • Total compensation package may also include healthcare benefits, 401(k) plan, disability coverage, life insurance, stock options, bonus plans and more.

Skills

GRCSOC 2pci-dssCybersecurityRisk Assessmentsecurity policiessecurity awareness trainingai governancecisacrisc
Zocdoc

Application Security Engineer

ZocdocUnited States

Application Security Engineer partnering with engineering teams to embed security into the SDLC, triage SAST/SCA findings, provide remediation guidance on OWASP issues, maintain security docs/playbooks, support governance/audits, and integrate GenAI tools while building AI governance guardrails.

100k – 140k/yrRemoteSecurity Engineering
Trail of Bits

Security Engineer, Application Security

Trail of BitsUnited States

Conduct low-level code security assessments, architecture reviews, and threat modeling for client applications. Build custom security tools bridging vulnerability research and application security. Requires manual code review, binary analysis, and programming proficiency in multiple languages.

100k – 200k/yrRemote5+ YOESecurity Engineering
Harvey

Compliance Analyst

HarveySan Francisco, CA

This Compliance Analyst role at Harvey involves owning and maintaining compliance documentation, coordinating evidence collection, and supporting third-party assessments. The role requires hands-on compliance work, close collaboration with Engineering and Security teams, and a detail-oriented approach to ensure program health and continuous monitoring.

99k – 149k/yrHybrid3+ YOESecurity Engineering
Chainguard

Security Engineer

ChainguardUnited States

Support engineers in Identity and Access Management, AI, and Cloud security at Chainguard. Ideal for those with strong IT admin or software development foundations seeking to grow into security roles, with hands-on experience in at least one focus area.

105k – 123k/yrRemoteSecurity Engineering
MongoDB

Product Security Engineer, Server

MongoDBNew York, NY +1

Strengthen MongoDB’s server products through product security assessments, threat modeling, vulnerability research, and security controls. The role requires application or product security experience, C++ expertise with low-level codebases, scripting ability, and strong cross-team communication.

106k – 209k/yrRemote5+ YOESecurity Engineering