GRC Analyst responsible for authoring security policies, managing company-wide security awareness training programs, establishing AI governance frameworks, conducting risk assessments on AI tools and models, and ensuring compliance with frameworks like SOC 2 and PCI-DSS. Requires 3+ years in information security GRC or compliance plus a Bachelor's degree.
100k – 135k/yr
On-site3+ YOESecurity Engineering
About the role
What you'll do
Author, update, and enforce corporate security policies to guarantee cross-departmental compliance
Deploy and manage required information security training campaigns as the platform owner
Transform static policies into interactive modules with comprehension quizzes for mandatory sign-offs
Establish and enforce an internal AI governance framework with Data, Legal, and Tech teams
Conduct structured risk assessments on emerging tools and internal AI models to maintain behavioral guardrails
Report training metrics, policy exceptions, and risk postures directly to senior management
Review vendor security profiles and software pipelines to mitigate security risk
What we're looking for
3+ years of experience in information security GRC, cybersecurity training, or technology compliance
Proven track record of managing required security awareness programs and driving cross-functional accountability
Experience with modern training orchestration platforms and understanding of AI and machine learning data security
Working knowledge of standard industry frameworks, specifically SOC 2 and PCI-DSS
Communication skills with the ability to explain complex regulatory needs to non-technical employees
Bachelor’s degree in Cybersecurity, Information Systems, or an equivalent technical discipline
Nice-to-haves
GRC certifications such as CISA or CRISC
Compensation
Anticipated base salary: $100,000 - $135,000 USD annually
Total compensation package may also include healthcare benefits, 401(k) plan, disability coverage, life insurance, stock options, bonus plans and more.
Application Security Engineer partnering with engineering teams to embed security into the SDLC, triage SAST/SCA findings, provide remediation guidance on OWASP issues, maintain security docs/playbooks, support governance/audits, and integrate GenAI tools while building AI governance guardrails.
100k – 140k/yrRemoteSecurity Engineering
Security Engineer, Application Security
Trail of BitsUnited States
Conduct low-level code security assessments, architecture reviews, and threat modeling for client applications. Build custom security tools bridging vulnerability research and application security. Requires manual code review, binary analysis, and programming proficiency in multiple languages.
100k – 200k/yrRemote5+ YOESecurity Engineering
Compliance Analyst
HarveySan Francisco, CA
This Compliance Analyst role at Harvey involves owning and maintaining compliance documentation, coordinating evidence collection, and supporting third-party assessments. The role requires hands-on compliance work, close collaboration with Engineering and Security teams, and a detail-oriented approach to ensure program health and continuous monitoring.
99k – 149k/yrHybrid3+ YOESecurity Engineering
Security Engineer
ChainguardUnited States
Support engineers in Identity and Access Management, AI, and Cloud security at Chainguard. Ideal for those with strong IT admin or software development foundations seeking to grow into security roles, with hands-on experience in at least one focus area.
105k – 123k/yrRemoteSecurity Engineering
Product Security Engineer, Server
MongoDBNew York, NY +1
Strengthen MongoDB’s server products through product security assessments, threat modeling, vulnerability research, and security controls. The role requires application or product security experience, C++ expertise with low-level codebases, scripting ability, and strong cross-team communication.