# Security GRC Analyst

**Company:** [Pinterest](https://hotfix.jobs/companies/pinterest)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $124k – $255k/yr
**Experience:** 4+ years
**Skills:** SOC 2, Cis Controls, ISO 27001, Nist Csf, Risk Registers, Security Audits, Control Testing, Security Policies, Security Awareness, Identity And Access Management, Vulnerability Management, Endpoint Security, Third-Party Risk, Cissp
**Posted:** 2026-08-31

> The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.

## Job Description

## Responsibilities
- Administer and maintain the security risk register, including risks, remediation activities, owners, and reporting.
- Identify, document, assess, and monitor security risks with Security and business stakeholders.
- Draft, review, update, and manage security policies, standards, and procedures.
- Coordinate evidence collection and follow-up activities for the annual SOC 2 Type 2 audit.
- Track and report security awareness training metrics, exceptions, and follow-up actions.
- Execute security control testing aligned with CIS Controls and document findings and remediation recommendations.
- Conduct and support internal security risk assessments.
- Monitor control effectiveness and improve process maturity, consistency, and evidence quality.
- Prepare dashboards, reports, and leadership presentations covering risk, compliance, audit, and awareness programs.
- Track remediation for control gaps, audit findings, and risk treatment actions.
- Contribute to continuous improvement of the GRC framework and operating processes.

## Requirements
- 4+ years of experience in security governance, risk, compliance, audit, or security assurance.
- Working knowledge of SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar frameworks.
- Experience supporting audits, assessments, or control testing in a technology or SaaS environment.
- Ability to write practical security policies, standards, and process documentation.
- Experience maintaining risk registers and supporting formal risk assessments.
- Strong organizational, cross-functional communication, and stakeholder information-gathering skills.
- Bachelor’s degree in a relevant field such as Computer Information Systems or Cybersecurity, or equivalent experience.

## Nice-to-haves
- Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment.
- Familiarity with security awareness program administration and reporting.
- Experience coordinating control testing mapped to recognized frameworks such as CIS Controls.
- Knowledge of identity and access management, logging and monitoring, vulnerability management, endpoint security, and third-party risk.
- Security+, CISA, CRISC, CISSP, or similar certification.

## Similar jobs

- [System Safety Engineer, Mining/Industrial](https://hotfix.jobs/jobs/644fb8c1-f6aa-4519-96c9-d8abfb23da9f) - Applied Intuition - Sunnyvale, CA - $125k – $225k/yr
- [Protective Intelligence & Threat Analyst](https://hotfix.jobs/jobs/19e4e635-ad0e-474f-85ee-147d674f6395) - OpenAI - San Francisco, CA - $126k – $225k/yr
- [Security Engineer](https://hotfix.jobs/jobs/b2d0b5eb-6441-418b-8992-e40ef5db3518) - DataVisor - Mountain View, CA - $120k – $150k/yr
- [Security Engineer, Application Security](https://hotfix.jobs/jobs/4ccb951f-6bd0-4244-8813-fa449cbf8f58) - GameChanger - Remote - $120k – $140k/yr
- [Security Analyst, Third-Party Ecosystem Risk Management](https://hotfix.jobs/jobs/04d279a2-cca0-4b85-9c84-c8fb7b794013) - Plaid - New York, NY - $119k – $176k/yr

**Apply:** https://hotfix.jobs/jobs/e2503f84-7d16-49f3-9f64-65e03e688c69
**Canonical:** https://hotfix.jobs/jobs/e2503f84-7d16-49f3-9f64-65e03e688c69