
Senior Security Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California, +1 more state.
• Implement and uphold compliance with SOC 2, NIST CSF, CIS, NYDFS, GLBA Safeguards, CCPA, and other relevant regulatory standards.
• Assist with internal and external security audits and examinations, encompassing evidence collection and remediation tracking.
• Develop AI-enhanced GRC workflows to expand GRC and security functions.
• Oversee the security risk register, conduct risk assessments, and manage remediation processes.
• Lead security governance and compliance projects while supporting other project management initiatives.
• Oversee security metrics, KPIs, and reporting activities.
• Aid in customer security due diligence processes.
• Review, manage, and supervise security policies to ensure compliance.
• Coordinate the remediation of security and compliance issues among stakeholders.
• Conduct vendor security risk assessments.
• Assist with on-call and operational security tasks, including security monitoring, incident management, general security reviews, security awareness and training, and additional responsibilities.
• Collaborate with the Head of Security GRC, the Security team, Product, Engineering, and cross-functional stakeholders to safeguard systems, cloud infrastructure, products, and data.
• A minimum of 5+ years of experience as a security analyst or security program manager with relevant duties and background.
• A Bachelor's degree in Computer Science, Information Security, Technology, or a related discipline.
• Relevant security certifications aligned with career experience (CompTIA Security+, CC, SSCP or related) or advanced career level (CISSP, CISM, CRISC or equivalent).
• Familiarity with security compliance frameworks and risk assessment methodologies.
• Experience in operational activities including issue management, security reviews, control monitoring, incident management, and reporting.
• Practical experience with AI tools and assisted workflows.
• Knowledge of security and compliance frameworks and requirements, including OWASP, SOC 2, NIST CSF / 800-53, ISO 27001/2, CIS, NYDFS, and CCPA.
• Basic understanding of cloud security and public cloud environments.
• Experience in developing, automating, and scaling security and GRC processes utilizing AI tools and agentic capabilities.
• Proficiency in maintaining a security risk register and managing issue processes.
• Strong organizational and project management abilities.
• Excellent communication and collaboration skills, capable of articulating security concepts to both technical and non-technical audiences.
• Ability to work independently, adapt quickly, and juggle multiple projects and operational tasks.
• Competitive salary with significant equity stake in the company.
• 401k retirement plan.
• Comprehensive medical, dental, and vision insurance benefits.
• Pre-tax commuter benefits for public transportation, rideshare services, and parking expenses.
• Company-wide orientation and opportunities for learning and development.
• Regular review cycles that include 360-degree feedback.
• Quarterly budgets allocated for team and company outings.
• Flexible paid time off policy.
• Sick leave.
• 11 designated company holidays.
• 12 weeks of fully paid parental bonding leave for both birthing and non-birthing parents.
SoftExpert - Software for Excellence
Nasajon Sistemas
SGA TI em Nuvem
AeroVironment
Get handpicked remote jobs straight to your inbox weekly.