
Staff Security Analyst β GRC
Posted 14 hours ago

Posted 14 hours ago
This is a fully remote position, open to applicants in United States.
β’ Provide advice, construct, and manage security and compliance programs at scale within the GRC team and Information Security organization.
β’ Oversee security initiatives to obtain and uphold commercial compliance certifications while supporting Federal projects.
β’ Create solutions that align with Harness security objectives and collaborate with business and engineering teams.
β’ Develop, implement, and consistently monitor compliance controls for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA.
β’ Establish automation to enhance compliance processes, automate control testing, incorporate continuous compliance checks into CI/CD pipelines, and simplify reporting.
β’ Contribute to Federal compliance projects related to FedRAMP Moderate+, CMMC, DoD IL, and FedRAMP 20x.
β’ Analyze customer contracts for security and privacy obligations.
β’ Complete security questionnaires for customers and manage the customer trust portal.
β’ Offer guidance on security and privacy by design across engineering, product, and business projects.
β’ Cultivate relationships with suppliers, auditors, assessors, and enterprise prospects.
β’ Identify, monitor, and mitigate risks associated with compliance projects.
β’ Oversee supply chain security and manage vendor risks.
β’ Articulate Harness security capabilities and controls to enterprise customers and regulatory auditors.
β’ A minimum of 8β10 years of pertinent industry experience in security, compliance, and GRC program management.
β’ Significant familiarity with commercial industry regulations, frameworks, and compliance certifications, including ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA.
β’ Experience utilizing GRC tools.
β’ Capability to develop automation for security and compliance controls in a cloud-native setting using AWS, GCP, or Azure.
β’ Working knowledge or exposure to Federal compliance frameworks such as NIST 800-53, FedRAMP, and CMMC.
β’ Strong understanding of cybersecurity principles.
β’ Technical skills related to enterprise SaaS applications and infrastructure.
β’ Proficient project management and organizational abilities.
β’ Excellent written and verbal communication skills.
β’ Ability to collaborate with technical engineering teams and non-technical stakeholders.
β’ Practical experience in building, delivering, or managing a FedRAMP-compliant service offering or achieving an ATO is advantageous.
β’ Familiarity with Platform One, Iron Bank, CMMC, or DoD IL is a plus.
β’ Relevant security or technical certifications such as ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials are advantageous.
β’ Experience in assessing and utilizing AI in a secure environment is beneficial.
β’ Exposure to Kubernetes, SBOMs, SLSA, and/or DLP is a plus.
β’ Competitive salary.
β’ Comprehensive healthcare benefits.
β’ Flexible Spending Account (FSA).
β’ Flexible work schedule.
β’ Employee Assistance Program (EAP).
β’ Flexible Time Off and Parental Leave.
β’ Monthly, quarterly, and annual social and team-building events.
β’ Monthly internet reimbursement.
β’ Equity may be included in the compensation package.
Veracity Insurance Solutions, LLC
Positivo S+
ShorePoint Inc
General Dynamics Information Technology
Get handpicked remote jobs straight to your inbox weekly.