Security GRC Analyst

7 hours, 8 minutes ago
Full-time
Mid Level
Cybersecurity
Pinterest

Pinterest

Pinterest is the world's first visual discovery engine, offering a vast dataset of ideas with over 200 billion recipes, home hacks, and style inspiration. With a mission to inspire everyone to create a life they love, Pinterest empowers its employees t...

Internet Software & Services
5K-10K
Founded 2010

Description

  • Administer the security risk register, including risk owners, remediation activities, updates, and reporting.
  • Identify, document, assess, and monitor security risks with Security and business stakeholders.
  • Draft, review, update, and manage security policies, standards, and procedures.
  • Coordinate evidence collection and follow-up activities for the annual SOC 2 Type 2 audit.
  • Track and report security awareness training metrics, exceptions, and follow-up actions.
  • Execute control testing aligned with CIS Controls and document findings and remediation recommendations.
  • Conduct and support internal security risk assessments.
  • Monitor control effectiveness and improve process maturity, consistency, and evidence quality.
  • Prepare leadership dashboards, reports, and presentations on risk, compliance, audit, and awareness programs.
  • Track remediation for control gaps, audit findings, and risk treatment actions while improving the GRC framework.

Requirements

  • 4+ years of experience in security governance, risk, compliance, audit, or security assurance.
  • Working knowledge of SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar frameworks.
  • Experience supporting audits, assessments, or control testing in a technology or SaaS environment.
  • Ability to write clear, practical security policies, standards, and process documentation.
  • Experience maintaining risk registers and supporting formal risk assessments.
  • Strong organizational skills with the ability to manage multiple workstreams and deadlines.
  • Ability to collaborate with technical and non-technical stakeholders and gather evidence.
  • Strong written and verbal communication skills for clearly summarizing risk and compliance issues.
  • Bachelor’s degree in Computer Information Systems, Cybersecurity, or a related field, or equivalent experience.
  • Preferred: SOC 2 Type 2, security awareness, CIS Controls testing, enterprise security domain, or relevant certification experience such as Security+, CISA, CRISC, or CISSP.

Benefits

  • US base salary range of $123,696–$254,667, plus equity eligibility.
  • Remote-friendly work model with in-office collaboration 1–2 times per quarter.
  • Position can be based anywhere in the United States.
  • Pinterest offers workplace benefits and culture programs; details are provided through its benefits resources.
  • Equal opportunity employer with accommodation support available during the application process.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

GRC Analyst

Coretelligent 251-1K Internet Software & Services

Coretelligent is seeking a GRC Analyst to support client cybersecurity and compliance programs through security awareness initiatives, vendor risk assessments, controls framework maintenance, and governance activities across multiple environments.

Cybersecurity HIPAA
6 hours, 53 minutes ago

Data Governance Analyst

GuidePoint Security 251-1K Internet Software & Services

GuidePoint Security is seeking a Data Governance Analyst to support client engagements involving data security, privacy, regulatory compliance, and responsible AI governance.

Python
2 days, 7 hours ago

SOC L1 Analyst

Lion Hires Recruitment / staffing / talent acquisition

The client is seeking a SOC Analyst to monitor fintech infrastructure, detect and respond to threats, and strengthen security operations protecting sensitive financial data.

AWS Azure Cybersecurity ELK Stack SIEM Splunk
2 days, 7 hours ago

SOC L2 Analyst

Lion Hires Recruitment / staffing / talent acquisition

Join the client’s Information Security team as a SOC L2 Analyst, investigating and resolving advanced threats while strengthening security operations across its fintech ecosystem.

AWS Azure Cybersecurity ELK Stack Splunk
2 days, 7 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers