Synack

Synack

Synack is a premier security testing platform that offers human-powered security solutions for enterprise applications and networks, providing continuous testing and strategic security solutions to stay ahead of threats.

Professional Services
51-250
Founded 2013
$112M raised

Description

  • Automate System Security Plans, including security concepts of operations, risk matrices, control traceability matrices, and security impact analyses.
  • Develop and maintain automated Plans of Action and Milestones (POAMs).
  • Own inventory and risk assessments for AI and agentic systems, aligned with NIST AI RMF and ISO 42001.
  • Build automated security evidence collection and control-drift monitoring.
  • Communicate compliance issues, mitigation activities, reports, and metrics to stakeholders.
  • Codify security controls into infrastructure-as-code guardrails, CNAPP policies, and CI/CD checks.
  • Collaborate with project managers and software engineers to implement security policies, hardening, and DevSecOps practices.
  • Coordinate responses to vendor security assessments and conduct third-party vendor risk assessments.
  • Support automation and responsible AI adoption within Information Security operations.

Requirements

  • 8+ years of experience in IT security strategy, risk management, IT audit, and compliance within a cloud service provider.
  • Experience with Python, Terraform, CI/CD pipelines, and integrating tools with AI.
  • Experience with enterprise GRC tools.
  • Experience with monitoring and alerting tools such as Datadog, Stackdriver, and Azure Sentinel.
  • Experience with SOAR or auto-remediation platforms and SIEM query or detection engineering languages.
  • Experience with Cloud Native Application Protection Platforms (CNAPP).
  • Experience integrating security tools into the software development lifecycle.
  • Familiarity with secrets management and non-human workload identity.
  • Working knowledge of ISO 27000, ISO 42001, OWASP, SOC 2, GDPR, CMMC, FedRAMP, and NIST frameworks.
  • Excellent written and verbal communication skills for technical and non-technical audiences.
  • Must be a United States citizen due to federal contract requirements.

Benefits

  • $150,000–$180,000 salary range across U.S. locations.
  • Potential equity and additional benefits.
  • Benefits package provided by Synack.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Security Analyst (Governance and Trust)

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a US-based Senior Security Analyst, Governance & Trust to build and operate the public-sector security program supporting government customer trust, compliance, and authorization.

GitOps
3 days, 11 hours ago

Vulnerability Mgmt / Scan Operator

Pingwind 51-250 Internet Software & Services

PingWind is seeking a remote Vulnerability Management / Scan Operator to support vulnerability identification, remediation, and federal cybersecurity compliance for a mission-critical Department of Education Federal Student Aid IAM program.

Encryption TLS
3 days, 11 hours ago

Open Source Intelligence Specialist

Binance 5K-10K Capital Markets

Binance is hiring an investigations professional to research corporate entities and individuals, identify financial and compliance risks, and strengthen the blockchain company’s risk framework.

Blockchain Cybersecurity
3 days, 11 hours ago

RMF / CSAM Analyst

Pingwind 51-250 Internet Software & Services

PingWind is seeking a remote RMF/CSAM Analyst to maintain continuous security authorization and compliance for a cloud-based federal IAM solution supporting FSA identity services.

Cybersecurity TLS
4 days, 10 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers