Synack

Synack

Synack is a premier security testing platform that offers human-powered security solutions for enterprise applications and networks, providing continuous testing and strategic security solutions to stay ahead of threats.

Professional Services
51-250
Founded 2013
$112M raised

Description

  • Automate System Security Plans, including security concepts of operations, risk matrices, control traceability matrices, and security impact analyses.
  • Develop and maintain automated Plans of Action and Milestones (POAMs).
  • Own inventory and risk assessments for AI and agentic systems, aligned with NIST AI RMF and ISO 42001.
  • Build automated security evidence collection and control-drift monitoring.
  • Communicate compliance issues, mitigation activities, reports, and metrics to stakeholders.
  • Codify security controls into infrastructure-as-code guardrails, CNAPP policies, and CI/CD checks.
  • Collaborate with project managers and software engineers to implement security policies, hardening, and DevSecOps practices.
  • Coordinate responses to vendor security assessments and conduct third-party vendor risk assessments.
  • Support automation and responsible AI adoption within Information Security operations.

Requirements

  • 8+ years of experience in IT security strategy, risk management, IT audit, and compliance within a cloud service provider.
  • Experience with Python, Terraform, CI/CD pipelines, and integrating tools with AI.
  • Experience with enterprise GRC tools.
  • Experience with monitoring and alerting tools such as Datadog, Stackdriver, and Azure Sentinel.
  • Experience with SOAR or auto-remediation platforms and SIEM query or detection engineering languages.
  • Experience with Cloud Native Application Protection Platforms (CNAPP).
  • Experience integrating security tools into the software development lifecycle.
  • Familiarity with secrets management and non-human workload identity.
  • Working knowledge of ISO 27000, ISO 42001, OWASP, SOC 2, GDPR, CMMC, FedRAMP, and NIST frameworks.
  • Excellent written and verbal communication skills for technical and non-technical audiences.
  • Must be a United States citizen due to federal contract requirements.

Benefits

  • $150,000–$180,000 salary range across U.S. locations.
  • Potential equity and additional benefits.
  • Benefits package provided by Synack.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security & Technology Risk Analyst

Moniepoint 1K-5K Diversified Financial Services

Moniepoint is seeking a Security & Technology Risk Analyst to assess and manage security and technology risks across its fintech ecosystem, supporting regulatory compliance, operational resilience, and informed executive decision-making.

Network Security
14 hours, 44 minutes ago

Middle Information Security Access Specialist

GR8 Tech 251-1K IT Services

GR8_TECH is hiring an IAM and access management professional to secure and automate employee access across its global B2B iGaming technology organization.

Active Directory AWS Azure
1 day, 15 hours ago

Investigations Analyst

Turing 251-1K Internet Software & Services

Turing is hiring an Investigations Analyst to support its security investigations function by handling fraud and insider-threat cases from initial signal through resolution, protecting the company and its customers.

Python SIEM SQL
1 day, 15 hours ago

Investigations Analyst

Turing 251-1K Internet Software & Services

Turing is hiring an Investigations Analyst to support its security investigations function by resolving fraud and insider-threat cases and protecting the company and its customers.

Python SIEM SQL
1 day, 15 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers