Staff Security Analyst - GRC

Harness
United States
Workplace: RemoteFull timeUSD 150,000 - 164,000 annuallyFunction: CybersecurityExperience: 8-10 yearsSkills: ["Project management","Organizational skills","Communication","Stakeholder management","Risk management"]

Lead GRC and security compliance programs at scale, partnering with engineering and business teams to maintain commercial and federal security requirements. Own control design and continuous monitoring for SOC 1/2, ISO 27001, PCI-DSS, and HIPAA, while building automation to integrate compliance checks into CI/CD. Support Federal compliance initiatives, manage customer trust activities, and guide risk and vendor/supplier compliance for enterprise prospects.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Harness
Harness
1 day ago

Staff Security Analyst - GRC

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 13 hours agoStatus: Live

Job Summary

Lead GRC and security compliance programs at scale, partnering with engineering and business teams to maintain commercial and federal security requirements. Own control design and continuous monitoring for SOC 1/2, ISO 27001, PCI-DSS, and HIPAA, while building automation to integrate compliance checks into CI/CD. Support Federal compliance initiatives, manage customer trust activities, and guide risk and vendor/supplier compliance for enterprise prospects.
Location: United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Design, implement, and continuously monitor commercial compliance controls with engineering teams for SOC 1/2, ISO 27001, PCI-DSS, and HIPAA.
  • •Build and implement compliance automation to scale control testing and integrate continuous compliance checks into the CI/CD pipeline.
  • •Support Federal compliance initiatives and frameworks including FedRAMP Moderate+, CMMC, DoD IL, and FedRAMP 20x.
  • •Serve customer trust needs by reviewing contracts for security/privacy requirements, completing security questionnaires, and maintaining the customer trust portal.
  • •Identify, track, and mitigate compliance risks, including supply chain security and vendor risk, and manage relationships with auditors and external assessors.

Pay and Benefits

Salary: USD 150,000 - 164,000 annually
Perks:Health InsurancePaid LeaveParental LeaveFlexible Work

Key Requirements

  • •8-10 years of relevant experience in security, compliance, and GRC program management.
  • •Expertise in commercial compliance frameworks and certifications including SOC 2, SOC 1, ISO 27001/ISO 27k, HIPAA, and PCI-DSS.
  • •Hands-on GRC tools experience and ability to build automation for security and compliance controls in a cloud-native environment (AWS, GCP, or Azure).
  • •Working knowledge of federal compliance frameworks such as NIST 800-53 and FedRAMP, and interest in expanding these programs.
  • •Strong cybersecurity acumen and strong project management, communication, and ability to operate in ambiguity while partnering with technical and non-technical stakeholders.
Experience:8-10 yearsGRCSecurity complianceCloud-nativeSaaSFedRAMPEnterprise security
Skills:Project managementOrganizational skillsCommunicationStakeholder managementRisk management
Certifications:ISO 27001 Lead Implementer/AuditorPCI QSACISACISSPPMPAWS/GCP ProfessionalFedRAMP-specific credentials
Languages:English
Tech Stack:AWSGCPAzureCI/CDSOC 1SOC 2ISO 27001PCI-DSSHIPAAFedRAMPNIST 800-53CMMCKubernetesSBOMsSLSADLPPlatform OneIron BankDoD ILAutomation

Company Brief

Harness
Provides a continuous delivery and software delivery platform that automates deployment, feature releases, rollbacks, and cloud cost optimization using machine learning to help engineering teams deliver changes quickly and safely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Funding: Series D
Headquarters: San Francisco, United States
Founded: 2016
WebsiteLinkedIn