ApplySarthi Match jobs to your CV

Staff Security Analyst - GRC

Jobgether

Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

2,790 open security roles across 437 companies are on ApplySarthi right now, most of them in Bengaluru (116), Hyderabad (28), Pune (22).

What security roles keep asking for: AWS (29%), Python (26%), SIEM (14%), GCP (12%), CI/CD (12%) — counted across their open postings here.

Security Analyst jobs in the United States · AWS jobs · Azure jobs · CI/CD jobs · GCP jobs

Jobgether has 3,942 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for security roles keep coming back to AWS, Python, SIEM, GCP. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with AWS? Tell me one thing you learned the hard way.
  3. Tell me about an analysis that changed a decision. What did you find?
  4. How do you check that your numbers are right before you share them?
  5. Walk me through a dashboard or report you built. Who used it, and for what?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Staff Security Analyst - GRC at Jobgether interview free →

Accountabilities:: Design, implement, and continuously monitor commercial security and compliance controls across environments supporting SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA requirements. Partner with engineering teams to ensure systems and environments are appropriately scoped, secured, and aligned with applicable compliance obligations. Develop and implement GRC engineering and automation solutions that scale compliance activities, automate control testing, and integrate continuous compliance checks into CI/CD pipelines. Streamline compliance reporting and improve the efficiency and reliability of security and compliance processes through automation. Support federal compliance initiatives involving frameworks and programs such as FedRAMP Moderate+, CMMC, DoD IL, FedRAMP 20x, and NIST 800-53. Support customer trust activities by reviewing contracts for security and privacy requirements, completing detailed security questionnaires, and maintaining the customer trust portal. Provide precise, actionable security and privacy guidance to engineering, product, and business teams, helping incorporate security and privacy by design. Build and maintain effective relationships with external suppliers, auditors, assessors, and enterprise prospects. Identify, track, and mitigate risks associated with compliance programs and projects while continuously monitoring supply chain security and vendor risk. Clearly communicate security capabilities, controls, and compliance practices to enterprise customers and regulatory auditors. Build new programs and initiatives from the ground up while managing multiple priorities in a complex, fast-moving environment. Share knowledge and help junior colleagues develop their understanding of security, compliance, and automation practices. Requirements 8–10+ years of relevant industry experience in security, compliance, GRC, or security program management. Extensive experience with commercial security frameworks, regulations, and certifications, including ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA. Experience working with GRC tools and building automation for security and compliance controls in cloud-native environments such as AWS, GCP, or Azure. Working knowledge of or exposure to federal compliance frameworks including NIST 800-53, FedRAMP, and CMMC, with an interest in expanding federal compliance programs. Strong cybersecurity knowledge and technical proficiency with enterprise SaaS applications and cloud infrastructure. Strong project management and organizational skills, with the ability to manage multiple priorities and establish new programs. Excellent written and verbal communication skills, with the ability to work effectively with both technical engineering teams and non-technical stakeholders. Ability to navigate ambiguity, create clarity, and make sound decisions in complex and rapidly changing situations. Hands-on experience building, delivering, or managing a FedRAMP-compliant service offering or achieving an Authority to Operate (ATO) is a plus. Familiarity with federal and defense environments such as Platform One, Iron Bank, CMMC, or DoD IL is a plus. Understanding of AWS or GCP environments and cloud configuration and management best practices is a plus. Relevant certifications such as ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials are a plus. Experience assessing or applying AI in secure environments is a plus. Exposure to Kubernetes, SBOMs, SLSA, and/or DLP is a plus. A strong interest in automation and a willingness to share knowledge with junior team members are valued. Benefits $150,000–$164,000 annual base salary, with compensation determined by location, level, relevant experience, and skills. Potential equity as part of the overall compensation package. Comprehensive healthcare benefits. Flexible Spending Account (FSA). Flexible work schedule. Employee Assistance Program (EAP). Flexible Time Off and parental leave. Monthly internet reimbursement. Monthly, quarterly, and annual social and team-building events. Remote work within the United States, with a hybrid option available from designated offices.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-09-22. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.