Pinterest6 дней назад
Аналитик GRC в области безопасности
Зарплата не указана
San Francisco
Обязанности
- 01Administer and maintain the security risk register, including tracking identified risks, updates, remediation activities, owners, and reporting outputs
- 02Partner with stakeholders across Security and the business to identify, document, assess, and monitor security risks
- 03Draft, review, update, and manage the lifecycle of security policies, standards, and supporting procedures
- 04Support the planning, coordination, evidence collection, and follow-up activities for Pinterest’s annual SOC 2 Type 2 audit
- 05Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions
- 06Execute security control testing activities aligned to CIS Controls and document testing outcomes, findings, and remediation recommendations
- 07Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders
- 08Help monitor control effectiveness and identify opportunities to improve process maturity, consistency, and evidence quality
- 09Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit, and awareness program status
- 10Support remediation tracking for control gaps, audit findings, and risk treatment actions
- 11Contribute to the continuous improvement of Pinterest’s GRC framework, documentation, and operating rhythms
- 12Maintain strong working relationships with internal partners to promote a practical, business-aligned approach to security governance and compliance
Требования
- 014+ years experience in security governance, risk, compliance, audit, or security assurance roles
- 02Working knowledge of core security and compliance frameworks such as SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar
- 03Experience supporting audits, assessments, or control testing programs in a technology or SaaS environment
- 04Ability to write clear, practical, and actionable security policies, standards, and process documentation
- 05Experience maintaining risk registers and supporting formal risk assessment processes
- 06Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail
- 07Comfort working cross-functionally and gathering information or evidence from technical and non-technical stakeholders
- 08Strong written and verbal communication skills, including the ability to summarize risk and compliance issues clearly
- 09A pragmatic, collaborative mindset and a desire to help teams meet security requirements in a scalable way
- 10Bachelor’s degree in a relevant field such as Computer Information systems or Cybersecurity, or equivalent experience
Условия
- 01This role will need to be in the office for in-person collaboration 1-2 times/quarter and therefore can be situated anywhere in the country
- 02This position is not eligible for relocation assistance
- 03The position is also eligible for equity