Pinterest6 дней назад

Аналитик GRC в области безопасности

Зарплата не указана
San Francisco

Обязанности

  • 01Administer and maintain the security risk register, including tracking identified risks, updates, remediation activities, owners, and reporting outputs
  • 02Partner with stakeholders across Security and the business to identify, document, assess, and monitor security risks
  • 03Draft, review, update, and manage the lifecycle of security policies, standards, and supporting procedures
  • 04Support the planning, coordination, evidence collection, and follow-up activities for Pinterest’s annual SOC 2 Type 2 audit
  • 05Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions
  • 06Execute security control testing activities aligned to CIS Controls and document testing outcomes, findings, and remediation recommendations
  • 07Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders
  • 08Help monitor control effectiveness and identify opportunities to improve process maturity, consistency, and evidence quality
  • 09Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit, and awareness program status
  • 10Support remediation tracking for control gaps, audit findings, and risk treatment actions
  • 11Contribute to the continuous improvement of Pinterest’s GRC framework, documentation, and operating rhythms
  • 12Maintain strong working relationships with internal partners to promote a practical, business-aligned approach to security governance and compliance

Требования

  • 014+ years experience in security governance, risk, compliance, audit, or security assurance roles
  • 02Working knowledge of core security and compliance frameworks such as SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar
  • 03Experience supporting audits, assessments, or control testing programs in a technology or SaaS environment
  • 04Ability to write clear, practical, and actionable security policies, standards, and process documentation
  • 05Experience maintaining risk registers and supporting formal risk assessment processes
  • 06Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail
  • 07Comfort working cross-functionally and gathering information or evidence from technical and non-technical stakeholders
  • 08Strong written and verbal communication skills, including the ability to summarize risk and compliance issues clearly
  • 09A pragmatic, collaborative mindset and a desire to help teams meet security requirements in a scalable way
  • 10Bachelor’s degree in a relevant field such as Computer Information systems or Cybersecurity, or equivalent experience

Условия

  • 01This role will need to be in the office for in-person collaboration 1-2 times/quarter and therefore can be situated anywhere in the country
  • 02This position is not eligible for relocation assistance
  • 03The position is also eligible for equity