Senior Staff GRC Analyst Strategic Account Partner
Job Summary
Most security assurance work is reactive: a customer asks a team scrambles an answer goes out. This role exists to end that cycle.
As a Senior Staff Analyst youll own a named portfolio of our most significant customers from a security perspective and get ahead of what they need their regulatory environment their audit calendar their risk appetite their control expectations well enough to have the evidence ready before the request arrives. Youll lead customer security audits hands-on sit across from customer security teams as a peer rather than a form-filler and build account security plans that make the next assessment predictable instead of painful.
This is deliberately a hands-on senior individual contributor role. Youll spend your time in audits in customer conversations and in the detail of controls and evidence not in a management chain. If youve got deep SOC 2 and ISO 27001 knowledge real technical range across cloud architecture identity and vulnerability management and the presence to hold a room with a sceptical CISO this is a portfolio you can genuinely own.
Heres a breakdown of what youll do (not all of it just the important stuff):
- Own a portfolio of strategic accounts as their dedicated security point of contact building durable relationships with their security risk compliance and procurement teams.
- Lead customer security audits and assessments hands-on scoping preparing evidence running the sessions defending control design and driving findings to closure with internal owners.
- Build and maintain an account security plan for each account: their frameworks and regulators audit and reassessment cycles known concerns open items and the roadmap commitments they care about.
- Anticipate requirements before theyre raised tracking regulatory change industry expectations and each accounts compliance calendar so documentation and evidence are staged in advance.
- Act as the escalation and expertise layer for complex assurance work bespoke questionnaires contractual security terms incident and vulnerability inquiries penetration tests and architecture-level questions.
- Partner with Sales Customer Success and Renewals as the embedded security resource and feed what you learn back into the security and compliance roadmap the shared answer library and trust site content.
These are the essentials youll need to get an interview:
- 5 years in security GRC customer assurance security consulting IT audit or a closely related function with meaningful time spent customer- or client-facing.
- Direct hands-on experience leading or defending security audits and assessments on either side of the table.
- Deep working knowledge of SOC 2 and ISO 27001 plus the adjacent expectations strategic customers raise NIST CSF GDPR HIPAA DORA and sector-specific requirements.
- Genuine technical depth: you can discuss cloud architecture encryption identity logging and vulnerability management with a customers security engineers without taking every question away.
- Excellent written communication especially the ability to write precisely about controls for an expert audience.
- The judgment and presence to hold a room with a sceptical CISO say we dont do that today heres why and heres what we do instead and keep the relationship intact.
- A demonstrated bias toward anticipation over reaction evidence youve built something that prevented fire drills rather than just handling them well.
It would be great if you had these to but well support you if you dont:
- Prior experience in a GRC analyst customer security officer or named account security or customer success role.
- Experience in financial services healthcare or the public sector or supporting customers in heavily regulated industries.
- Certifications such as CISSP CISA CRISC or ISO 27001 Lead Auditor.
- Familiarity with trust center platforms and AI-assisted assurance tooling.
- Experience in a multi-product SaaS environment where certifications and control boundaries differ by product.
- Comfort with occasional travel for on-site customer audits and executive reviews.
About Us
Diligent is the AI leader in governance risk and compliance (GRC) SaaS solutions helping more than 1 million users and 700000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners the C-Suite and the board a consolidated view of their entire GRC practice so they can more effectively manage risk build greater resilience and make better decisions faster.
Learn more or follow us onLinkedInandFacebook
What Diligent Offers You
- Creativity is ingrained in our culture. We are innovative collaborators by nature. We thrive in exploring how things can be differently both in our internal processes and to help our clients
- We care about our people.Diligent offers a flexible work environment global days of service comprehensive health benefits meeting free days generous time off policy and wellness programsto name a few
- We have teams all over the world. We may be headquartered in New York City but we have office hubs in Washington D.C. Vancouver London Galway Budapest Munich Bengaluru Singapore and Sydney.
- Diversity is important to us. Growing maintaining and promoting a diverse team is a top priority for us. We foster and encourage diversity through our Employee Resource Groups and provide access to resources and education to support the education of our team facilitate dialogue and foster understanding.
Diligent created the modern governance movement. Our world-changing idea is to empower leaders with the technology insights and connections they need to drive greater impact and accountability to lead with purpose. Our employees are passionate smart and creative people who not only want to help build the software company of the future but who want to make the world a more sustainable equitable and better place.
Headquartered in New York Diligent has offices in Washington D.C. London Galway Budapest Vancouver Bengaluru Munich Singapore and Sydney. To foster strong collaboration and connection this role will follow a hybrid work model. If you are within a commuting distance to one of our Diligent office locations you will be expected towork onsite at least 50% of the time.We believe that in-person engagement helps drive innovation teamwork and a strong sense of community.
Diligent is proud to be an equal opportunity employer. We do not discriminate based on race color religious creed sex national origin ancestry citizenship status pregnancy childbirth physical disability mental disability age military status protected veteran status marital status registered domestic partner or civil union status gender (including sex stereotyping and gender identity or expression) medical condition (including but not limited to cancer related or HIV/AIDS related) genetic information or sexual orientation in accordance with applicable federal state and local also consider qualified applicants regardless of criminal histories consistent with legal requirements. See alsoDiligentsEEO PolicyandUS EEOCs Know Your Rights. We are a drug free workplace.
We are committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability you may contact us at
Required Experience:
Staff IC
About Company
Diligent, a modern governance company, is the only comprehensive governance software provider featuring tools to improve and simplify modern day governance.