Security GRC Analyst
San Francisco, CA - USA
Job Summary
About Pinterest:
Millions of people around the world come to our platform to find creative ideas dream about new possibilities and plan for memories that will last a lifetime. At Pinterest were on a mission to bring everyone the inspiration to create a life they love and that starts with the people behind the product.
Discover a career where you ignite innovation for millions transform passion into growth opportunities celebrate each others unique experiences and embrace theflexibility to do your best work. Creating a career you love Its Possible.
At Pinterest AI isnt just a feature its a powerful partner that augments our creativity and amplifies our impact and were looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities well explore your foundational skills and how you collaborate with AI.
Through our interview process what matters most is that you can always explain your approach showing us not just what you know but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here.
Pinterests Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented collaborative and motivated by building scalable security processes that help the business manage risk effectively.
Reporting to the Interim Head of Security Governance Risk & Compliance this individual contributor will partner closely with Security Engineering IT Legal Internal Audit and other cross-functional stakeholders to help maintain and improve Pinterests security control environment. The role will contribute to core GRC activities including risk management policy governance control testing audit support awareness tracking and internal risk assessments.
What youll do:
- Administer and maintain the security risk register including tracking identified risks updates remediation activities owners and reporting outputs.
- Partner with stakeholders across Security and the business to identify document assess and monitor security risks.
- Draft review update and manage the lifecycle of security policies standards and supporting procedures.
- Support the planning coordination evidence collection and follow-up activities for Pinterests annual SOC 2 Type 2 audit.
- Track and report on security awareness training metrics completion rates exceptions and follow-up actions.
- Execute security control testing activities aligned to CIS Controls and document testing outcomes findings and remediation recommendations.
- Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders.
- Help monitor control effectiveness and identify opportunities to improve process maturity consistency and evidence quality.
- Prepare dashboards reports and presentations for leadership on risk compliance audit and awareness program status.
- Support remediation tracking for control gaps audit findings and risk treatment actions.
- Contribute to the continuous improvement of Pinterests GRC framework documentation and operating rhythms.
- Maintain strong working relationships with internal partners to promote a practical business-aligned approach to security governance and compliance.
What we are looking for:
- 4 years experience in security governance risk compliance audit or security assurance roles.
- Working knowledge of core security and compliance frameworks such as SOC 2 CIS Controls ISO 27001 NIST CSF or similar.
- Experience supporting audits assessments or control testing programs in a technology or SaaS environment.
- Ability to write clear practical and actionable security policies standards and process documentation.
- Experience maintaining risk registers and supporting formal risk assessment processes.
- Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail.
- Comfort working cross-functionally and gathering information or evidence from technical and non-technical stakeholders.
- Strong written and verbal communication skills including the ability to summarize risk and compliance issues clearly.
- A pragmatic collaborative mindset and a desire to help teams meet security requirements in a scalable way.
- Bachelors degree in a relevant field such as Computer Information systems or Cybersecurity or equivalent experience.
Preferred qualifications:
- Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment.
- Familiarity with security awareness program administration and reporting.
- Experience performing or coordinating control testing mapped to recognized frameworks such as CIS Controls.
- Knowledge of common enterprise security domains including identity and access management logging and monitoring vulnerability management endpoint security and third-party risk.
- Relevant certifications such as Security CISA CRISC CISSP or similar are a plus.
In-Office Requirement Statement:
- We let the type of work you do guide the collaboration style. That means were not always working in an office but we continue to gather for key moments of collaboration and connection.
- This role will need to be in the office for in-person collaboration 1-2 times/quarter and therefore can be situated anywhere in the country.
Relocation Statement:
- This position is not eligible for relocation assistance. Visit our PinFlex page to learn more about our working model.
#LI-REMOTE
Required Experience:
IC
About Company
Join the people behind the product to build a more positive internet for Pinterest users worldwide.