14 security grc analyst jobs at 14 companies in San Jose, CA
1mo
Save
Mark Applied
Hide
1mo
Security GRC Analyst
San Francisco, California, United States
$116k-$160k/yrOnsiteFull Time
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
United States or San Francisco or New York City or Bengaluru
$150k-$200k/yrHybridFull Time
Mesh: Connecting digital wallets and exchanges for unified cryptocurrency payments.
5+ YOERequires 5+ years of hands-on GRC experience, compliance program management, major security framework familiarity, business continuity and disaster recovery experience, risk lifecycle expertise, and scalable process-building skills.
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yrOnsiteFull Time
SandiskNasdaq: SNDK: Designs and manufactures flash memory and data storage products.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
Discord: A platform providing voice, video, and text communication services.
4+ YOE4+ years in security compliance/GRC or related fields; familiarity with ISO 27001/27002,SOC 2,PCI DSS,GDPR/CPRA; hands-on compliance processes; automation-first mindset; strong writing and cross-team collaboration skills.
ISO 27001, ISO 27002, SOC 2, PCI DSS, GDPR, CPRA, GRC platform, ticketing, docs and wikis
NavanNasdaq: NAVN: Integrated platform for corporate travel and expense management.
6+ YOE6+ years in security GRC/auditing, hands-on ISMS management, experience with PCI, SOX, ISO 27001/42001, SOC 1/2, control automation, auditor coordination, and cloud security.
RingCentralNYSE: RNG: Sells cloud-based business phone and video conferencing software.
2+ YOERequires 2–3 years in security, risk, or enablement focused on GRC, TPRM, or security trust; a technical bachelor's degree or equivalent experience; security, vendor risk, compliance, writing, and data analysis skills.
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam
$134k-$214k/yrHybridFull Time
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
6+ YOE6+ years in security assurance/GRC with ownership of customer-facing security workflows; experience reviewing security contract provisions; familiarity with SOC 2, ISO 27001, NIST frameworks, PCI, GLBA, GDPR/CCPA; program design, metrics ownership, and AI-assisted workflow experience.
Pure StorageNYSE: PSTG: Provides all-flash enterprise data storage and management solutions.
2+ YOE2–5 years in customer trust/GRC/security assurance; knowledge of SOC 2, ISO/IEC 27001, NIST CSF, GDPR; strong technical writing, cross-functional collaboration, and problem-solving; generative AI or automation experience desirable.
SOC 2, ISO/IEC 27001, NIST CSF, GDPR, generative AI
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.