14 security grc analyst jobs at 14 companies in San Jose, CA

1mo
Save
Mark Applied
Hide
Security GRC Analyst
San Francisco, California, United States
$116k-$160k/yr OnsiteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
1mo
Save
Mark Applied
Hide
Senior Security GRC Analyst
San Mateo, California, United States
$224k-$272k/yr HybridFull Time
Roblox
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
3w
Save
Mark Applied
Hide
GRC Analyst
San Francisco, California, United States
$95k-$150k/yr HybridFull Time
Zip
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
1mo
Save
Mark Applied
Hide
Information Security GRC Analyst 4
San Jose or Seattle or Lehi or New York City
$113k-$229k/yr OnsiteFull Time
Adobe
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
2d
Save
Mark Applied
Hide
Governance, Risk & Compliance (GRC) Senior Analyst
United States or San Francisco or New York City or Bengaluru
$150k-$200k/yr HybridFull Time
Mesh
Mesh: Connecting digital wallets and exchanges for unified cryptocurrency payments.
5+ YOERequires 5+ years of hands-on GRC experience, compliance program management, major security framework familiarity, business continuity and disaster recovery experience, risk lifecycle expertise, and scalable process-building skills.
SOC 2, NIST, PCI, MiCA, NYDFS, CCPA, Vanta, Drata, Archer
3w
Save
Mark Applied
Hide
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yr OnsiteFull Time
Sandisk
SandiskNasdaq: SNDK: Designs and manufactures flash memory and data storage products.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
2w
Save
Mark Applied
Hide
Security Analyst
San Francisco, California, United States
$144k-$162k/yr HybridFull Time
Discord
Discord: A platform providing voice, video, and text communication services.
4+ YOE4+ years in security compliance/GRC or related fields; familiarity with ISO 27001/27002,SOC 2,PCI DSS,GDPR/CPRA; hands-on compliance processes; automation-first mindset; strong writing and cross-team collaboration skills.
ISO 27001, ISO 27002, SOC 2, PCI DSS, GDPR, CPRA, GRC platform, ticketing, docs and wikis
2w
Save
Mark Applied
Hide
Staff Security Analyst
Palo Alto, California, United States
$131k-$291k/yr OnsiteFull Time
Navan
NavanNasdaq: NAVN: Integrated platform for corporate travel and expense management.
6+ YOE6+ years in security GRC/auditing, hands-on ISMS management, experience with PCI, SOX, ISO 27001/42001, SOC 1/2, control automation, auditor coordination, and cloud security.
Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, AWS, Azure, GCP, SIEM
2d
Save
Mark Applied
Hide
Associate Security Trust Analyst
Belmont, California, United States
$96k-$118k/yr OnsiteFull Time
RingCentral
RingCentralNYSE: RNG: Sells cloud-based business phone and video conferencing software.
2+ YOERequires 2–3 years in security, risk, or enablement focused on GRC, TPRM, or security trust; a technical bachelor's degree or equivalent experience; security, vendor risk, compliance, writing, and data analysis skills.
AI, SaaS, SOC 2, ISO 27001, NIST
1mo
Save
Mark Applied
Hide
Senior Security Analyst, Customer Assurance
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam
$134k-$214k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
6+ YOE6+ years in security assurance/GRC with ownership of customer-facing security workflows; experience reviewing security contract provisions; familiarity with SOC 2, ISO 27001, NIST frameworks, PCI, GLBA, GDPR/CCPA; program design, metrics ownership, and AI-assisted workflow experience.
SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR, CCPA, NIST 800-53
2mo
Save
Mark Applied
Hide
Security Compliance Analyst, Privacy
San Francisco or New York
$175k-$220k/yr OnsiteFull Time
LangChain
LangChain: Tools for building and deploying production-ready AI agents.
5+ YOE5+ years in privacy/GRC/security compliance; hands-on experience with GDPR, HIPAA, CCPA, SOC 2, ISO frameworks; DPAs/BAAs experience; technical fluency (can read code, validate data flows); strong writing skills.
Python
3w
Save
Mark Applied
Hide
Customer Trust Analyst
Santa Clara, California, United States
$126k-$189k/yr OnsiteFull Time
Pure Storage
Pure StorageNYSE: PSTG: Provides all-flash enterprise data storage and management solutions.
2+ YOE2–5 years in customer trust/GRC/security assurance; knowledge of SOC 2, ISO/IEC 27001, NIST CSF, GDPR; strong technical writing, cross-functional collaboration, and problem-solving; generative AI or automation experience desirable.
SOC 2, ISO/IEC 27001, NIST CSF, GDPR, generative AI
1mo
Save
Mark Applied
Hide
Governance, Risk, Compliance & Trust Analyst
Oakland, California, United States
$140k-$178k/yr HybridFull Time
Everlaw
Everlaw: Provides a cloud-based litigation platform for legal teams.
5+ YOE5+ years GRC experience; strong knowledge of FedRAMP, SOC 2, ISO frameworks; audit readiness, vendor reviews, customer security questionnaires, trust portals, and producing clear, audit-ready deliverables.
FedRAMP, SOC 2, ISO 27001, ISO 27017, ISO 27018, Covey, Covey Scout, Modern Health
2w
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
AWS, Azure, GCP, Covey