Staff Security Analyst - GRC
United States · Remote
- Posted 2w ago
- From Harness’s careers page
- Location
- United States
- Work mode
- Remote
- Level
- Staff
- Experience
- 8+ years
- Department
- Other
Opens the listing on harness.io
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Position Summary
A Staff Security Analyst will be a critical member of the GRC team working within the Information Security organization and across the business to advise, build, and operate security and compliance programs at scale. Utilizing in-depth expertise across multiple disciplines, you will be responsible for executing various components of Harness' security posture and overseeing end-to-end solutions to complex compliance problems.
About the role
- Commercial Compliance Management: Design, implement, and continuously monitor commercial compliance controls, collaborating with engineering teams to ensure environments are properly scoped and secured for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA.
- GRC Engineering & Automation: Develop and implement automation solutions to scale compliance tasks, automate control testing, integrate continuous compliance checks into the CI/CD pipeline, and streamline reporting.
- Federal Compliance Support: Contribute to Federal compliance initiatives and frameworks (such as FedRAMP Moderate+, CMMC, DoD IL, and FedRAMP 20x) as Harness expands its public sector footprint.
- Customer Trust & Advisory: Support customer trust initiatives by reviewing contracts for security and privacy requirements, completing detailed customer security questionnaires, and maintaining the customer trust portal.
- Cross-Functional Collaboration: Contribute precise and actionable guidance to ensure security and privacy by design for engineering, product, and business initiatives.
- Stakeholder Engagement: Manage relationships and facilitate engagement with external suppliers, auditors, assessors, and enterprise prospects.
- Risk Management: Identify, track, and mitigate risks related to compliance projects, continuously monitor supply chain security, and manage vendor risk.
- Evangelism: Articulate Harness's security capabilities and controls clearly to enterprise customers and regulatory auditors
About you
- You have a minimum of 8-10 years of relevant industry experience in security, compliance, and GRC program management.
- Extensive exposure to commercial industry regulations, frameworks, and compliance certifications (ISO 27001, SOC 1, SOC 2, PCI-DSS, HIPAA).
- Previous experience with GRC tools and a demonstrated ability to build automation for security and compliance controls in a cloud-native environment (AWS, GCP, or Azure).
- Working knowledge or exposure to Federal compliance frameworks (e.g., NIST 800-53, FedRAMP, CMMC) and are interested in expanding these programs.
- You possess strong cybersecurity acumen and solid technical proficiency with enterprise SaaS applications and infrastructure.
- Excellent project management and organizational skills, with the ability to handle multiple priorities and build new programs from scratch.
- Clear, concise communication skills, both written and verbal, and can effectively partner with technical engineering teams as well as non-technical stakeholders.
- You are comfortable navigating ambiguity and driving clarity in complex, fast-paced situations.
Bonus Points!
- You have hands-on experience building, delivering, or managing a FedRAMP-compliant service offering (FedRAMP Moderate+) or achieving an ATO.
- Familiarity with specialized defense/federal environments like Platform One, Iron Bank, CMMC, or DoD IL.
- You are familiar with what is going on under the hood of the AWS or GCP console and can speak to best practices for configuration and management.
- You hold relevant security or technical certifications (ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials).
- Previous experience assessing and utilizing AI in a secure environment.
- You have exposure to or experience with Kubernetes, SBOMs, SLSA, and/or DLP.
- You like to "automate the boring stuff" and are eager to share your knowledge with junior colleagues
Skills they ask for
Pick one to see other roles that ask for it.
About Harness
An AI platform for software deliveryHarness provides an autonomous software delivery platform that uses AI to manage pipelines, assess risk, and govern software releases.
See all 27 roles at HarnessMore roles at Harness
See all 27- Senior Customer ArchitectUnited States · Senior · RemoteCustomer Service · Senior · RemoteUnited States9h
- Staff/Senior Software Engineer - Cloud Platform EngineeringUnited States · Senior · RemoteSoftware Development · Senior · RemoteUnited States2d
- Customer Experience Engineer I/IIUnited States · Entry Level · RemoteEntry Level · RemoteUnited States2d
- AppSec Sales Engineer - EastUnited States · Senior · RemoteSales · Senior · RemoteUnited States3d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.