Security GRC Analyst

Pinterest

Confirmed live 3 days ago High trust
Remote

Quick summary

Work type
Remote
Location
San Francisco, CA
Salary
$123,696–$254,667 / yr
Posted
7 days ago
Freshness
Confirmed live 3 days ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $150k
This role $189k
$100k most similar roles pay here $271k

This role pays more than 82% of similar roles. Most pay $123,375–$177,525 — the shaded band above. At the midpoint, this role pays about $189k versus about $150k for comparable roles.

Based on 239 similar postings.

Employer

About Pinterest

Pinterest is a visual discovery and inspiration platform where people find ideas for home, style, recipes, and more. It serves hundreds of millions of users worldwide through its image and video pinboard product.

Pinterest currently has 82 open roles on FindRole.

Listed pay typically runs $164,695–$337,990 across 82 roles with salary data.

Most-posted roles

View all roles at Pinterest

At a glance

TL;DR · Security GRC Analyst

As a Security GRC Senior Analyst on the Pinfosec team, you will support and strengthen security governance and assurance programs to manage risk effectively. You will partner with cross-functional stakeholders across Engineering, IT, Legal, and Internal Audit to maintain the security control environment. Your daily responsibilities include managing the security risk register, drafting and updating policy documentation, tracking security awareness metrics, and executing control testing aligned to CIS Controls. You will also coordinate evidence collection for annual SOC 2 Type 2 audits and prepare status reports for leadership. The role requires expertise in frameworks such as SOC 2, CIS Controls, ISO 27001, and NIST CSF within a technology or SaaS environment. Key skills include risk assessment, policy writing, and experience with identity management, vulnerability management, and third-party risk.

What you'll do

  • Administer and maintain the security risk register by tracking identified risks, remediation activities, and reporting outputs.
  • Draft, review, and manage the lifecycle of security policies, standards, and supporting procedures.
  • Coordinate evidence collection and follow-up activities for annual SOC 2 Type 2 audits.
  • Execute security control testing aligned to CIS Controls and document findings and remediation recommendations.
  • Conduct risk assessments in partnership with internal security teams and business stakeholders.
  • Track and report on security awareness training metrics, completion rates, and exceptions.
  • Prepare dashboards and presentations for leadership regarding risk, compliance, and audit status.
  • Monitor control effectiveness to identify opportunities for improving process maturity and evidence quality.

What we're looking for

  • Bachelor’s degree in a relevant field such as Computer Information Systems or Cybersecurity, or equivalent experience.
  • 4+ years of experience in security governance, risk, compliance, audit, or security assurance roles.
  • Working knowledge of core security and compliance frameworks including SOC 2, CIS Controls, ISO 27001, or NIST CSF.
  • Experience supporting audits, assessments, or control testing programs in a technology or SaaS environment.
  • Ability to write clear, practical, and actionable security policies, standards, and process documentation.
  • Experience maintaining risk registers and supporting formal risk assessment processes.
  • Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail.
  • Relevant certifications such as Security+, CISA, CRISC, or CISSP are preferred.

More like this

Similar roles

Senior Security GRC Analyst

Salesforce

Remote (Herndon, VA) 10 days ago $117,200$176,700
Information Security Cybersecurity FedRAMP DoD SRG AWS Azure GCP SaaS IaaS PaaS Compliance Engineering AI Scripting Incident Response Security Operations Agile
4+ yrs exp Remote

Security Engineer, GRC

Plaid

San Francisco, CA +2 57 days ago $156,000$213,600
Python SQL AWS Terraform CI/CD OPA Rego Sentinel Policy-as-Code OpenAI Claude SOC 2 ISO 27001 NIST CSF FedRAMP Mode GitHub API

Security Analyst

General Dynamics

Chantilly, VA 7 days ago
Microsoft Office Data Entry IC Databases Background Investigations ICD 704 E.O. 12968
3+ yrs exp

Lead Security Engineer, GRC

Anduril Industries

Costa Mesa, CA 168 days ago $166,000$253,000
Go Python Rust Terraform AWS CDK CMMC NIST 800-171 FedRAMP SOC 2 APIs Data Pipelines Kubernetes CSPM STIG ConMon Security Data Lakes Log Aggregation
6+ yrs exp

Lead Security Engineer, GRC

Anduril Industries

Boston, MA 16 days ago $166,000$253,000
Python Go Rust Terraform AWS CDK CMMC NIST 800-171 FedRAMP SOC 2 APIs Data Pipelines Kubernetes CSPM STIG ConMon Security Data Lakes
6+ yrs exp

Lead Security Engineer, GRC

Anduril Industries

Washington, DC 16 days ago $166,000$253,000
Go Python Rust Terraform AWS CDK CMMC NIST 800-171 FedRAMP SOC 2 APIs Data Pipelines Kubernetes CSPM STIG ConMon Security Data Lakes Log Aggregation
6+ yrs exp