A Senior Governance, Risk, and Compliance (GRC) Analyst responsible for developing and managing security and compliance processes, dashboards, and frameworks to ensure regulatory adherence and operational resilience in a high-scale SaaS environment.
Key Responsibilities
Transform complex security and compliance requirements into streamlined processes to safeguard customers and support growth
Serve as a strategic liaison between technical teams and business functions to ensure risks are visible and decisions are data-driven
Develop and maintain GRC dashboards to provide leadership with actionable insights on governance and compliance metrics
Lead strategic GRC projects, drive process automation, and evaluate emerging technologies to enhance GRC efficiency
Manage the evolution of the Common Controls Framework (SOC 2, ISO, NIST) to meet regional and regulatory obligations
Track and report on security awareness training completion and enhance the global security awareness program
Own and streamline the security exception lifecycle, including request validation and risk assessments
Consolidate and manage GRC program documentation in a central repository for leadership, control owners, and auditors
Requirements
Deep understanding of mapping business processes to frameworks like SOC 2, ISO 27001, or NIST, with the ability to translate technical security gaps into clear business impact likelihood, impact, and operational implications.
Technical proficiency in building and managing GRC metrics, dashboards, and risk registers using tools like Jira or GRC platforms to identify trends and support objective decision-making.
Experience in driving Governance and Compliance Metrics and Visibility by architecting and maintaining GRC dashboards to provide leadership with actionable insights, ensuring all key governance and compliance metrics are documented and actively managed.
Experience collaborating with the Director of GRC to lead strategic GRC projects, drive process automation, and evaluate emerging technologies like AI to enhance GRC function efficiency and effectiveness.
Proficiency in managing the evolution of our Common Controls Framework (SOC 2, ISO, NIST) by mapping requirements to business processes, ensuring compliance with regional and regulatory obligations while maintaining customer trust.
Experience tracking and reporting on annual security training completion, partnering with stakeholders to ensure high adoption and enhance the global security awareness program.
Ownership of the end-to-end security exception lifecycle within Jira, including validating requests and supporting risk assessments to balance business velocity with necessary security guardrails.
Ability to develop and manage GRC program documentation into a central repository, consolidating and maturing GRC charter, policy library links, risk framework, and compliance mappings (e.g., SOC 2, GDPR) for leadership, control owners, employees, and auditors.
Operational resilience experience, including navigating third-party risk management and supply chain security within a shared-responsibility model to ensure continuous operational uptime and data protection.
Ability to work in an in-office environment at the Lehi, Utah office in compliance with company policies, unless on PTO, work travel, or other approved leave.
Benefits & Perks
Salary range: 131,000 - 197,000 USD
Potential for incentive pay and equity
Work environment primarily in-office at Lehi, Utah
Flexible time off
Wellness resources
Company-sponsored team events
Support for growth and development
Inclusive and diverse workplace culture
Ready to Apply?
Join Pure Storage and make an impact in renewable energy