The role involves leading governance, risk, and compliance efforts within a high-scale SaaS environment, transforming security requirements into streamlined processes, managing compliance frameworks, and collaborating across teams to ensure operational resilience and data security.
Key Responsibilities
Develop and maintain GRC dashboards to provide leadership with actionable compliance and governance insights
Lead strategic GRC projects, automate processes, and evaluate emerging technologies to improve GRC efficiency
Manage the evolution of compliance frameworks (SOC 2, ISO, NIST) to meet regional and regulatory requirements
Track and report on security awareness training completion and enhance global security awareness programs
Own and streamline the security exception lifecycle, including request validation and risk assessments
Consolidate and maintain GRC program documentation in a central repository for leadership, control owners, and auditors
Map business processes to security frameworks and translate technical gaps into clear business impacts
Build and manage GRC metrics, dashboards, and risk registers to identify trends and support decision-making
Collaborate with stakeholders across Legal, Finance, and Engineering to align on compliance and risk mitigation strategies
Navigate third-party risk management and supply chain security within a shared-responsibility operational model
Requirements
Deep understanding of mapping business processes to frameworks like SOC 2, ISO 27001, or NIST, with the ability to translate technical security gaps into clear business impact likelihood, impact, and operational implications.
Technical proficiency in building and managing GRC metrics, dashboards, and risk registers using tools like Jira or GRC platforms to identify trends and support objective decision-making.
Experience in driving Governance and Compliance Metrics and Visibility by architecting and maintaining GRC dashboards to provide leadership with actionable insights, ensuring all key governance and compliance metrics are documented and actively managed.
Experience collaborating with the Director of GRC to lead strategic GRC projects, drive process automation, and evaluate emerging technologies like AI to enhance GRC function efficiency and effectiveness.
Experience managing the evolution of our Common Controls Framework (SOC 2, ISO, NIST) by mapping requirements to business processes, ensuring regional and regulatory compliance while maintaining customer trust.
Experience tracking and reporting on annual security training completion, partnering with stakeholders to ensure high adoption and enhance the global security awareness program.
Ownership of the end-to-end security exception lifecycle within Jira, including validating requests and supporting risk assessments to balance business velocity with necessary security guardrails.
Consolidating and maturing the Governance, Risk, and Compliance (GRC) program documentation into a central repository that houses the GRC charter, links to policy library, risk framework, and compliance mappings (e.g., SOC 2, GDPR) for leadership, control owners, employees, and auditors.
Operational resilience experience navigating third-party risk management and supply chain security within a shared-responsibility model to ensure continuous operational uptime and data protection.
Ability to work in an in-office environment at the Lehi, Utah office in compliance with company policies, unless on PTO, work travel, or other approved leave.
Benefits & Perks
Salary range: 131,000 - 197,000 USD
Potential eligibility for incentive pay and equity
Work environment primarily in-office at Lehi, Utah
Flexible time off
Wellness resources
Company-sponsored team events
Ready to Apply?
Join Pure Storage and make an impact in renewable energy