At JFrog, we’re reinventing DevSecOps to help the world’s greatest companies innovate. Our team of industry-leading software security experts is a true pioneer, constantly pushing the boundaries with original research and technological innovation. JFrog is a special place with a unique combination of brilliance, spirit, and just all-around great people. Thousands of customers, including the majority of the Fortune 100, trust JFrog to manage, accelerate, and secure their software delivery from code to production – a concept we call “liquid software”. Wouldn't it be amazing if you could join us on our journey?
We are seeking a GRC Specialist (Governance, Risk, and Compliance) to join our growing GRC Team. This is a fantastic opportunity to be part of a growing team and support the company as it grows and matures. If you're a team player, self-driven, creative thinker, passionate about cybersecurity, and capable of blending a process-oriented mindset with a tech-oriented outlook, we are looking for you!
As a GRC specialist at JFrog you will...- Maintain internal and external trust platforms, supporting ongoing customer due diligence activities including audits, questionnaires, and reviewing security contractual requirements.
- Provide training and guidance to sales teams on compliance-related matters and develop tools and resources to enable the Sales Team to efficiently respond to compliance inquiries from prospective and existing customers.
- Collaborate with cross-functional teams to support and enhance the overall GRC program.
- Ensure company policies, procedures, and controls are aligned with regulatory requirements and industry standards.
- Proactively gather customer feedback and stay abreast of industry trends to adapt and mature the GRC program accordingly.
- Implement improvements and updates to the program, based on regulatory changes and customer requirements.
- Participate in risk assessment and risk management processes.
- Minimum 1-2 years as a cyber security / GRC specialist, expert, or consultant
- Strong knowledge and hands-on experience with ISO 27001 and SOC 2 Type II
- Familiarity with additional security frameworks as well as privacy regulations and standards (NIST, CSA, CAIQ, SIG, GDPR, CCPA, ISO 27701) is an advantage.
- An excellent ability to communicate verbally and in writing
- Ability to work on multiple projects simultaneously
- Project management skills
- Self-driven and fast learner with a can-do approach
- Passionate about the team and responsibilities
- Experience with auditing cloud environments
- Experience in working with regulators and auditors
- Experience in working with GRC tools
Skills Required
- 1–2 years of experience as a cybersecurity or GRC specialist, expert, or consultant
- Strong knowledge and hands-on experience with ISO 27001
- Strong knowledge and hands-on experience with SOC 2 Type II
- Excellent verbal and written communication skills
- Ability to work on multiple projects simultaneously
- Project management skills
- Experience auditing cloud environments
- Experience working with regulators and auditors
- Experience working with GRC tools
- Familiarity with NIST, CSA, CAIQ, SIG, GDPR, CCPA, and ISO 27701
- Self-driven, fast learner with a can-do approach
- Passion for the team and responsibilities
JFrog Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about JFrog and has not been reviewed or approved by JFrog.
-
Fair & Transparent Compensation — Pay is considered competitive overall, with many indicating they feel paid fairly relative to their roles. Compensation sentiment appears to have improved recently.
-
Equity Value & Accessibility — Equity grants and an employee stock purchase plan are commonly part of offers, adding meaningful value to total rewards. These components are highlighted alongside base pay as reasons packages are viewed favorably.
-
Healthcare Strength — U.S. medical, dental, and vision coverage are characterized as comprehensive and high quality. Employer-verified listings reinforce strong core health coverage.
JFrog Insights
What We Do
JFrog Ltd. (Nasdaq: FROG), is on a mission to create a world of software delivered without friction from developer to device. Driven by a “Liquid Software” vision, the JFrog Software Supply Chain Platform is a single system of record that powers organizations to build, manage, and distribute software quickly and securely, ensuring it is available, traceable, and tamper-proof. The integrated security features also help identify, protect, and remediate against threats and vulnerabilities. JFrog’s hybrid, universal, multi-cloud platform is available as both self-hosted and SaaS services across major cloud service providers. Millions of users and 7K+ customers worldwide, including a majority of the FORTUNE 100, depend on JFrog solutions to securely embrace digital transformation. Once you leap forward, you won’t go back!






