Senior Analyst, GRC

Posted 9 Days Ago
Be an Early Applicant
Austin, TX, USA
In-Office
112K-154K Annually
Senior level
Cloud • Software
We are powering progress for our customers in the construction industry by connecting them on a global platform.
The Role
Manage the full cybersecurity risk lifecycle, from assessment and scoring through treatment, acceptance, and closure. Map penetration test, audit, vulnerability, and configuration findings to root-cause risks and controls. Assess cloud and SaaS security risks, maintain data quality in the risk register, and communicate actionable insights to technical and business stakeholders. Use AI tools to accelerate risk analysis, evidence summarization, scenario modeling, reporting, and GRC automation.
Summary Generated by Built In

We're looking for a highly motivated and detail-oriented Senior Cybersecurity Risk Analyst to join our Governance, Risk, and Compliance (GRC) organization. Focused on technical risk management, you'll be a key partner to security, engineering, IT, and business teams to assess and manage security risks across our information asset ecosystem.

This role is designed for a self-driven, critical thinker who views AI as a force multiplier. Our program tracks risks and exceptions: findings from pen tests, audits, and scans are grouped under the bigger risks they point to so we address the root cause, and escalated exceptions are tracked so items stay visible even when they're accepted. You won't just follow a risk manual,  you'll use new technologies and tools to synthesize complex technical data, accelerate risk assessments, and provide the business with high-accuracy insights. You'll play a key role in the entire risk journey. This position reports to our Director, GRC.
 

WHAT YOU'LL DO:

  • End-to-End Risk Lifecycle Management: Manage individual risks end to end, including assessment, scoring, treatment tracking, risk acceptance, and closure. Apply qualitative methods and partner with GRC leadership to validate risk levels against appetite and set priority.

  • Issues/Findings-to-Risk Mapping: Bring findings from pen tests, audits, vulnerability scans, issue management, data protection, and configuration reviews onto the register. Combine related discoveries into root-cause risks with a treatment plan, and track severe accepted or untreated items as exceptions so they stay visible until the risk changes.

  • Risk-to-Control Mapping: Map each risk to the controls that mitigate it so that treatment plans, control gaps, and framework alignment (ISO/IEC 27001, SOC 2, NIST CSF / 800-53) all draw from the same picture. Recommend best-practice controls and treatment options where gaps exist.

  • Technical Risk Assessment: Evaluate risks and configuration issues across our cloud and SaaS ecosystem, including IAM, network security, vulnerability findings, and pen test results, and translate them into clear, actionable risk statements with defensible severity.

  • Partnerships: You'll work directly with architects,  engineering,  Security, IT, system owners, and business stakeholders to validate severity, agree on treatment, and keep entries current.

  • Data Quality Ownership: Keep the risk register complete, current, consistent, and defensible. You'll catch stale entries, unclear ownership, and scoring drift before they reach a report.

  • AI-Powered Operations: Use AI tooling daily to accelerate risk statement drafting, evidence summarization, scenario modeling, and reporting, and look for new opportunities to automate manual GRC work.

WHAT WE ARE LOOKING FOR:

  • Experience: 6+ years in security risk management, GRC, or cybersecurity, with hands-on exposure to cloud environments. Demonstrated experience managing risk above the individual finding level, including aggregating related issues into broader risks, driving systemic treatment, and measuring residual risk.

  • The AI Edge: Current, hands-on AI fluency. You use LLMs in your daily work, can structure prompts that produce accurate and repeatable outputs, and understand failure modes like hallucination and data privacy well enough to know when to double-check results.

  • Data Quality Mindset: Strong attention to data quality. You spot stale records, inconsistent scores, and unclear ownership, and you improve the process that let them happen.

  • Tooling Fluency: Comfortable with Jira and Google Workspace (Sheets, Docs, Slides) as daily working tools, from running workflows in Jira to building analysis and reporting artifacts in Google.

  • Stakeholder Partnership: A track record of working well with technical and business teams, including engineers, offensive security, IT, and system owners, and building credibility with partners you don't have authority over.

  • Independent Contributor: We are a lean team, so you'll work with real autonomy. Proven ability to work independently, take ownership of tasks, prioritize effectively, and raise blockers early in a fast-moving environment with evolving architectures.

  • Technical Knowledge: Able to read network diagrams, vulnerability reports, and pen test findings, understand attack paths, and engage confidently with Security Architects and SecOps engineers. Working knowledge of cloud infrastructure security (AWS, GCP, or Azure) and at least one security framework (ISO 27001, SOC 2, or NIST CSF / NIST 800-53). You know common security controls well enough to recommend appropriate treatments based on best practice, even though deep implementation expertise sits with the engineering teams.

  • Communication: Strong writing and presentation skills, with the ability to explain technical issues to non-technical audiences and walk business stakeholders through risk data in live meetings.

  • Preferred

    • Experience in high-growth SaaS or cloud-native environments

    • Familiarity with DevOps and CI/CD security controls

    • Experience with modern GRC platforms and integrating AI tooling into daily workflows

    • Certifications such as CRISC, CISM, CISSP, or cloud provider certifications.


Additional Information

Base Pay Range:

111,760.00 - 153,670.00 USD Annual

This role may also be eligible for Equity Compensation and/or Bonus Incentive Compensation. Procore is committed to offering competitive, fair, and commensurate compensation. Actual compensation will be based on a candidate’s job-related skills, experience, education or training, and location.

For Los Angeles County (unincorporated) Candidates:

Procore will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.

A criminal history may have a direct, adverse, and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment: 1. appropriately managing, accessing, and handling confidential information including proprietary and trade secret information, as well as accessing Procore's information technology systems and platforms; 2. interacting with and occasionally having unsupervised contact with internal/external customers, stakeholders, and/or colleagues; and 3. exercising sound judgment.

Skills Required

  • 6+ years of experience in security risk management, GRC, or cybersecurity
  • Hands-on exposure to cloud environments
  • Experience aggregating related security issues into broader risks, driving systemic treatment, and measuring residual risk
  • Current hands-on AI fluency, including daily LLM use, prompt structuring, and understanding of hallucination and data privacy risks
  • Strong attention to data quality, including identifying stale records, inconsistent scores, and unclear ownership
  • Proficiency with Jira and Google Workspace, including Sheets, Docs, and Slides
  • Experience partnering with technical and business stakeholders, including engineers, offensive security, IT, and system owners
  • Ability to work independently, take ownership, prioritize effectively, and raise blockers early
  • Ability to read network diagrams, vulnerability reports, and penetration test findings and understand attack paths
  • Working knowledge of cloud infrastructure security in AWS, GCP, or Azure
  • Working knowledge of at least one security framework: ISO 27001, SOC 2, NIST CSF, or NIST 800-53
  • Knowledge of common security controls and ability to recommend appropriate risk treatments
  • Strong writing and presentation skills with the ability to explain technical issues to nontechnical audiences
  • Experience in high-growth SaaS or cloud-native environments
  • Familiarity with DevOps and CI/CD security controls
  • Experience with modern GRC platforms and integrating AI tooling into daily workflows
  • CRISC, CISM, CISSP, or cloud provider certification

Procore Technologies Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Procore Technologies and has not been reviewed or approved by Procore Technologies.

  • Healthcare Strength Health coverage includes an Anthem Blue Cross PPO with broad coverage and low premiums, alongside dental, vision, disability, and life insurance. Mental‑health resources and a wellbeing stipend further support overall care.
  • Leave & Time Off Breadth A values‑driven, non‑accrual PTO approach, 12 paid holidays, and an annual company‑wide Wellness Week indicate generous time‑off options. Hybrid/remote flexibility is also highlighted in many roles and locations.
  • Parental & Family Support Fertility benefits (e.g., via Progyny on some plans) and cash support for adoption and surrogacy are available for eligible U.S. employees. Paid parental leave and structured return‑to‑work programs are also described.

Procore Technologies Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Carpinteria, CA
4,500 Employees
Year Founded: 2002

What We Do

At Procore Technologies, we’re collectively building towards what’s next for our employees, industry, customers, and global communities. Our cloud-based construction management software streamlines the entire lifecycle of a construction project, connecting field and office teams, centralizing data to mitigate risks, providing real-time financials, and more to help clients efficiently build everything from skyscrapers to hospitals to airports. Procore was founded in 2002, and we’ve since grown into a global company of groundbreakers working throughout North America, EMEA, and APAC. Coming together from across diverse backgrounds to be our best, we embrace a culture of ownership and excellence that gives our teams the tools to grow and thrive as they shape their careers – and the Procore of tomorrow. To learn more about Procore and how you can build what comes next for your career, visit us at https://careers.procore.com/.

Why Work With Us

We make each other better at Procore. Here, your career is not pre-defined and it can take many paths. While you own your career, we provide you with the support and opportunities to help you succeed. You can help us transform an industry while you are transforming your career.

Gallery

Gallery

Similar Jobs

Hotman Group, LLC Logo Hotman Group, LLC

Experienced or Senior GRC Analyst

Information Technology • Consulting • Cybersecurity
In-Office
Fort Worth, TX, USA
14 Employees

BAE Systems, Inc. Logo BAE Systems, Inc.

EO/IR Pointing & Tracking - Systems Engineering Lead

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Hybrid
Austin, TX, USA
40000 Employees
150K-254K Annually

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Brook Meadows, Friendswood, TX, USA
16000 Employees
15-20 Hourly

Tapestry - Coach and Kate Spade Logo Tapestry - Coach and Kate Spade

Sales Associate III

eCommerce • Fashion • Retail • Sales • Wearables • Design
Hybrid
Brook Meadows, Friendswood, TX, USA
16000 Employees
15-20 Hourly

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account