Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Harness

Staff Security Analyst – GRC

Harness

. Advise, build, and operate security and compliance programs at scale within the GRC team and Information Security organization .

Posted 9/21/2026full-timeRemote • United StatesLead💰 $150,000 - $164,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security and compliance program management, with a strong focus on implementing and monitoring compliance controls for various frameworks such as SOC 1, SOC 2, ISO 27001, and PCI-DSS. Proficient in building automation for compliance tasks in cloud-native environments and collaborating effectively with technical and non-technical stakeholders.

Highest-signal resume keywords
Security And Compliance Program ManagementCompliance Controls ImplementationAutomation In Cloud-Native EnvironmentsGRC Tools ExperienceStrong Cybersecurity Acumen

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
SOC 1SOC 2ISO 27001PCI-DSSHIPAANIST 800-53FedRAMPCMMCProject ManagementAutomation Development
Soft Skills
Clear CommunicationOrganizational SkillsCollaboration
Tools & Technologies
AWSGCPAzureEnterprise SaaS ApplicationsKubernetes
Certifications & Qualifications
ISO 27001 Lead Implementer/AuditorPCI QSACISACISSPPMP
Industry Keywords
GRCCompliance CertificationsSupply Chain SecurityVendor Risk ManagementFederal Compliance Initiatives

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityGoogle Cloud PlatformKubernetesPMP

About the role

Key responsibilities & impact
  • Advise, build, and operate security and compliance programs at scale within the GRC team and Information Security organization
  • Lead security efforts to acquire and maintain commercial compliance certifications while assisting with Federal initiatives
  • Design solutions that support Harness security goals and collaborate with business and engineering teams
  • Design, implement, and continuously monitor compliance controls for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA
  • Develop automation to scale compliance tasks, automate control testing, integrate continuous compliance checks into CI/CD pipelines, and streamline reporting
  • Contribute to Federal compliance initiatives involving FedRAMP Moderate+, CMMC, DoD IL, and FedRAMP 20x
  • Review customer contracts for security and privacy requirements
  • Complete customer security questionnaires and maintain the customer trust portal
  • Provide guidance for security and privacy by design across engineering, product, and business initiatives
  • Manage relationships with suppliers, auditors, assessors, and enterprise prospects
  • Identify, track, and mitigate compliance project risks
  • Monitor supply chain security and manage vendor risk
  • Explain Harness security capabilities and controls to enterprise customers and regulatory auditors

Requirements

What you’ll need
  • Minimum of 8–10 years of relevant industry experience in security, compliance, and GRC program management
  • Extensive exposure to commercial industry regulations, frameworks, and compliance certifications, including ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA
  • Experience with GRC tools
  • Ability to build automation for security and compliance controls in a cloud-native environment using AWS, GCP, or Azure
  • Working knowledge or exposure to Federal compliance frameworks such as NIST 800-53, FedRAMP, and CMMC
  • Strong cybersecurity acumen
  • Technical proficiency with enterprise SaaS applications and infrastructure
  • Project management and organizational skills
  • Clear written and verbal communication skills
  • Ability to partner with technical engineering teams and non-technical stakeholders
  • Hands-on experience building, delivering, or managing a FedRAMP-compliant service offering or achieving an ATO is a bonus
  • Familiarity with Platform One, Iron Bank, CMMC, or DoD IL is a bonus
  • Relevant security or technical certifications such as ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials are a bonus
  • Experience assessing and utilizing AI in a secure environment is a bonus
  • Exposure to Kubernetes, SBOMs, SLSA, and/or DLP is a bonus

Benefits

Comp & perks
  • Competitive salary
  • Comprehensive healthcare benefits
  • Flexible Spending Account (FSA)
  • Flexible work schedule
  • Employee Assistance Program (EAP)
  • Flexible Time Off and Parental Leave
  • Monthly, quarterly, and annual social and team building events
  • Monthly internet reimbursement
  • Equity may be included in the compensation package