Information Security GRC Analyst 4
$157,900–$228,575 year
On-siteSeattle, Washington, United States or San Jose, California, United States
Job Summary
Lead complex compliance and assurance programs from initiation through completion, driving planning, execution, issue management, and reporting while owning program outcomes with minimal strategic direction. Serve as the primary Tech GRC lead for internal readiness assessments, regulatory audits, certifications, and external assurance engagements, coordinating evidence collection, walkthroughs, testing activities, and auditor interactions. Independently manage relationships with partners up to the senior manager and director level, presenting risk assessments and program status to management audiences. Proactively identify risks, dependencies, and execution challenges, driving resolution plans and building trusted partnerships across Security, Engineering, Legal, Privacy, Product, HR, and external auditors. Develop deep expertise in multiple compliance frameworks, including Adobe's Common Controls Framework, and contribute to internal documentation, standards, training materials, and knowledge-sharing initiatives. Drive operational improvements that enhance efficiency, consistency, and audit readiness by building repeatable processes, templates, dashboards, and governance mechanisms.
Required Qualifications
- 5-8+ years of experience in Governance, Risk & Compliance (GRC), Information Security, Audit, Risk Management, or a related field
- Solid understanding of industry frameworks and standards such as SOC 1/2/3, ISO 27001, ISO 9001, ISO 42001, HIPAA, CSA STAR, FedRAMP, NIST, or similar regulatory and compliance requirements
- Experience driving multi-functional programs involving Security, Engineering, Product, Legal, Privacy, HR, and external auditors
- Strong executive communication and presentation skills, with the ability to translate technical and compliance concepts into clear business-focused recommendations
- Strong analytical, problem-solving, and organizational skills with exceptional attention to detail
- Ability to work effectively in ambiguous environments, exercise good judgment, and proactively identify and mitigate risks before they become critical issues
Desired Qualifications
- Experience leading large-scale assurance programs such as internal preparedness evaluations, enterprise audit portfolios, certification readiness initiatives, or regulated product onboarding efforts
- Familiarity with Adobe's Common Controls Framework (CCF) or similar enterprise control frameworks
- Experience managing external assessor relationships and leading customer-facing or regulator-facing audits
- Knowledge of cloud technologies (AWS, Azure, GCP), security technologies, and modern software development practices
- Demonstrated success mentoring junior team members and raising quality standards across a team or program
- Professional certifications such as CISA, CRISC, CISSP, CISM, ISO 27001 Lead Auditor, ISO 42001 Lead Implementer/Auditor, PCI ISA, or equivalent
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.