Security GRC Analyst

PinterestSan Francisco, CA
Remote

About The Position

Pinterest's Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively. Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessments.

Requirements

  • 4+ years experience in security governance, risk, compliance, audit, or security assurance roles.
  • Working knowledge of core security and compliance frameworks such as SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar.
  • Experience supporting audits, assessments, or control testing programs in a technology or SaaS environment.
  • Ability to write clear, practical, and actionable security policies, standards, and process documentation.
  • Experience maintaining risk registers and supporting formal risk assessment processes.
  • Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail.
  • Comfort working cross-functionally and gathering information or evidence from technical and non-technical stakeholders.
  • Strong written and verbal communication skills, including the ability to summarize risk and compliance issues clearly.
  • A pragmatic, collaborative mindset and a desire to help teams meet security requirements in a scalable way.
  • Bachelor’s degree in a relevant field such as Computer Information systems or Cybersecurity, or equivalent experience.

Nice To Haves

  • Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment.
  • Familiarity with security awareness program administration and reporting.
  • Experience performing or coordinating control testing mapped to recognized frameworks such as CIS Controls.
  • Knowledge of common enterprise security domains, including identity and access management, logging and monitoring, vulnerability management, endpoint security, and third-party risk.
  • Relevant certifications such as Security+, CISA, CRISC, CISSP, or similar are a plus.

Responsibilities

  • Administer and maintain the security risk register, including tracking identified risks, updates, remediation activities, owners, and reporting outputs.
  • Partner with stakeholders across Security and the business to identify, document, assess, and monitor security risks.
  • Draft, review, update, and manage the lifecycle of security policies, standards, and supporting procedures.
  • Support the planning, coordination, evidence collection, and follow-up activities for Pinterest’s annual SOC 2 Type 2 audit.
  • Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions.
  • Execute security control testing activities aligned to CIS Controls and document testing outcomes, findings, and remediation recommendations.
  • Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders.
  • Help monitor control effectiveness and identify opportunities to improve process maturity, consistency, and evidence quality.
  • Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit, and awareness program status.
  • Support remediation tracking for control gaps, audit findings, and risk treatment actions.
  • Contribute to the continuous improvement of Pinterest’s GRC framework, documentation, and operating rhythms.
  • Maintain strong working relationships with internal partners to promote a practical, business-aligned approach to security governance and compliance.

Benefits

  • Flexibility to do your best work
  • Career opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service