Senior Security GRC Analyst

Turo•San Francisco, CA
•$131,000 - $164,000•Hybrid

About The Position

Turo is searching for a highly motivated and versatile Senior Security GRC Analyst under the Enterprise Security team to lead security compliance programs as a senior individual contributor. This role carries primary ownership of SOC 2 Type II and PCI DSS audit readiness and coordination, and serves as the connective tissue between Engineering, IT, Finance, Legal, and business control owners. You will drive complex security compliance workstreams with limited oversight, exercising strong judgment and cross-functional influence to keep Turo audit-ready year-round.

Requirements

  • 5+ years in security compliance, GRC, or IT audit, with hands-on experience running security audit programs from start to finish.
  • Direct ownership of at least one full audit cycle under SOC 2 Type II and/or PCI DSS - from scoping through final report.
  • Demonstrated ability to coordinate evidence collection and remediation across multiple engineering and business teams with limited oversight.
  • Working knowledge of cloud security (AWS), IAM, and encryption frameworks - sufficient to assess controls and evaluate evidence critically.
  • Strong written and verbal communication skills; able to translate technical compliance requirements into clear guidance for non-security stakeholders.
  • Comfort operating independently in an ambiguous, fast-moving environment, managing competing deadlines without close supervision.
  • Bachelor's degree in Computer Science, Information Security, Information Assurance or equivalent practical experience.
  • Relevant certification: CISA, CISM, CISSP, or equivalent security certification.

Nice To Haves

  • Experience scaling a security compliance program through initial certification and into annual renewal cycles.
  • Familiarity with GRC tooling (e.g., Vanta, Drata, ZenGRC) and security-automation platforms.
  • Experience in a regulated or high-trust industry - fintech, marketplace, or SaaS handling sensitive personal or financial data.

Responsibilities

  • Own the compliance calendar and drive end-to-end audit readiness for SOC 2 Type II and PCI DSS, including scoping, control mapping, and continuous readiness between audit cycles.
  • Coordinate evidence collection across Engineering, IT, Finance, and business teams; track control owners and close gaps ahead of audit windows.
  • Serve as the primary day-to-day liaison with external auditors and assessors to manage requests, facilitate walkthroughs, and coordinate remediation of findings.
  • Maintain and evolve the common control framework: map controls across SOC 2, PCI DSS, and other applicable standards; identify and eliminate redundant testing where possible.
  • Lead compliance testing activities, document results, and maintain evidence repositories that support both internal review and external audit.
  • Track open audit findings and remediation commitments; provide status reporting to Security leadership and relevant stakeholders.
  • Manage the security exception process and document risk acceptances, obtain appropriate approvals, and monitor exceptions through expiration or remediation.
  • Identify control gaps proactively and partner with control owners to design and implement compensating or corrective controls.
  • Develop, maintain, and enforce security policies, standards, and procedures; keep them current with regulatory change and evolving business needs.
  • Partner with Legal on data-privacy obligations, subprocessor reviews, and breach-notification readiness.
  • Establish and report on compliance metrics - audit readiness scores, open findings aging, exception inventory, and cycle time - to drive accountability and visibility.
  • Identify and implement process and automation improvements that increase throughput and reduce manual effort across compliance workflows.

Benefits

  • Competitive salary, equity, benefits, and perks for all full-time employees
  • Employer-paid medical, dental, and vision insurance (Country specific)
  • Retirement employer match
  • Learning & Development stipend to invest in your professional development
  • Turo host matching program
  • Turo travel credit
  • Cell phone and internet stipend
  • Paid time off to relax and recharge
  • Paid holidays, volunteer time off, and parental leave
  • In-office lunch, office snacks, and fun activities for those who are in the office full-time or hybrid
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service