Senior Staff GRC Analyst

Procore Technologies•Austin, TX
•$163,040 - $224,180•Onsite

About The Position

Procore Technologies is the leading technology partner for every stage of construction. We empower construction teams to drive efficiency and mitigate risk through actionable AI & data-driven insights. For over 20 years, we have been transforming the industry with purpose-built solutions for construction professionals and we are looking for talented people to help us build together. We are looking for a Senior Staff GRC Analyst to own Procore's Cyber Essentials and Cyber Essentials Plus certification program from end to end. As a Senior Staff GRC Analyst on our GRC team, you will be the program's hands-on owner and subject matter expert, working closely with IT, Security Engineering, and our external certification body to keep our controls audit-ready year-round and give our UK customers confidence that their project data is protected. Your strengths in security compliance program ownership, technical control validation, and influencing without authority will drive your success. You will report to the Senior Manager, GRC and will be based in our Austin office.

Requirements

  • 7+ years of experience in IT audit, GRC, security compliance, or security consulting, including end-to-end ownership of Cyber Essentials or Cyber Essentials Plus certifications.
  • Hands-on knowledge of endpoint and cloud security controls such as patch management, device configuration, and identity and access management, with experience validating them in tools like [Intune, Okta, AWS].
  • Familiarity with related frameworks such as ISO 27001, SOC 2, or NIST CSF, so you can connect Cyber Essentials to the rest of our control environment.
  • Proven ability to lead through influence rather than authority, driving action across IT, Security, and business teams.
  • Track record of independently planning and delivering compliance programs against firm external deadlines, because certification dates do not33 move.
  • Proficiency with GRC platforms for evidence collection and control tracking, and interest in automating manual compliance work.
  • Willingness to share your expertise and mentor other GRC analysts, raising the bar for the whole team.
  • Degree in IT, Computer Science, Cybersecurity, or a related field, or equivalent relevant work experience.

Nice To Haves

  • Certifications such as CISA, CISM, CISSP, or ISO 27001 Lead Auditor are a plus.

Responsibilities

  • Own the annual Cyber Essentials Plus certification cycle end to end, from scoping and self-assessment through independent technical verification and renewal.
  • Define and maintain the certification scope across devices, networks, cloud services, and user accounts.
  • Validate the five technical controls (firewalls, secure configuration, user access control, malware protection, and security update management) hands-on, partnering with IT and Security teams on design and operation.
  • Drive remediation of control gaps by aligning with control owners on root cause and practical corrective actions.
  • Serve as the primary contact for our certification body, coordinating assessments, evidence requests, and technical testing.
  • Align Cyber Essentials with our broader compliance programs, such as ISO 27001 and SOC 2, to cut duplicate testing and evidence requests.
  • Improve the program over time through automation, continuous control monitoring, and cleaner evidence processes.
  • Report program status, risks, and readiness to leadership, turning technical detail into clear decisions and escalating when needed.

Benefits

  • Equity Compensation
  • Bonus Incentive Compensation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service