Procore Technologies, Inc

Senior Analyst, GRC

Procore Technologies, Inc$111K — $153K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security risk management, GRC or cybersecurity with hands-on cloud experience.
  • Current AI fluency and ability to use LLMs for accurate outputs.
  • Strong attention to data quality and improvement processes.
  • Proficient in Jira and Google Workspace for daily tasks and reporting.
  • Proven collaboration skills with technical and business teams.
  • Ability to work autonomously in a fast-paced environment.
  • Familiarity with common security frameworks and ability to recommend controls.

Responsibilities

  • Manage the entire risk lifecycle including assessment and closure.
  • Map findings from various security assessments to overarching risks.
  • Align risks with mitigating controls and make recommendations for best practices.
  • Evaluate risks and configuration issues in cloud environments and summarize them.
  • Collaborate with various teams to validate risk severity and treatment plans.
  • Ensure the risk register is thorough and up to date.
  • Leverage AI tools to streamline risk assessment and reporting processes.

Benefits

  • Equity Compensation and/or Bonus Incentive Compensation may be offered.
  • Work in a collaborative and high-growth environment.
  • Opportunity for professional growth and development in GRC.
  • Autonomy in project management and decision making.
Full Job Description
We're looking for a highly motivated and detail-oriented Senior Cybersecurity Risk Analyst to join our Governance, Risk, and Compliance (GRC) organization. Focused on technical risk management, you'll be a key partner to security, engineering, IT, and business teams to assess and manage security risks across our information asset ecosystem.

This role is designed for a self-driven, critical thinker who views AI as a force multiplier. Our program tracks risks and exceptions: findings from pen tests, audits, and scans are grouped under the bigger risks they point to so we address the root cause, and escalated exceptions are tracked so items stay visible even when they're accepted. You won't just follow a risk manual, you'll use new technologies and tools to synthesize complex technical data, accelerate risk assessments, and provide the business with high-accuracy insights. You'll play a key role in the entire risk journey. This position reports to our Director, GRC.

WHAT YOU'LL DO:
  • End-to-End Risk Lifecycle Management: Manage individual risks end to end, including assessment, scoring, treatment tracking, risk acceptance, and closure. Apply qualitative methods and partner with GRC leadership to validate risk levels against appetite and set priority.
  • Issues/Findings-to-Risk Mapping: Bring findings from pen tests, audits, vulnerability scans, issue management, data protection, and configuration reviews onto the register. Combine related discoveries into root-cause risks with a treatment plan, and track severe accepted or untreated items as exceptions so they stay visible until the risk changes.
  • Risk-to-Control Mapping: Map each risk to the controls that mitigate it so that treatment plans, control gaps, and framework alignment (ISO/IEC 27001, SOC 2, NIST CSF / 800-53) all draw from the same picture. Recommend best-practice controls and treatment options where gaps exist.
  • Technical Risk Assessment: Evaluate risks and configuration issues across our cloud and SaaS ecosystem, including IAM, network security, vulnerability findings, and pen test results, and translate them into clear, actionable risk statements with defensible severity
  • Partnerships: You'll work directly with architects, engineering, Security, IT, system owners, and business stakeholders to validate severity, agree on treatment, and keep entries current.
  • Data Quality Ownership: Keep the risk register complete, current, consistent, and defensible. You'll catch stale entries, unclear ownership, and scoring drift before they reach a report.
  • AI-Powered Operations: Use AI tooling daily to accelerate risk statement drafting, evidence summarization, scenario modeling, and reporting, and look for new opportunities to automate manual GRC work.


WHAT WE ARE LOOKING FOR:
  • Experience: 6+ years in security risk management, GRC, or cybersecurity, with hands-on exposure to cloud environments. Demonstrated experience managing risk above the individual finding level, including aggregating related issues into broader risks, driving systemic treatment, and measuring residual risk.
  • The AI Edge: Current, hands-on AI fluency. You use LLMs in your daily work, can structure prompts that produce accurate and repeatable outputs, and understand failure modes like hallucination and data privacy well enough to know when to double-check results.
  • Data Quality Mindset: Strong attention to data quality. You spot stale records, inconsistent scores, and unclear ownership, and you improve the process that let them happen.
  • Tooling Fluency: Comfortable with Jira and Google Workspace (Sheets, Docs, Slides) as daily working tools, from running workflows in Jira to building analysis and reporting artifacts in Google.
  • Stakeholder Partnership: A track record of working well with technical and business teams, including engineers, offensive security, IT, and system owners, and building credibility with partners you don't have authority over.
  • Independent Contributor: We are a lean team, so you'll work with real autonomy. Proven ability to work independently, take ownership of tasks, prioritize effectively, and raise blockers early in a fast-moving environment with evolving architectures.
  • Technical Knowledge: Able to read network diagrams, vulnerability reports, and pen test findings, understand attack paths, and engage confidently with Security Architects and SecOps engineers. Working knowledge of cloud infrastructure security (AWS, GCP, or Azure) and at least one security framework (ISO 27001, SOC 2, or NIST CSF / NIST 800-53). You know common security controls well enough to recommend appropriate treatments based on best practice, even though deep implementation expertise sits with the engineering teams.
  • Communication: Strong writing and presentation skills, with the ability to explain technical issues to non-technical audiences and walk business stakeholders through risk data in live meetings.
  • Preferred
    • Experience in high-growth SaaS or cloud-native environments
    • Familiarity with DevOps and CI/CD security controls
    • Experience with modern GRC platforms and integrating AI tooling into daily workflows
    • Certifications such as CRISC, CISM, CISSP, or cloud provider certifications.


Additional Information

Base Pay Range:
111,760.00 - 153,670.00 USD Annual

This role may also be eligible for Equity Compensation and/or Bonus Incentive Compensation. Procore is committed to offering competitive, fair, and commensurate compensation. Actual compensation will be based on a candidate's job-related skills, experience, education or training, and location.

About Procore Technologies, Inc

About Procore

Revolutionizing Construction Management

Procore Technologies, founded in 2003 and headquartered in Carpinteria, California, stands at the forefront of construction management solutions. With a commitment to innovation and leadership in the field, Procore offers a comprehensive cloud-based platform designed to streamline construction projects.

A Global Presence

Boasting over 1.6 million users across more than 125 countries, Procore has cemented its reputation as a leader in the industry.

Legacy of Success

The company's rapid growth trajectory and substantial funding underline its impact and the trust it has garnered from leading construction firms worldwide.

Career Opportunities at Procore

A World of Opportunity

Procore's dynamic environment offers a plethora of opportunities for professionals passionate about making a difference in the construction industry.

Building Careers

With roles ranging from technical product management to software engineering, Procore is on the lookout for talent ready to contribute to its mission.

Job Application Process

Your Path to Procore

Navigating the application process at Procore is straightforward, emphasizing transparency and opportunity for all candidates.

How to Apply

Details on submitting your application, crafting your resume to stand out, and tips for preparing for the interview process can be found on Procore’s website.

Leading Roles at Procore

There are several different roles at Procore. Some of the high-paying roles such as Account Executive, Technical Product Manager, and Senior Full Stack Software Engineer promise not just rewards but a chance to contribute to significant projects.

Company Culture and Values

Innovation at Its Core

An exploration of Procore's dedication to innovation, teamwork, and leadership in the construction tech industry.

Cultivating Success Together

How collaboration and a shared vision of success drive Procore's team to new heights.

Benefits and Perks

Beyond the Basics

Procore offers a competitive benefits package, including health care, retirement plans, and work-life balance initiatives. Inquiry with Procore’s HR department for more details.

Training and Development Programs

Investing in Your Growth

Procore is committed to employee advancement through professional development opportunities and training programs.

Employee Testimonials

Real Stories of Advancement

For insights and real stories from current and past employees at Procore, visit their profile on Glassdoor.

Connect with Procore

Visit Procore’s website for more detailed information on how to reach Procore's HR team and inquire about available positions, the application process, and more.
Learn more about Procore Technologies, Inc
Size
2,000 employees
Market Cap
$6.5 billion
Industry
Founded
2002
NASDAQ

Similar Jobs

More Jobs at Procore Technologies, Inc

More Information Technology Jobs

Find similar Senior Analyst, GRC jobs: