Diligent Corporation

Senior Staff GRC Analyst - Strategic Account Partner

Diligent Corporation$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in security GRC, customer assurance, or related role, with significant customer interaction experience.
  • Hands-on experience leading and defending security audits from both sides.
  • Deep knowledge of SOC 2 and ISO 27001, as well as related frameworks like NIST CSF and GDPR.
  • Technical proficiency in cloud architecture, encryption, and identity management.
  • Excellent written communication skills, particularly in control documentation for experts.
  • Strong interpersonal skills to engage with CISO-level executives and maintain effective relationships.
  • Proactive mindset focused on anticipating customer needs and preventing urgent issues.

Responsibilities

  • Own a portfolio of key accounts, serving as their primary security liaison with security and compliance teams.
  • Lead and manage customer security audits, including preparation and evidence collection.
  • Develop and upkeep an account security plan, detailing compliance frameworks and audit cycles.
  • Proactively monitor industry regulations and customer calendars to prepare necessary documentation.
  • Provide expertise for complex assurance tasks, including security questionnaires and vulnerability inquiries.
  • Collaborate with Sales and Customer Success to integrate security insights into the broader organizational strategy.

Benefits

  • Hybrid work model with a requirement of onsite presence for at least 50% of the time.
  • opportunities for professional development and certifications support.
Full Job Description
Most security assurance work is reactive: a customer asks, a team scrambles, an answer goes out. This role exists to end that cycle.

As a Senior Staff Analyst, you'll own a named portfolio of our most significant customers from a security perspective, and get ahead of what they need - their regulatory environment, their audit calendar, their risk appetite, their control expectations - well enough to have the evidence ready before the request arrives. You'll lead customer security audits hands-on, sit across from customer security teams as a peer rather than a form-filler, and build account security plans that make the next assessment predictable instead of painful.

This is deliberately a hands-on senior individual contributor role. You'll spend your time in audits, in customer conversations, and in the detail of controls and evidence - not in a management chain. If you've got deep SOC 2 and ISO 27001 knowledge, real technical range across cloud architecture, identity and vulnerability management, and the presence to hold a room with a sceptical CISO, this is a portfolio you can genuinely own.

Here's a breakdown of what you'll do (not all of it, just the important stuff):
  • Own a portfolio of strategic accounts as their dedicated security point of contact, building durable relationships with their security, risk, compliance and procurement teams.
  • Lead customer security audits and assessments hands-on - scoping, preparing evidence, running the sessions, defending control design and driving findings to closure with internal owners.
  • Build and maintain an account security plan for each account: their frameworks and regulators, audit and reassessment cycles, known concerns, open items and the roadmap commitments they care about.
  • Anticipate requirements before they're raised, tracking regulatory change, industry expectations and each account's compliance calendar so documentation and evidence are staged in advance.
  • Act as the escalation and expertise layer for complex assurance work - bespoke questionnaires, contractual security terms, incident and vulnerability inquiries, penetration tests and architecture-level questions.
  • Partner with Sales, Customer Success and Renewals as the embedded security resource, and feed what you learn back into the security and compliance roadmap, the shared answer library and trust site content.

These are the essentials you'll need to get an interview:
  • 5+ years in security GRC, customer assurance, security consulting, IT audit or a closely related function, with meaningful time spent customer- or client-facing.
  • Direct hands-on experience leading or defending security audits and assessments, on either side of the table.
  • Deep working knowledge of SOC 2 and ISO 27001, plus the adjacent expectations strategic customers raise - NIST CSF, GDPR, HIPAA, DORA and sector-specific requirements.
  • Genuine technical depth: you can discuss cloud architecture, encryption, identity, logging and vulnerability management with a customer's security engineers without taking every question away.
  • Excellent written communication, especially the ability to write precisely about controls for an expert audience.
  • The judgment and presence to hold a room with a sceptical CISO, say "we don't do that today, here's why and here's what we do instead," and keep the relationship intact.
  • A demonstrated bias toward anticipation over reaction - evidence you've built something that prevented fire drills rather than just handling them well.


It would be great if you had these to, but we'll support you if you don't:

  • Prior experience in a GRC analyst, customer security officer, or named account security or customer success role.
  • Experience in financial services, healthcare or the public sector, or supporting customers in heavily regulated industries.
  • Certifications such as CISSP, CISA, CRISC or ISO 27001 Lead Auditor.
  • Familiarity with trust center platforms and AI-assisted assurance tooling.
  • Experience in a multi-product SaaS environment where certifications and control boundaries differ by product.
  • Comfort with occasional travel for on-site customer audits and executive reviews.


Headquartered in New York, Diligent has offices in Washington D.C., London, Galway, Budapest, Vancouver, Bengaluru, Munich, Singapore and Sydney. To foster strong collaboration and connection, this role will follow a hybrid work model. If you are within a commuting distance to one of our Diligent office locations, you will be expected to work onsite at least 50% of the time. We believe that in-person engagement helps drive innovation, teamwork, and a strong sense of community.

About Diligent Corporation

Diligent Corporation is a software company that provides secure corporate governance and collaboration solutions for boards and senior executives. The company's solutions are used by over 19,000 organizations and 650,000 leaders in more than 90 countries. Diligent's products include Diligent Boards, a board portal that provides secure access to board materials and collaboration tools, and Diligent Messenger, a secure messaging and collaboration platform. Diligent Corporation was founded in 2001 and is headquartered in New York City. The company has offices in the United States, Canada, Europe, and Asia-Pacific. Diligent Corporation is a privately held company and is not traded on any stock exchange.
Learn more about Diligent Corporation
Size
2,000 employees
Industry

Similar Jobs

More Jobs at Diligent Corporation

More Information Technology Jobs

Find similar Senior Staff GRC Analyst - Strategic Account Partner jobs: