Harness

Staff Security Analyst - GRC

Harness$160K — $190K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-10 years of experience in security, compliance, and GRC program management.
  • Expertise in commercial regulations and certifications like ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA.
  • Experience with GRC tools and automation in cloud environments (AWS, GCP, Azure).
  • Familiarity with federal compliance frameworks (NIST 800-53, FedRAMP, CMMC).
  • Strong project management skills and ability to handle multiple priorities effectively.
  • Excellent written and verbal communication skills for diverse stakeholder engagement.
  • Adaptable in fast-paced, ambiguous situations.

Responsibilities

  • Design and implement commercial compliance controls for various certifications.
  • Develop automation solutions for security compliance tasks and reporting.
  • Support federal compliance initiatives, including FedRAMP and CMMC frameworks.
  • Manage customer trust by reviewing contracts and security questionnaires.
  • Provide actionable security guidance for product and engineering projects.
  • Engage with external suppliers, auditors, and assessors for compliance management.
  • Identify and mitigate risks in compliance projects and vendor relationships.

Benefits

  • Comprehensive healthcare benefits including FSA options.
  • Flexible work schedules and Remote or Hybrid work available.
  • Employee Assistance Program for personal support.
  • Flexible Time Off and Parental Leave policies.
  • Participate in monthly, quarterly, and annual team-building events.
  • Monthly internet reimbursement to support remote work.
Full Job Description
Position Summary

A Staff Security Analyst will be a critical member of the GRC team working within the Information Security organization and across the business to advise, build, and operate security and compliance programs at scale. Utilizing in-depth expertise across multiple disciplines, you will be responsible for executing various components of Harness' security posture and overseeing end-to-end solutions to complex compliance problems.

As a Staff Security Analyst, you will lead security efforts to acquire and maintain crucial compliance certifications across Commercial sectors while assisting with Federal initiatives. You will design solutions that enable Harness' security goals and collaborate directly with business and engineering teams to preserve velocity while ensuring top-tier security. This role requires a strong core in Commercial Compliance mastery (SOC 2, SOC 1, ISO 27k, HIPAA, PCI), Customer Trust experience, and hands-on GRC Engineering and Automation capabilities, complemented by familiarity with Federal Compliance (FedRAMP, NIST 800-53).

About the role

  • Commercial Compliance Management: Design, implement, and continuously monitor commercial compliance controls, collaborating with engineering teams to ensure environments are properly scoped and secured for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA.
  • GRC Engineering & Automation: Develop and implement automation solutions to scale compliance tasks, automate control testing, integrate continuous compliance checks into the CI/CD pipeline, and streamline reporting.
  • Federal Compliance Support: Contribute to Federal compliance initiatives and frameworks (such as FedRAMP Moderate+, CMMC, DoD IL, and FedRAMP 20x) as Harness expands its public sector footprint.
  • Customer Trust & Advisory: Support customer trust initiatives by reviewing contracts for security and privacy requirements, completing detailed customer security questionnaires, and maintaining the customer trust portal.
  • Cross-Functional Collaboration: Contribute precise and actionable guidance to ensure security and privacy by design for engineering, product, and business initiatives.
  • Stakeholder Engagement: Manage relationships and facilitate engagement with external suppliers, auditors, assessors, and enterprise prospects.
  • Risk Management: Identify, track, and mitigate risks related to compliance projects, continuously monitor supply chain security, and manage vendor risk.
  • Evangelism: Articulate Harness's security capabilities and controls clearly to enterprise customers and regulatory auditors

About you

  • You have a minimum of 8-10 years of relevant industry experience in security, compliance, and GRC program management.
  • Extensive exposure to commercial industry regulations, frameworks, and compliance certifications (ISO 27001, SOC 1, SOC 2, PCI-DSS, HIPAA).
  • Previous experience with GRC tools and a demonstrated ability to build automation for security and compliance controls in a cloud-native environment (AWS, GCP, or Azure).
  • Working knowledge or exposure to Federal compliance frameworks (e.g., NIST 800-53, FedRAMP, CMMC) and are interested in expanding these programs.
  • You possess strong cybersecurity acumen and solid technical proficiency with enterprise SaaS applications and infrastructure.
  • Excellent project management and organizational skills, with the ability to handle multiple priorities and build new programs from scratch.
  • Clear, concise communication skills, both written and verbal, and can effectively partner with technical engineering teams as well as non-technical stakeholders.
  • You are comfortable navigating ambiguity and driving clarity in complex, fast-paced situations.
Bonus Points!
  • You have hands-on experience building, delivering, or managing a FedRAMP-compliant service offering (FedRAMP Moderate+) or achieving an ATO.
  • Familiarity with specialized defense/federal environments like Platform One, Iron Bank, CMMC, or DoD IL.
  • You are familiar with what is going on under the hood of the AWS or GCP console and can speak to best practices for configuration and management.
  • You hold relevant security or technical certifications (ISO 27001 Lead Implementer/Auditor, PCI QSA, CISA, CISSP, PMP, AWS/GCP Professional, or FedRAMP-specific credentials).
  • Previous experience assessing and utilizing AI in a secure environment.
  • You have exposure to or experience with Kubernetes, SBOMs, SLSA, and/or DLP.
  • You like to "automate the boring stuff" and are eager to share your knowledge with junior colleagues


Work Location
  • Remote within the U.S or Hybrid from one of our offices.
What you will have at Harness
  • Competitive salary
  • Comprehensive healthcare benefits
  • Flexible Spending Account (FSA)
  • Flexible work schedule
  • Employee Assistance Program (EAP)
  • Flexible Time Off and Parental Leave
  • Monthly, quarterly, and annual social and team building events
  • Monthly internet reimbursement


The anticipated base salary range for this position is between $160,000 and $190,000 annually. Salary is determined by a combination of factors including location, level, relevant experience, and skills. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. The compensation package for this position may also include equity, and benefits. More details about our company benefits can be found at the following link: https://www.harness.io/company/careers.

Pay transparency

$160,000-$190,000 USD

About Harness

Harness is a continuous delivery platform that helps businesses automate their software delivery processes. The platform offers a range of tools and services to help developers build, test, and deploy software more quickly and efficiently. Harness uses AI and machine learning to optimize the software delivery process, and provides analytics and insights to help teams identify and resolve issues more quickly. The company was founded in 2016 and is headquartered in Santa Clara, California.
Learn more about Harness
Size
500 employees
Industry
Founded
2015

Similar Jobs

More Jobs at Harness

More Information Technology Jobs

Find similar Staff Security Analyst - GRC jobs: