7-9 years in GRC, security compliance, or IT audit.
Proven ownership of a security compliance program, ideally leading a company through its first SOC 2.
In-depth knowledge of SOC 2 and NIST CSF, including control mapping and audit mechanics.
Technical fluency to assess cloud configurations and access setups against controls.
Ability to create automation using scripts or AI tools.
Responsibilities
Build and manage Suno's security control framework, ensuring alignment with SOC 2 and NIST CSF.
Lead the end-to-end SOC 2 preparation process, including gap assessments and remediation efforts.
Automate evidence collection and control monitoring using scripts and AI tools.
Conduct vendor security reviews and maintain up-to-date security policies.
Collaborate with the CISO to provide leadership with a clear view of the security posture.
Foster trust with partners and customers to enhance Suno's reach in the music space.
Benefits
Opportunity to build a security compliance program from the ground up.
Direct reporting line to the CISO and involvement with leadership.
Work in a collaborative environment with AppSec and InfraSec teams.
Engagement in innovative automation and AI tools for security processes.
Chance to impact the security posture of a growing company.
Full Job Description
About the Role
We're looking for a Staff Security GRC Analyst to build Suno's security compliance program from the ground up. You'll report to our CISO, work alongside our AppSec and InfraSec teams, and own the control framework that ties everything together: which controls we have, how they map to SOC 2 and NIST CSF, and whether they actually work. You're as comfortable reading a cloud config as an audit standard, and you'd rather automate evidence collection with AI than chase screenshots. It's a greenfield build with real stakes and a direct line to leadership.
Listen to the song we made about it: https://suno.com/s/8U6fbhqLEghsnRsm
What You'll Do
Build and own Suno's security control framework, mapping controls to SOC 2, NIST CSF, and future frameworks, and writing control descriptions with the teams who run them.
Lead SOC 2 preparation end to end, from gap assessments and readiness tracking to driving remediation with control owners and working with our external auditor.
Automate evidence collection and control monitoring with scripts, integrations, and AI tools, deciding where human review stays in the loop.
Run vendor security reviews, keep our security policies current, and answer customer security questionnaires alongside Product and Legal.
Partner with the CISO to give leadership and the board a clear, evidence-backed view of our security posture, and lay the foundations of GRC as part of a growing Security team.
Help earn the trust of the partners and customers who bring Suno to more people, so creating music can be part of everyone's day.
What You'll Need Must-Haves
7-9 years in GRC, security compliance, or IT audit.
Hands-on, end-to-end ownership of a security compliance program as its primary owner, ideally including taking a company through its first SOC 2.
Deep working knowledge of SOC 2 and NIST CSF, including control mapping, audit mechanics (design vs. operating effectiveness, sampling, evidence), and staying current as requirements evolve.
Enough technical fluency to read a cloud configuration, access setup, or pipeline and judge whether it enforces what the control says. You don't need to write production code.
Comfort building your own automation with scripts or AI tools.
Nice-to-Haves
Experience standing up continuous controls monitoring or automated evidence collection, including what it covered and what changed as a result.
Experience applying LLMs to assurance work, such as control drafting, framework mapping, or evidence testing.
Experience with cloud environments such as AWS or GCP, and with a modern GRC platform.