About the role
Who you are
- 4+ years experience in security governance, risk, compliance, audit, or security assurance roles
- Working knowledge of core security and compliance frameworks such as SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar
- Experience supporting audits, assessments, or control testing programs in a technology or SaaS environment
- Ability to write clear, practical, and actionable security policies, standards, and process documentation
- Experience maintaining risk registers and supporting formal risk assessment processes
- Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail
- Comfort working cross-functionally and gathering information or evidence from technical and non-technical stakeholders
- Strong written and verbal communication skills, including the ability to summarize risk and compliance issues clearly
- A pragmatic, collaborative mindset and a desire to help teams meet security requirements in a scalable way
- Bachelor’s degree in a relevant field such as Computer Information systems or Cybersecurity, or equivalent experience
- Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment
- Familiarity with security awareness program administration and reporting
- Experience performing or coordinating control testing mapped to recognized frameworks such as CIS Controls
- Knowledge of common enterprise security domains, including identity and access management, logging and monitoring, vulnerability management, endpoint security, and third-party risk
- Relevant certifications such as Security+, CISA, CRISC, CISSP, or similar are a plus
What the job involves
- Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively
- Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment
- The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessments
- Administer and maintain the security risk register, including tracking identified risks, updates, remediation activities, owners, and reporting outputs
- Partner with stakeholders across Security and the business to identify, document, assess, and monitor security risks
- Draft, review, update, and manage the lifecycle of security policies, standards, and supporting procedures
- Support the planning, coordination, evidence collection, and follow-up activities for Pinterest’s annual SOC 2 Type 2 audit
- Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions
- Execute security control testing activities aligned to CIS Controls and document testing outcomes, findings, and remediation recommendations
- Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders
- Help monitor control effectiveness and identify opportunities to improve process maturity, consistency, and evidence quality
- Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit, and awareness program status
- Support remediation tracking for control gaps, audit findings, and risk treatment actions
- Contribute to the continuous improvement of Pinterest’s GRC framework, documentation, and operating rhythms
- Maintain strong working relationships with internal partners to promote a practical, business-aligned approach to security governance and compliance
Millions of jobs, with real people getting hired every day
20,000+
New jobs added daily7,000,000+
Verified job listings500,000+
Tailored applications submittedFAQ
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at Pinterest was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
