Search jobs > San Francisco, CA > Grc analyst

Senior Principal GRC Analyst

Notion
San Francisco, California, US
$160K-$215K a year
Full-time

About Us :

Make sure to apply quickly in order to maximise your chances of being considered for an interview Read the complete job description below.

We're on a mission to make it possible for every person, team, and company to tailor their software to solve any problem and take on any challenge.

Computers may be our most powerful tools, but most of us can't build or modify the software we use on them every day. At Notion, we want to change this with focus, design, and craft.

We've been working on this together since 2016, and have customers like Pixar, Mitsubishi, Figma, Plaid, Match Group, and thousands more on this journey with us.

Today, we're growing fast and excited for new teammates to join us who are the best at what they do. We're passionate about building a company as diverse and creative as the millions of people Notion reaches worldwide.

Notion is an in person company, and currently requires its employees to come to the office for two Anchor Days (Mondays & Thursdays).

About The Role :

Millions of people use Notion and this number is increasing every day. Our users depend on us to deliver a secure, consistent, and trustworthy experience, and we value this more than anything.

We want to keep building on that trust, while also continuing to amaze our users with the tools they can build in Notion.

This is where you come in partnering with teams across the organization to envision, plan, and build Notion's Information Security posture for governance, risk, and compliance.

What You'll Achieve :

  • Helping build, mature, and scale our Security GRC program based on industry best practices for (some or all of) the following functions including Audit Management, Compliance Management, and Governance.
  • Working cross functionally to retain / achieve SOC2 Type II, ISO 27001, BSI C5, and planning for other new certifications that exhibit assurance internally and externally.
  • Tracking, remediating, and reporting on risks while overseeing risk reduction through the GRC system.
  • Driving annual and new hire staff training around Security GRC processes while building custom training to support policy enforcement.
  • Understanding what it takes to improve Information security policies, procedures, and standards for processes, applications, and infrastructure.

Skills You'll Need to Bring :

  • Security Assessment Expertise : You have experience working with various stakeholders to review and help improve their current processes through assessments or other tools.
  • Pragmatic and business oriented : You care about business impact and prioritize projects accordingly you understand the risks and balance the right security investments with the right bottom line outcomes.
  • Empathetic communication : You communicate nuanced ideas clearly, whether you're explaining compliance requirements in writing or brainstorming in real time.

When building consensus, you engage thoughtfully with other perspectives and compromise when needed.

Team player : For you, work isn't a solo endeavor. You enjoy collaborating cross functionally to accomplish shared goals, and you care about learning, growing, and helping others to do the same.

Nice to Haves :

  • You can explore new security threats, the technology controls, and the tactics required to mitigate those threats.
  • You've managed, maintained, and monitored systems like Compliance, Risk, and Security Training focused GRC tools.
  • You've been responsible for maintaining continuous controls and participating in audits in relation to our customer facing certifications (like SOC2).
  • You have been a partner to sales teams, in customer facing discussions, and can talk to customers about our security posture confidently.
  • You have been a partner to HR, engineering, and sales teams to build proposals for new compliance initiatives as well as build processes to enforce continuous compliance checks.
  • You have experience leading projects from start to finish across multiple teams and time zones.

We hire talented and passionate people from a variety of backgrounds because we want our global employee base to represent the wide diversity of our customers.

If you're excited about a role but your past experience doesn't align perfectly with every bullet point listed in the job description, we still encourage you to apply.

If you're a builder at heart, share our company values, and are enthusiastic about making software toolmaking ubiquitous, we want to hear from you.

Notion is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic.

Notion considers qualified applicants with criminal histories, consistent with applicable federal, state, and local law.

Notion is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures.

If you need assistance or an accommodation due to a disability, please let your recruiter know.

NYC + SF Roles

Roles without incentive compensation :

Notion is committed to providing highly competitive cash compensation, equity, and benefits. The compensation offered for this role will be based on multiple factors such as location, the role's scope and complexity, and the candidate's experience and expertise, and may vary from the range provided below.

For roles based in San Francisco or New York City, the estimated base salary range for this role is $160,000 $215,000 per year.

Notion is an in person company, and currently requires its employees to come to the office for two Anchor Days (Mondays & Thursdays) and requests that employees spend the majority of their week in the office (including a third day).

Notion reserves the right to adjust these requirements, and wants to ensure that you understand that we prioritize your presence for the magic of in person collaboration.

Notion will consider requests for accommodation to this policy, and, upon request, will work with employees to explore a reasonable accommodation for physical or mental disabilities or other reasons recognized by applicable law.

J-18808-Ljbffr

10 days ago
Related jobs
Promoted
Notion
San Francisco, California

Helping build, mature, and scale our Security GRC program based on industry best practices for (some or all of) the following functions including Audit Management, Compliance Management, and Governance. Tracking, remediating, and reporting on risks while overseeing risk reduction through the GRC sys...

Promoted
Kandji
San Francisco, California

The Senior GRC Analyst II will report to the Team Lead, GRC and work collaboratively with other departments across Kandji. Kandji is looking for a Senior Governance Risk and Compliance (GRC) Analyst II to add to our growing Security, IT and Trust teams. The GRC team is part of the Kandji Security an...

Promoted
Roblox
San Mateo, California

As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will support the implementation of our security governance program. This role will report to the GRC Manager. Partner with your GRC, InfoSec and Engineering colleagues and support the design and implementation of a “...

Promoted
Medallia, Inc.
San Francisco, California

A phenomenal opportunity exists within Medallia's Risk & Compliance Team as we are looking for a Senior Staff GRC (Governance, Risk, and Compliance) Analyst to drive compliance maturity and risk management in an ever-evolving SaaS landscape. ...

finra
San Francisco, California

The Senior Principal Analyst of the Strategic Metrics & Reporting (“Metrics”) team in FINRA’s Department of Enforcement is responsible for performing a wide variety of tasks in support of establishing and maintaining controls related to Enforcement’s production of internal and external reports, ...

Ontario Municipal Social Services Association
The College of Early Childhood Educators, CA

The Senior Data Analyst will work across all Departments at the College and with external partners. ...

Promoted
HashiCorp
San Francisco, California

We are looking for a cloud and DevOps savvy GRC Compliance Analyst II to support compliance enablement across HashiCorp product lines. Compliance Analyst II - Governance, Risk and Compliance. Leverage your technical expertise and deep understanding of the product to effectively collaborate with th...

Promoted
Hyundai Rotem USA
CA, United States

Support the Project Manager to develop and maintain customer relationships. Supports the Project Manager to identify and resolve issues/conflicts. Monitor, document, and report project progress (daily, weekly, monthly), including. Project time & schedule progress. ...

Promoted
Klimbnow
Oakland, California

We are seeking a motivated Junior Associate Data Architect (Data & Analytics) to join our team. Assist in reviewing and optimizing the Data Analytics architecture to enhance performance and data processing capabilities. Support the creation of dynamic environments for experimentation and innovation,...

Promoted
CGS Business Solutions | INC 5000 Company
CA, United States
Remote

This role requires an individual adept in all areas of cyber security, with particular skills in identifying, analyzing, and neutralizing advanced cyber threats, requiring proven experience with Azure and AWS cloud security. At least 3 years of experience in cybersecurity, with a significant focus o...