Sr. GRC Specialist, Security Risk Management

HashiCorp
San Francisco, CA Full Time
POSTED ON 4/28/2024

About the team

As part of the Security organization and within the Governance, Risk and Compliance (GRC) department, the Security Risk team is responsible for security risk management at HashiCorp. The team defines the security risk management process, operationalizes it, manages risk pragmatically, and tracks and reports on security risk across HashiCorp. This includes both internal and third party vendor security risk.

We are looking for an experienced security risk manager who has done risk management at scale in a mature environment to join a new Security Risk team to help mature and operationalize the security risk management program at HashiCorp. This role is an opportunity to have direct and considerable impact on a newer risk management program from the ground up. This role will contribute to HashiCorp primarily by helping define the risk management framework and program, assessing risk, and tracking, reporting and communicating on security risk. This role will also spend some time on vendor security risk management, in particular helping better identify and articulate the security-related vendor risks to our products and services, as well as key business processes and data.

In this role, you will:

  • Help define and mature the internal and vendor security risk framework, program and processes
  • Help define, standardize, and educate stakeholders on risk taxonomy and nomenclature
  • Help define and continually improve risk scoring methodologies
  • Perform and facilitate internal and vendor security risk assessments
  • Review new risk submissions and facilitate its progress through the risk management process
  • Track progress against, follow up and report on risk treatment efforts
  • Maintain the security risk register
  • Track and report on risks to stakeholders across the company
  • Track and report on trends in security risk and threats
  • Define, track and report on KRIs
  • Help develop the HashiCorp Common Controls Framework
  • Help develop and contribute to quarterly and annual planning for the risk program
  • Track execution against OKRs and the risk program roadmap
  • Assist with other GRC activities as needed, including external security audits and other tasks as required

Must-Have Qualifications

  • 6 years of experience in risk management, with at least 3 in security risk management
  • Strong understanding of cloud, preferably AWS
  • Considerable hands-on experience with one or more risk management framework or standard (e.g., FAIR, ISO 31000 and 27005, RMF, etc)
  • Ability to ask the right questions and understand complex technical topics
  • Strong understanding of current cyber security threats and TTPs
  • Excellent written and verbal communication
  • Ability to prioritize and track multiple projects in parallel
  • Highly responsive and collaborative
  • Flexibility in daily hours (i.e., willingness to work longer hours during end of quarter, peak periods and audits)

Desired Qualifications

  • Previous experience at a technology or SaaS company in similar role
  • Experience with risk engineering and using data to make risk-informed decisions
  • Experience with quantitatively measuring security risks
  • Experience with risk management in other industries (e.g., finance, insurance, aerospace, etc)
  • Experience with risk management tooling and platforms

#LI-REMOTE

The base pay range for this role in the SF Bay Area / NYC area is:
$182,800-$215,000 USD
The base pay range for this role in Seattle Metro, Denver / Boulder Metro, New York (excluding NYC), Washington D.C., or California (excluding SF Bay Area) is:
$167,500-$197,100 USD
The base pay range for this role in Colorado (excluding Denver / Boulder Metro) and Washington (excluding Seattle Metro) is:
$152,300-$179,200 USD

ALERT: HashiCorp has received reports of scams where individuals purporting to represent HashiCorp conduct bogus "employment interviews" via email or text, and then request payment as a condition for receiving an offer of employment. HashiCorp and its subsidiaries do not conduct interviews by email or text, and will never request payment as a condition for applying for a position or receiving an offer of employment. These scam operators may also ask for your personal information (name, address, birthdate, social security number, etc.), which you should not provide to them. If you have been the target of such a scam, you should report it to the U.S. Federal Trade Commission (see this FTC posting for further details: https://www.consumer.ftc.gov/articles/job-scams) the office of your state Attorney General, or the government agency responsible for investigating matters such as this where you reside.


HashiCorp is proud to be an Equal Employment Opportunity employer. We are committed to providing equal employment opportunities to qualified applicants and do not discriminate on the basis of race, color, ancestry, religion, sex, pregnancy, gender, gender identity, gender expression, sexual orientation, national origin, age, marital status, genetic information, disability, protected veteran status or any other characteristic protected by federal, state, or local laws. We also consider qualified applicants with arrest and conviction records consistent with the San Francisco Fair Chance Ordinance, the Los Angeles Fair Chance Ordinance, and other applicable state or local laws.

 

Salary.com Estimation for Sr. GRC Specialist, Security Risk Management in San Francisco, CA
$108,036 to $157,350
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

Sign up to receive alerts about other jobs that are on the Sr. GRC Specialist, Security Risk Management career path.

Click the checkbox next to the jobs that you are interested in.

Income Estimation: 
$78,757 - $123,444
Income Estimation: 
$72,130 - $129,563
Income Estimation: 
$63,048 - $87,463
Income Estimation: 
$94,101 - $128,317
Income Estimation: 
$129,607 - $193,461
Income Estimation: 
$119,383 - $160,758
Income Estimation: 
$121,970 - $151,760
Income Estimation: 
$85,556 - $110,523

Sign up to receive alerts about other jobs with skills like those required for the Sr. GRC Specialist, Security Risk Management.

Click the checkbox next to the jobs that you are interested in.

  • Compliance Management Skill

    • Income Estimation: $75,283 - $99,371
    • Income Estimation: $76,148 - $102,051
  • Forecasting Skill

    • Income Estimation: $111,371 - $159,071
    • Income Estimation: $113,416 - $155,495
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at HashiCorp

HashiCorp
Hired Organization Address Atlanta, GA Full Time
Solutions Engineer About the role... As a Solutions Engineer at HashiCorp, you will work across the entire customer jour...
HashiCorp
Hired Organization Address San Francisco, CA Full Time
About the role Strategic Account Manager is an outside sales position responsible for developing, managing, and closing ...
HashiCorp
Hired Organization Address San Francisco, CA Full Time
Sr. Designer, Design Systems Location: US or Canada (Remote) Meet the Team As a member of the Design Systems team, you'l...
HashiCorp
Hired Organization Address Austin, TX Full Time
Solutions Engineer About the role... As a Solutions Engineer at HashiCorp, you will work across the entire customer jour...

Not the job you're looking for? Here are some other Sr. GRC Specialist, Security Risk Management jobs in the San Francisco, CA area that may be a better fit.

Safety & Risk Management Specialist

ESM INSITE, San Francisco, CA

Security GRC Analyst

Lambda, San Francisco, CA