Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Analyst (GRC Specialist) image - Rise Careers
Job details

Security Analyst (GRC Specialist)

Our Story So Far


Since our founding in 2019, Pigment has become one of the fastest-growing SaaS companies in the world today. Our product, a highly efficient Enterprise Performance Management (EPM) platform, is helping companies achieve their financial goals by quickly responding to dynamic factors in their respective markets including Tech, Retail, CPG & Financial Services. 


In less than 5 years, Pigment has grown to over 450 employees across offices in New York, Toronto, London & Paris and attracted a total of $393M in investment from some of the top Venture Capital firms globally.

We serve companies including Unilever, Deliveroo, Gong and Brex to name a few!


We are looking for a Governance, Risk and Compliance specialist, whose core focus will be to protect our customers' and compliance data.


Key Responsibilities
  • Strategic Leadership

  • Under the coordination of the CISO, participate in the definition of a multi-year, risk-driven security roadmap, design policies, processes and guidance documents driving its implementation

  • Implementing the security roadmap, either autonomously or with support from other engineering teams, either in a delivery or project management capacity, depending on the project’s technical requirements.

  • Establish and implement company-wide security policies and procedures covering internal IT, production platforms, facilities, and more.

  • Improve and maintain the risk analysis and its mitigation planDesign and implement a comprehensive reporting framework of security indicators

  • Operational Excellence

  • Drive implementation of the security roadmap, leading initiatives and coordinating with engineering teams or other relevant stakeholders (legal, HR, support, customer experience

  • Oversee vulnerability remediation, including triage, prioritization, and mitigation follow up.

  • Oversee vendor security assessments and ensure alignment with compliance requirements, deliver security approvals in the procurement process

  • Participate in the asset management program (contractors, accounts, datasets, etc.) 

  • Compliance Management

  • Lead certifications renewals for SOC 1, SOC 2, and contribute to acquisition of new certification (e.g., ISO 27001, ISO 27701)

  • Lead planning and execution of compliance audit programs conducted both internally and externally.

  • Maintain and enhance compliance programs, collaborating cross-functionally to ensure adherence.

  • Coordinate with the Sales and Legal teams to understand the legislative landscape and market requirements in terms of compliance.

  • Advocacy and Training

  • Design and implement security awareness training programs and champion best practices across teams (onboarding training, awareness training, phishing simulations, developer trainings)


Experience & Expertise
  • At least 5 years of experience on governance and compliance topics, either as Security Engineer, Security Project Manager, or compliance officer (of course, you can be way more experienced!)

  • Extensive knowledge and experience with the ISO27000 series standard:  implementation experience in obtaining and maintaining is a plusSolid technical background in security engineering

  • Great team spirit with a problem-solving, can-do attitude.

  • Good dose of humility and the willingness to grow (no matter your seniority!).

  • Fluent in English (French is not mandatory!).


Environment
  • The scope of this role includes both the production environment and internal IT
  • Sites in Paris, London, Toronto and NYC 
  • MacOS, Windows, Linux
  • GCP, Kubernetes, Terraform, Postgres, SingleStore, Vault
  • Okta, Oauth, JWT, C#, .NET Core, TypeScript, React
  •  Vanta (GRC), Riot (awareness), Google Workspace (office), Jumpcloud (MDM and SSO), Hibob (HRIS), Slack (IM), GitHub (VCS), CircleCI / ArgoCD (CI/CD) HackerOne (Bug Bounty program), Datadog (SIEM), 1Password (password manager)


€60,000 - €80,000 a year
- Competitive salary
- Equity
- The best health insurance with Alan Blue entirely free for you and your family 💙
- Trust and flexible working hours
- Brand new offices in the heart of Paris, London, New York and, Toronto
- Remote-friendly environment

Pigment is an equal opportunity employer. We believe diversity is a strength and fosters innovation. We are committed to enabling everyone to feel included and valued at the workplace.  All qualified applicants will receive consideration for employment without regard to age, color, family, gender identity, marital status, national origin, physical or mental disability,  sex (including pregnancy), sexual orientation, social origin, or any other characteristic protected by applicable laws. We may process your personal data in accordance with our HR Data Protection Notice.

Pigment Glassdoor Company Review
4.6 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Pigment DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Pigment
Pigment CEO photo
Romain Niccoli, Eléonore Crespo
Approve of CEO

Average salary estimate

$70000 / YEARLY (est.)
min
max
$60000K
$80000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Analyst (GRC Specialist), Pigment

Are you ready to elevate your career as a Security Analyst (GRC Specialist) at Pigment? Based in the vibrant cities of London or Paris, you'll join one of the fastest-growing SaaS companies in the world, with a mission to help organizations reach our financial goals through our innovative Enterprise Performance Management (EPM) platform. With a passionate team of over 450 experts across our offices – from New York to Toronto – Pigment has made significant waves, serving renowned clients like Unilever and Deliveroo. As a Security Analyst, you'll play a vital role in safeguarding our customers' data by developing and implementing a comprehensive risk-driven security roadmap. Collaborating closely with the CISO, you’ll design policies and procedures that enhance our security posture across production environments and internal IT. Your efforts will include overseeing vulnerability assessments, managing compliance protocols, and championing security awareness through effective training programs. Moreover, your expertise in governance and compliance will be crucial in leading our SOC certifications and enhancing compliance initiatives across the organization. At Pigment, we value your experience, passion, and problem-solving spirit, ensuring you grow within an inclusive environment. Join us in shaping a more secure future!

Frequently Asked Questions (FAQs) for Security Analyst (GRC Specialist) Role at Pigment
What skills do I need to become a Security Analyst (GRC Specialist) at Pigment?

To excel as a Security Analyst (GRC Specialist) at Pigment, you should ideally have at least 5 years of experience in governance and compliance domains, with a strong foundation in security engineering. A deep understanding of ISO27000 series standards and experience with vulnerability assessments and compliance audits are essential. Your ability to collaborate with various teams and communicate effectively will greatly benefit you in this role. Familiarity with GCP, Kubernetes, and security tools will also be advantageous.

Join Rise to see the full answer
What does the role of Security Analyst (GRC Specialist) at Pigment entail?

As a Security Analyst (GRC Specialist) at Pigment, you will be responsible for safeguarding customer and compliance data while developing and implementing a multi-year security roadmap under the guidance of the CISO. You'll manage security policies, coordinate with engineering teams, and lead compliance programs. This role also involves training team members on security best practices and ensuring alignment with legal and compliance requirements as the company scales.

Join Rise to see the full answer
What are the career growth opportunities for Security Analysts at Pigment?

At Pigment, as a Security Analyst (GRC Specialist), you will have ample opportunities for career development. You’ll engage in strategic security initiatives that position you as a key player in the organization. You can grow your skills and portfolio through exposure to cutting-edge technologies and collaboration with talented professionals. Furthermore, our commitment to training and inclusivity fosters personal and professional growth, allowing you to move into more senior roles or specialized areas of security.

Join Rise to see the full answer
How does Pigment foster diversity and inclusion for its employees?

Pigment deeply values diversity and inclusion, recognizing these aspects as crucial for innovation and growth. We actively promote an inclusive workplace that welcomes individuals from all backgrounds. Regardless of age, gender identity, nationality, or other characteristics, every candidate will be given fair consideration for employment. Our team is committed to ensuring that all employees feel valued, respected, and empowered to contribute to our success.

Join Rise to see the full answer
What is the work culture like at Pigment for Security Analysts?

The work culture at Pigment for Security Analysts is characterized by collaboration, innovation, and a supportive environment. Our focus on trust and flexibility allows you to manage your time effectively while contributing to meaningful projects. As a Security Analyst at Pigment, you'll work alongside a diverse, talented team, engage in continuous learning, and share your ideas openly, all in an atmosphere that values your contributions and promotes professional growth.

Join Rise to see the full answer
What are the primary compliance certifications required for the Security Analyst (GRC Specialist) at Pigment?

As a Security Analyst (GRC Specialist) at Pigment, you will be involved in maintaining key compliance certifications such as SOC 1, SOC 2, and potentially ISO 27001 and ISO 27701. These certifications ensure that we meet industry standards for data security and privacy. Your expertise will be essential in leading certification renewals, conducting compliance audits, and ensuring that our practices align with evolving legal and market demands.

Join Rise to see the full answer
What technologies will I work with as a Security Analyst (GRC Specialist) at Pigment?

In the role of Security Analyst (GRC Specialist) at Pigment, you will work with a variety of technologies that enhance our security posture. Some of the tools include Google Cloud Platform (GCP), Kubernetes, Terraform, and different security management platforms like Vanta. Your work will involve collaborating on internal IT security, implementing security indicators, and managing identity and access using tools like Okta, ensuring that our systems remain robust and secure.

Join Rise to see the full answer
Common Interview Questions for Security Analyst (GRC Specialist)
What experience do you have with governance and compliance in security?

In answering this question, elaborate on your previous roles managing compliance frameworks, handling governance audits, and what specific standards you’ve worked with, like ISO27000 series. Provide examples of how you navigated challenges and improved compliance processes, emphasizing measurable results.

Join Rise to see the full answer
How do you approach vulnerability management?

Explain your systematic approach to vulnerability management, detailing how you identify, assess, and prioritize vulnerabilities. Discuss the tools and methods you use for risk assessment, and describe your process for tracking remediation efforts and the importance of collaboration with engineering teams.

Join Rise to see the full answer
Can you outline your experience with compliance audits?

Share your experiences with compliance audits, emphasizing the specific audits you have led or participated in, such as SOC 1, SOC 2, or ISO standards. Provide insights into how you prepared for these audits, what documentation you managed, and any positive outcomes, such as certifications obtained or compliance gaps successfully addressed.

Join Rise to see the full answer
What security awareness programs have you developed?

Discuss specific security awareness programs you have created or implemented, highlighting the goals, content, and methods used to engage team members. Consider including examples of training sessions, phishing simulations, and how you've measured the impact of these programs on organizational security posture.

Join Rise to see the full answer
How would you handle a security incident?

Outline your incident response protocol, covering preparation, detection, containment, eradication, and recovery stages. Discuss any relevant tools you might use and the importance of communication with stakeholders and documentation throughout the incident process to ensure lessons are learned for future improvement.

Join Rise to see the full answer
What methodologies do you use for risk assessment?

In your response, describe the methodologies you prefer for conducting risk assessments, such as qualitative versus quantitative methods. Detail how you gather information, evaluate potential threats, and determine impacts on business operations, while emphasizing your analytical skills and attention to detail.

Join Rise to see the full answer
How do you stay updated on the latest security threats and compliance regulations?

Emphasize your commitment to continuous learning and professional development in cybersecurity. Mention subscriptions to reputable security blogs, attending webinars, joining professional networks, and certifications you hold or aspire to. Highlight how this knowledge translates into actionable strategies for your role.

Join Rise to see the full answer
Why do you want to work at Pigment?

Articulate genuine reasons for your interest in Pigment, such as admiration for the company's growth, commitment to innovation, and its diverse and inclusive culture. Connect your personal values and professional goals to the company's mission and explain how you can contribute to its success.

Join Rise to see the full answer
Explain how you prioritize tasks in a multi-project environment.

Detail your approach to time management and prioritization, especially in fast-paced environments with multiple projects. Consider discussing techniques such as the Eisenhower Matrix or the use of project management tools to balance urgency and importance effectively.

Join Rise to see the full answer
Can you describe your experience working with cross-functional teams?

Discuss your history of collaborating with various departments, such as legal, HR, and engineering. Highlight how you effectively communicate security needs and compliance requirements across teams, ensuring that different perspectives are integrated into achieving common goals.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
CLEAR - Corporate Remote New York, New York, United States
Posted 6 days ago
Photo of the Rise User
Posted 14 days ago
Photo of the Rise User
Praetorian Remote Remote within United States, Canada
Posted 12 days ago
Photo of the Rise User
Telos Corporation Hybrid Joint Base Andrews, MD
Posted 6 days ago
Photo of the Rise User
Posted 24 hours ago
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Maternity Leave
Paternity Leave
401K Matching
Paid Holidays
Paid Sick Days
Paid Time-Off
Paid Volunteer Time
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Family Coverage (Insurance)
Medical Insurance
Mental Health Resources
Photo of the Rise User
AECOM Remote Albuquerque, NM, United States
Posted 8 days ago
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Future Maker
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
November 29, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!