Senior Security GRC Analyst

2 weeks ago


San Francisco, CA, United States Lambda Full time

Lambda, The Superintelligence Cloud, is a leader in AI cloud infrastructure serving tens of thousands of customers. Our customers range from AI researchers to enterprises and hyperscalers. Lambda's mission is to make compute as ubiquitous as electricity and give everyone the power of superintelligence. One person, one GPU.

If you'd like to build the world's best AI cloud, join us.

*Note: This position requires presence in our San Francisco or San Jose office location 4 days per week; Lambda's designated work from home day is currently Tuesday.

What You'll Do

  • Validate and verify the organization's security controls and practices meet the requirements of ISO 27001, 27701, PCI, SOC 2 and other relevant regulatory requirements to ensure alignment to business objectives
  • Manage IT Risk Register including risk identification, tracking, and prioritization.
  • Assist with and drive remediation of control deficiencies and gaps
  • Provide guidance to Control Owners in the planning, design, implementation, operation, maintenance & remediation of control activities and other supporting requirements (e.g. policies, standards, processes, system configurations, etc.)
  • Communicate with technical and non-technical stakeholders and leaders on cybersecurity risk and controls management topics and program-specific reporting
  • Assist with the Customer Trust program which may include managing customer assessments, and security questionnaires
  • Assist control owners with root cause analysis and track risk management action plan progress.
  • Create risk metrics for management regarding information security control maturity, compliance status, risks, performance and findings
    Assist with the third-party risk management assessment process, ensuring consistent enforcement of information security requirements
You
  • Have a minimum of 8 years of experience supporting cybersecurity risk or controls management programs with in-depth knowledge and experience of cybersecurity frameworks including ISO 27001 and 27701, PCI-DSS, SOC, NIST CSF and other regulatory requirements
  • Have experience managing and running audits, certification programs and control assessments. This includes but is not limited to scope planning, defining control procedures based on requirements, policies and standards, control testing, and mapping issues to risks
  • Have experience collaborating closely with engineers, business teams, and security partners, including incident response, red teams, and architects to seamlessly incorporate cybersecurity controls and risk management processes into their day-to-day operations
  • Possess a strong ability to define, drive and execute a program vision, strategy, approach and milestones in alignment with organization priorities and initiatives
Nice to Have
  • Experience in the machine learning or computer hardware industry
  • Experience with Security by Design and/or Privacy by Design principles
  • Experience with standard cyber controls frameworks, including CIS Top18, NIST Cyber Security Framework (CSF), NIST 800.53, NIST 800.171, CMMC, Cybersecurity Maturity Model Certification (CMMC), ISO 27001 and 27701, and SOX ITGC control frameworks.
  • Broad knowledge of IT infrastructure and architecture of computer systems as well as exposure to a variety of platforms such as operating systems, networks, databases, and ERP systems
  • Familiarity with using third-party tools such as Audit Board, Whistic, RSA Archer, ServiceNow for third-party risk management
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Experience in the AI infrastructure, machine learning and/or computer hardware industry
Salary Range Information

The annual salary range for this position has been set based on market data and other factors. However, a salary higher or lower than this range may be appropriate for a candidate whose qualifications differ meaningfully from those listed in the job description.

About Lambda
  • Founded in 2012, with 500+ employees, and growing fast
  • Our investors notably include TWG Global, US Innovative Technology Fund (USIT), Andra Capital, SGW, Andrej Karpathy, ARK Invest, Fincadia Advisors, G Squared, In-Q-Tel (IQT), KHK & Partners, NVIDIA, Pegatron, Supermicro, Wistron, Wiwynn, Gradient Ventures, Mercato Partners, SVB, 1517, and Crescent Cove
  • We have research papers accepted at top machine learning and graphics conferences, including NeurIPS, ICCV, SIGGRAPH, and TOG
  • Our values are publicly available: https://lambda.ai/careers
  • We offer generous cash & equity compensation
  • Health, dental, and vision coverage for you and your dependents
  • Wellness and commuter stipends for select roles
  • 401k Plan with 2% company match (USA employees)
  • Flexible paid time off plan that we all actually use

A Final Note:

You do not need to match all of the listed expectations to apply for this position. We are committed to building a team with a variety of backgrounds, experiences, and skills.

Equal Opportunity Employer

Lambda is an Equal Opportunity employer. Applicants are considered without regard to race, color, religion, creed, national origin, age, sex, gender, marital status, sexual orientation and identity, genetic information, veteran status, citizenship, or any other factors prohibited by local, state, or federal law.
  • GRC Analyst

    2 weeks ago


    San Francisco, CA, United States Insight Global Full time

    Pay Range: 45-55/hr+ About the Role Insight Global's client is searching for a GRC analyst to join their team. As a GRC Analyst, you will partner across the organization to strengthen our information security posture through governance, risk, and compliance (GRC). You will primarily support Sales teams by providing accurate, thoughtful responses to...

  • GRC Analyst

    2 weeks ago


    San Francisco, CA, United States Insight Global Full time

    Pay Range: 45-55/hr+ About the Role Insight Global's client is searching for a GRC analyst to join their team. As a GRC Analyst, you will partner across the organization to strengthen our information security posture through governance, risk, and compliance (GRC). You will primarily support Sales teams by providing accurate, thoughtful responses to...

  • GRC Analyst

    2 weeks ago


    San Francisco, CA, United States Insight Global Full time

    Pay Range: 45-55/hr+ About the Role Insight Global's client is searching for a GRC analyst to join their team. As a GRC Analyst, you will partner across the organization to strengthen our information security posture through governance, risk, and compliance (GRC). You will primarily support Sales teams by providing accurate, thoughtful responses to...

  • GRC Analyst

    7 days ago


    San Francisco, CA, United States Insight Global Full time

    Pay Range: 45-55/hr+ About the Role Insight Global's client is searching for a GRC analyst to join their team. As a GRC Analyst, you will partner across the organization to strengthen our information security posture through governance, risk, and compliance (GRC). You will primarily support Sales teams by providing accurate, thoughtful responses to...

  • GRC Analyst

    3 days ago


    San Francisco, CA, United States Insight Global Full time

    Pay Range: 45-55/hr+ About the Role Insight Global's client is searching for a GRC analyst to join their team. As a GRC Analyst, you will partner across the organization to strengthen our information security posture through governance, risk, and compliance (GRC). You will primarily support Sales teams by providing accurate, thoughtful responses to...


  • San Francisco, CA, United States DocuSign Full time

    Company Overview Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now,...


  • San Jose, CA, United States Cynet Systems Full time

    Job Description: Pay Range $98hr - $103.05hr Responsibilities: Support the GRC operating model and the service-oriented customer engagement model. Support GRC capabilities, such as enterprise security risk management, compliance and audit management, policy management, security awareness training, third party risk management, and metrics and...


  • San Jose, CA, United States Cynet Systems Full time

    Job Description: Pay Range $98hr - $103.05hr Responsibilities: Support the GRC operating model and the service-oriented customer engagement model. Support GRC capabilities, such as enterprise security risk management, compliance and audit management, policy management, security awareness training, third party risk management, and metrics and...


  • San Jose, CA, United States Cynet Systems Full time

    Job Description: Pay Range $98hr - $103.05hr Responsibilities: Support the GRC operating model and the service-oriented customer engagement model. Support GRC capabilities, such as enterprise security risk management, compliance and audit management, policy management, security awareness training, third party risk management, and metrics and...

  • Security GRC Manager

    6 hours ago


    San Francisco, CA, United States Plaid Full time

    We believe that the way people interact with their finances will drastically improve in the next few years. We're dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with...