- Страна
- США
- Зарплата
- 120 000 $ – 135 000 $
Откликайтесь
на вакансии с ИИ

GRC Risk Analyst
Высокий балл обусловлен прозрачной и конкурентной заработной платой, отличным пакетом льгот (включая акции и VTO) и репутацией Tanium как лидера в своей области. Позиция предлагает хорошие возможности для профессионального роста в среде AI и кибербезопасности.
Сложность вакансии
Роль требует 3-5 лет опыта и глубоких знаний специфических фреймворков (FedRAMP, ISO 27001). Основная сложность заключается в необходимости сочетать технический аудит с написанием политик и проведением интервью с техническим персоналом.
Анализ зарплаты
Предлагаемый диапазон $120,000 – $135,000 полностью соответствует рыночным ожиданиям для специалиста среднего уровня (Middle/Senior) в регионе Рестон/Вашингтон, округ Колумбия. Это конкурентоспособная зарплата для GRC-аналитика в крупной технологической компании.
Сопроводительное письмо
I am writing to express my strong interest in the GRC Risk Analyst position at Tanium. With over four years of experience in information security auditing and risk management within software engineering environments, I have developed a deep understanding of how to balance rigorous compliance requirements with the fast-paced needs of a technology-driven business. My background includes extensive work with frameworks such as SOC2, ISO 27001, and NIST CSF, which aligns perfectly with the standards Tanium upholds.
In my previous roles, I have successfully led end-to-end risk assessments, drafted comprehensive security policies, and managed complex vendor due diligence processes. I am particularly drawn to Tanium's mission of delivering Autonomous IT and believe that my analytical skills and experience in implementing Plan-Do-Check-Act methodologies will allow me to contribute immediately to your GRC team. I am confident that my ability to communicate technical risks to both engineering and executive stakeholders will support Tanium's continued growth and resilience.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в tanium уже сейчас
Присоединяйтесь к Tanium и станьте ключевым звеном в обеспечении безопасности ведущей платформы автономного ИТ!
Описание вакансии
The Basics
The ideal candidate demonstrates knowledge in information security, audit, risk management and continual improvement approaches. The GRC Risk Analyst conducts compliance assessments, develops policies and manages risks across Tanium. The GRC Risk Analyst works closely with stakeholders to ensure that the organization adheres to regulatory requirements and industry standards.
What you'll do
- Executes audits and risk assessments, communicates results of findings and makes recommendations for improvement through concise, high-quality reports
- Ensures company management is knowledgeable of the risks of noncompliance to information security standards and regulatory requirements
- Writes and revises policies, standards, procedures, guidelines and other documentation based on Tanium’s business needs
- Participates in Information Security, Information Technology and Product Security projects driving the implementation of new process improvements and risk treatments
- Works closely with Information Security, Information Technology, Product Security and System Owners to review and respond to security questionnaires and due diligence requests
- Assists in the assessment and review of new vendors to ensure adequate levels of controls are in place to maintain compliance with security requirements
- Prepares reports summarizing risk assessment findings and presents them to management
- Recommends changes in business processes or policies to manage risks
- Ensures compliance with regulatory requirements related to risk management
- Monitors risks, proposing preventive measures and solutions to prevent future risks
We’re looking for someone with
- Education
- Bachelor's Degree in Computer Science, Engineering or equivalent experience
- Experience
+ 3-5 years in information technology / information security auditing, preferably within a software engineering environment
+ Technical knowledge of fundamental audit and risk concepts within the context of information technology and information security
+ Familiarity with one or more of the following frameworks: FedRAMP, StateRAMP, CMMC, ISO 27001:2013, SOC2, NIST Cyber Security Framework (CSF)
+ Experience writing audit findings, reports, policies, standards, procedures and guidelines
+ Comfortable performing technical interviews with technical personnel and business process reviews with non-technical personnel
+ Working knowledge of risk assessment methodologies, contingency planning approaches, data analysis techniques and improvement tools including root cause analysis, corrective action, preventative action, Plan-Do-Check-Act and the cost of quality
+ Working knowledge of improvement programs such as Total Quality Management, ISO 9001, Six Sigma, Theory of Constraints or Lean
+ Experience managing projects, implementing change and tracking their implementation progress
+ Excellent knowledge of risk analysis methodologies and tools
+ Strong analytical and problem-solving skills
+ Proficiency in risk management software
About Tanium
Tanium is the Autonomous IT company. Driven by AI and real-time endpoint intelligence, Tanium Autonomous IT empowers IT and security teams to make their organizations unstoppable.
Many of the world’s leading organizations trust Tanium’s single, unified platform for endpoint management and security to innovate faster, stay resilient and move business forward with confidence, at scale. To learn how Tanium delivers Autonomous IT for unstoppable business – visit www.tanium.com and follow us on LinkedIn and X.
On a mission. Together.
At Tanium, we are stewards of a culture that emphasizes the importance of collaboration, respect, and diversity. In our pursuit of revolutionizing the way some of the largest enterprises and governments in the world solve their most difficult IT challenges, we are strengthened by our unique perspectives and by our collective actions.
As a global organization with stakeholders around the world, it’s imperative that the diversity of our customers and communities is reflected internally in our team members. We strive to create a diverse and inclusive environment where everyone feels they have opportunities to succeed and grow because we know that only together can we do great things.
Our commitment to excellence and innovation has earned us a place on the Forbes Cloud 100 list for ten consecutive years, and we continue to be recognized worldwide as a great place to work.
Each of our team members has 5 days set aside as volunteer time off (VTO) to contribute to the communities they live in and give back to the causes they care about most.
What you’ll get
The annual base salary range for this full-time position is $120,000 to $135,000. This range is an estimate for what Tanium will pay a new hire. The actual annual base salary offered may be adjusted based on a variety of factors, including but not limited to, location, education, skills, training, and experience.
In addition to an annual base salary, team members will receive equity awards and a generous benefits package consisting of medical, dental and vision plan, family planning benefits, health savings account, flexible spending account, transportation savings account, 401(k) retirement savings plan with company match, life, accident and disability coverage, business travel accident insurance, employee assistance programs, disability insurance, and other well-being benefits.
For more information on how Tanium processes your personal data, please see our Privacy Policy.
#LI-AO1
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- ISO 27001
- FedRAMP
- CMMC
- Risk Assessment
- Six Sigma
- SOC2
- Root Cause Analysis
- GRC
- Information Security Audit
- Lean
- NIST CSF
- Vendor Risk Management
- Policy Writing
- StateRAMP
Возможные вопросы на собеседовании
Проверка практического опыта работы с ключевыми стандартами, упомянутыми в вакансии.
Расскажите о вашем опыте подготовки организации к сертификации по стандарту ISO 27001 или SOC2. С какими основными трудностями вы столкнулись?
Оценка способности кандидата оценивать риски сторонних сервисов, что является важной частью обязанностей.
Каков ваш процесс оценки безопасности нового вендора? На какие критические контроли вы обращаете внимание в первую очередь?
Вакансия требует навыков написания документации и взаимодействия с разными отделами.
Как вы подходите к написанию политик безопасности, чтобы они были одновременно понятны сотрудникам и соответствовали строгим регуляторным требованиям?
Проверка аналитических способностей и владения методологиями улучшения процессов.
Можете ли вы привести пример использования анализа корневых причин (Root Cause Analysis) для решения выявленной проблемы в области безопасности?
Оценка навыков коммуникации и умения доносить важность комплаенса до технических специалистов.
Как вы ведете себя в ситуации, когда техническая команда сопротивляется внедрению нового контроля безопасности из-за его влияния на производительность?
Похожие вакансии
Специалист по защите информации (Mobile Security Engineer)
Senior Information Security (ИБ)
Senior Android Security / Reverse Engineer (HTTPS Traffic, Google Services)
Специалист по информационной безопасности (Пентестер)
Исследователь безопасности Android
Senior AppSecOps Engineer
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- США
- Зарплата
- 120 000 $ – 135 000 $