Auf einen Blick
- Aufgaben: Verwalte Sicherheitsrisiken und unterstütze die Sicherheitsgovernance bei Pinterest.
- Unternehmen: Pinterest, eine Plattform für kreative Ideen und Inspiration.
- Vorteile: Flexibles Arbeiten, wettbewerbsfähiges Gehalt und ein inklusives Arbeitsumfeld.
- Weitere Informationen: Möglichkeiten zur beruflichen Weiterentwicklung und Zusammenarbeit in einem dynamischen Team.
- Warum dieser Job: Gestalte die Sicherheitsstrategie eines innovativen Unternehmens und arbeite mit KI zusammen.
- Qualifikationen: Mindestens 4 Jahre Erfahrung in Sicherheitsgovernance oder Compliance-Rollen.
Das prognostizierte Gehalt liegt zwischen 123696 - 254667 € pro Jahr.
About Pinterest
Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime.
At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product.
Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work.
Creating a career you love?
It’s Possible.
At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that.
To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI.
Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think.
You can read more about our AI interview philosophy and how we use AI in our recruiting process here.
Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs.
This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively.
Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment.
The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessments.
What you’ll do
- Administer and maintain the security risk register, including tracking identified risks, updates, remediation activities, owners, and reporting outputs.
- Partner with stakeholders across Security and the business to identify, document, assess, and monitor security risks.
- Draft, review, update, and manage the lifecycle of security policies, standards, and supporting procedures.
- Support the planning, coordination, evidence collection, and follow-up activities for Pinterest’s annual SOC 2 Type 2 audit.
- Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions.
- Execute security control testing activities aligned to CIS Controls and document testing outcomes, findings, and remediation recommendations.
- Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders.
- Help monitor control effectiveness and identify opportunities to improve process maturity, consistency, and evidence quality.
- Prepare dashboards, reports, and presentations for leadership on risk, compliance, audit, and awareness program status.
- Support remediation tracking for control gaps, audit findings, and risk treatment actions.
- Contribute to the continuous improvement of Pinterest’s GRC framework, documentation, and operating rhythms.
- Maintain strong working relationships with internal partners to promote a practical, business-aligned approach to security governance and compliance.
What we are looking for
- 4+ years experience in security governance, risk, compliance, audit, or security assurance roles.
- Working knowledge of core security and compliance frameworks such as SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar.
- Experience supporting audits, assessments, or control testing programs in a technology or Saa S environment.
- Ability to write clear, practical, and actionable security policies, standards, and process documentation.
- Experience maintaining risk registers and supporting formal risk assessment processes.
- Strong organizational skills with the ability to manage multiple workstreams and deadlines with attention to detail.
- Comfort working cross-functional and gathering information or evidence from technical and non-technical stakeholders.
- Strong written and verbal communication skills, including the ability to summarize risk and compliance issues clearly.
- A pragmatic, collaborative mindset and a desire to help teams meet security requirements in a scalable way.
- Bachelor’s degree in a relevant field such as Computer Information systems or Cybersecurity, or equivalent experience.
Preferred qualifications
- Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment.
- Familiarity with security awareness program administration and reporting.
- Experience performing or coordinating control testing mapped to recognized frameworks such as CIS Controls.
- Knowledge of common enterprise security domains, including identity and access management, logging and monitoring, vulnerability management, endpoint security, and third-party risk.
- Relevant certifications such as Security+, CISA, CRISC, CISSP, or similar are a plus.
In-Office Requirement Statement
- We let the type of work you do guide the collaboration style.
That means we're not always working in an office, but we continue to gather for key moments of collaboration and connection.
- This role will need to be in the office for in-person collaboration 1-2 times/quarter and therefore can be situated anywhere in the country.
Relocation Statement
- This position is not eligible for relocation assistance. Visit our Pin Flex page to learn more about our working model.
- #LI-REMOTE
Our Commitment to Inclusion
Pinterest is an equal opportunity employer and makes employment decisions on the basis of merit.
We want to have the best qualified people in every job.
All qualified applicants will receive consideration for employment without regard to race, color, ancestry, national origin, religion or religious creed, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, age, marital status, status as a protected veteran, physical or mental disability, medical condition or genetic information or characteristics (or those of a family member) or any other consideration made unlawful by applicable federal, state or local laws.
We also consider qualified applicants regardless of criminal histories, consistent with legal requirements.
If you require a medical or religious accommodation during the job application process, please complete this form for support.
At Pinterest we believe the workplace should be equitable, inclusive, inspiring for every employee.
In an effort to provide greater transparency, we are sharing the base salary range for this position.
The position is also eligible for equity.
Final salary is based on a number of factors including location, travel, relevant prior experience, or particular skills and expertise.
Information regarding the culture at Pinterest and benefits available for this position can be found here.
- US based applicants only
- #J-18808-Ljbffr
Security GRC Analyst Arbeitgeber: Pinterest
Pinterest ist ein hervorragender Arbeitgeber, der Kreativität und Innovation fördert und seinen Mitarbeitern die Möglichkeit bietet, bedeutungsvolle Erfahrungen zu gestalten. Mit einem flexiblen Arbeitsumfeld, das persönliche Entwicklung und Zusammenarbeit in interdisziplinären Teams unterstützt, können Mitarbeiter ihre Fähigkeiten im Bereich Content Design weiterentwickeln und an spannenden Projekten arbeiten, die Millionen von Nutzern inspirieren. Die Unternehmenskultur legt Wert auf Vielfalt und Inklusion, was Pinterest zu einem attraktiven Arbeitsplatz für kreative Köpfe macht.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Security GRC Analyst erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Pinterest kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Pinterest zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Pinterest.
Wir glauben, dass du diese Fähigkeiten brauchst, um Security GRC Analyst mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei Pinterest vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Pinterest könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Pinterest sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird Pinterest auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!