
Staff Security Analyst II (GRC)
About the role
Role: Staff Security Analyst II, GRC
Location: US Remote
Synonymous Business Title (s): Sr. Program Manager, Security
Overview:
Blue Yonder is a global leader in AI‑driven digital supply chain solutions, empowering businesses to optimize and transform their operations with innovative, intelligent technology. As we shape the future of global cybersecurity, our GRC team is seeking a talented Staff Security Analyst II, GRC.
This role will work across teams to ensure Blue Yonder product and internal processes are operating and managed with appropriate IT and security controls that meet regulatory, industry, and internal standards. This role partners with cross-functional teams to ensure controls are implemented and operating effectively and manage audit engagements.
What You’ll Be Doing:
Control Management:
Lead internal IT and security control assessments aligned with best practice standards and frameworks (ISO 27001/27701/22301, SOC1/2 Type II, etc.)
Identify control deficiencies and drive remediation activities with stakeholders
Support evidence collection and documentation of controls in support of internal and external audits
Regularly communicate compliance posture to stakeholders and leadership
Stay current with regulatory and security compliance standards and frameworks
Audit Readiness and Management:
Train and prepare control owners for audit participation and evidence collection
Plan, coordinate and manage internal and external audit activities including audit schedules and scope
Manage report reviews, respond to audit findings, and track remediation to closure
What We’re Looking For:
Required Qualifications
7 years of information security compliance or IT audit roles.
Strong understanding of IT and security control frameworks (ISO 27001, SOC1, SOC2).
Familiarity with cloud security practices and the shared responsibility model.
Must have experience performing end to end IT and Security control testing and remediation tracking.
Excellent communication and stakeholder management skills.
Strong analytical and problem-solving skills.
Preferred Qualifications
Certifications such as CISA, CISM, or CISSP (preferred but not required)
Experience working with AI Compliance frameworks such as ISO 42001.
Bachelor’s degree or equivalent in Information Systems, Cybersecurity, Business or related field
#LI-MH1
Compensation
This Security Engineer role pays $130k-$164k/yr. Within typical range for security engineer roles in United States.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.