You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Yahoo

Paranoids Senior Security GRC Analyst

  • Hybrid
  • 6+ years

Salary

$128,250+/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions and powerful data to engage with our brands and deliver results.

A Little About Us

When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo, known as "The Paranoids."

Within the Paranoids, the Cyber Risk team exists to guide Yahoo to make reasonable, compliant, cyber risk-conscious decisions. We position security as a business advantage - surfacing actionable cyber risks, facilitating executive risk decisions, and ensuring that security and compliance are aligned with company goals.

A Lot About You

We are looking for a Senior Security GRC Analyst to join the team. This role sits at the intersection of three critical GRC functions: exception management, security risk assessment, and policy and standards management.

You will work directly with business leaders, engineers, and Paranoids security teams to identify, assess, document, and communicate security risks - and then help the organization make informed decisions about them. Some days that means writing a risk evaluation memo that goes to the CISO. Other days it means assessing a property's security posture against Paranoids policy, drafting a new standard, or working through the nuances of an exception request with a business unit that's navigating a hard tradeoff.

We operate in a modern, fast-moving security landscape. We view AI as a force multiplier that allows us to scale governance, synthesize complex technical data faster, and deliver higher-impact risk insights. The work requires that you understand enough about technology to ask the right questions, exercise sound judgment when evaluating AI-generated outputs, and understand enough about the business to frame risk in terms that drive good decisions.

Responsibilities

  • Evaluate and document known security risks for executive review, ensuring risks are described clearly, contextualized for impact, and paired with actionable treatment options.
  • Manage the end-to-end lifecycle of risk exceptions from intake and evaluation through decision, documentation, and periodic reassessment across Yahoo properties.
  • Conduct property-level and initiative-level security risk assessments against Paranoids policies, industry frameworks, and modern architecture patterns.
  • Draft, revise, and maintain security policies and standards that set clear, realistic expectations across engineering and product teams.
  • Partner with stakeholders across the business to socialize new or updated standards, gathering input and building cross-functional alignment before publication.
  • Act as a trusted liaison between business teams, engineering, and security - translating technical security concepts for non-technical stakeholders and ensuring business context informs risk decisions.
  • Identify and implement AI-assisted workflows and automation to eliminate manual GRC tasks, and streamline security exception and policy reviews
  • Basic Qualifications
  • 5+ years of experience in security governance, risk management, compliance, or a related information security discipline within modern technology environments.
  • Demonstrated experience conducting comprehensive security risk assessments and communicating actionable findings to senior leadership and technical teams.
  • Strong written and verbal communication skills - proven ability to write an executive-ready risk memo, present to leaders, and collaborate effectively with software and infrastructure engineers.
  • Working knowledge of security frameworks and risk methodologies (e.g., NIST CSF, ISO 27001, FAIR) and how they apply to real-world cloud infrastructure, web applications, and identity systems.
  • Proven experience developing or managing security policies, standards, or exception/risk acceptance governance programs.
  • Demonstrated experience using generative AI tools (e.g., Claude, ChatGPT, Gemini, Copilot) to accelerate daily productivity—including drafting documentation, structuring risk analyses, or automating repetitive research workflows.
  • Strong critical evaluation skills with the ability to exercise judgment in when to apply AI tools versus manual review, paired with an understanding of AI data confidentiality and risk governance.
  • Understanding of regulatory and compliance frameworks applicable to global technology organizations (e.g., SOC 2, PCI DSS, GDPR).
  • Track record of continuous process improvement—having established or meaningfully upgraded an assessment program, policy lifecycle, or risk tracking mechanism.
  • Preferred Qualifications
  • Experience working within an information security organization at a large-scale consumer technology or cloud enterprise.
  • Experience utilizing GRC platforms or risk workflow platforms (e.g., ServiceNow GRC, Archer, Jira) with an interest in configuring automated workflows.
  • Familiarity with emerging risk domains, including AI/ML security governance
  • Professional security certifications such as CRISC, CISSP, CISA, or CISM.
  • The material job duties and responsibilities of this role include those listed above as well as adhering to Yahoo policies ; exercising sound judgment ; working effectively, safely and inclusively with others ; exhibiting trustworthiness and meeting expectations ; and safeguarding business operations and brand integrity.
  • At Yahoo, we offer flexible hybrid work options that our employees love! While most roles don’t require regular office attendance, you may occasionally be asked to attend in-person events or team sessions. You’ll always get notice to make arrangements. Your recruiter will let you know if a specific job requires regular attendance at a Yahoo office or facility. If you have any questions about how this applies to the role, just ask the recruiter!
  • We believe that a diverse and inclusive workplace strengthens Yahoo and deepens our relationships. When you support everyone to be their best selves, they spark discovery, innovation and creativity. Among other efforts, our 11 employee resource groups (ERGs) enhance a culture of belonging with programs, events and fellowship that help educate, support and create a workplace where all feel welcome.
  • The compensation for this position ranges from $128,250.00 - $266,875.00/yr and will vary depending on factors such as your location, skills and experience.The compensation package may also include incentive compensation opportunities in the form of discretionary annual bonus or commissions. Our comprehensive benefits include healthcare, a great 401k, backup childcare, education stipends and much (much) more.
  • Currently work for Yahoo? Please apply on our internal career site.

Where you’d work

Part of the week in the office

You can work from

  • United States

About the company

Yahoo

Office in United States

Also hiring in Ireland

Your chances

Worth a look before you spend an evening tailoring a CV for it.

  • 21 checks run
  • 3 red flags

Still hiring?

14 checks

2 red flags

How crowded?

7 checks

1 red flag

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details11 facts · Role, Location, Compensation, Employment
Seniority
Senior
Type
Full-time
Specialty
Security
Region
United States
Pay period
Annual
Show 6 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
5+ years

Location

Work model
Hybrid
Region
United States
Office
  • United States
Remote from
  • United States

Compensation

Salary
$128,250+ / year
Pay period
Annual

Employment

Type
Full-time

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason