About the Role
This role focuses on technical risk management within the Governance, Risk, and Compliance (GRC) organization. You will partner with security, engineering, IT, and business teams to assess and manage security risks across the company's information asset ecosystem, utilizing AI as a force multiplier to synthesize complex data and provide high-accuracy insights.
Responsibilities
- Manage individual risks end to end, including assessment, scoring, treatment tracking, risk acceptance, and closure.
- Apply qualitative methods and partner with GRC leadership to validate risk levels against appetite and set priority.
- Map findings from pen tests, audits, vulnerability scans, issue management, data protection, and configuration reviews onto the register.
- Combine related discoveries into root-cause risks with a treatment plan, and track severe accepted or untreated items as exceptions.
- Map each risk to the controls that mitigate it, ensuring alignment across treatment plans, control gaps, and frameworks (ISO/IEC 27001, SOC 2, NIST CSF / 800-53).
- Recommend best-practice controls and treatment options where gaps exist.
- Evaluate risks and configuration issues across cloud and SaaS environments, including IAM, network security, vulnerability findings, and pen test results.
- Translate technical findings into clear, actionable risk statements with defensible severity.
- Work directly with architects, engineering, Security, IT, system owners, and business stakeholders to validate severity, agree on treatment, and keep entries current.
- Ensure the risk register is complete, current, consistent, and defensible by identifying and addressing stale entries, unclear ownership, and scoring drift.
- Utilize AI tooling daily to accelerate risk statement drafting, evidence summarization, scenario modeling, and reporting.
- Identify new opportunities to automate manual GRC work.
Requirements
- 6+ years in security risk management, GRC, or cybersecurity, with hands-on exposure to cloud environments.
- Demonstrated experience managing risk above the individual finding level, including aggregating related issues into broader risks, driving systemic treatment, and measuring residual risk.
- Current, hands-on AI fluency, including structuring prompts for accurate and repeatable outputs and understanding failure modes like hallucination and data privacy.
- Strong attention to data quality, with the ability to spot and improve processes for stale records, inconsistent scores, and unclear ownership.
- Comfortable with Jira and Google Workspace (Sheets, Docs, Slides) for daily work, including workflow management, analysis, and reporting.
- Proven track record of working well with technical and business teams, including engineers, offensive security, IT, and system owners, and building credibility.
- Proven ability to work independently, take ownership of tasks, prioritize effectively, and raise blockers early in a fast-moving environment.
- Ability to read network diagrams, vulnerability reports, and pen test findings, understand attack paths, and engage confidently with Security Architects and SecOps engineers.
- Working knowledge of cloud infrastructure security (AWS, GCP, or Azure) and at least one security framework (ISO 27001, SOC 2, or NIST CSF / NIST 800-53).
- Understanding of common security controls to recommend appropriate treatments based on best practice.
- Strong writing and presentation skills, with the ability to explain technical issues to non-technical audiences and present risk data in live meetings.
Skills
- Technical risk management
- AI tooling
- Risk assessment
- Risk scoring
- Risk treatment tracking
- Risk acceptance
- Risk closure
- Qualitative risk assessment
- Risk appetite validation
- Root-cause analysis
- Exception tracking
- Control mapping
- ISO/IEC 27001
- SOC 2
- NIST CSF
- NIST 800-53
- Cloud security
- SaaS security
- IAM
- Network security
- Vulnerability management
- Penetration testing analysis
- Data quality management
- Prompt engineering
- LLM usage
- Jira
- Google Workspace
- Google Sheets
- Google Docs
- Google Slides
- Stakeholder management
- Independent work
- Prioritization
- Blocker identification
- Network diagram interpretation
- Vulnerability report analysis
- Attack path understanding
- Cloud infrastructure security (AWS, GCP, Azure)
- Security framework knowledge
- Security control recommendation
- Technical writing
- Presentation skills
Location
- Los Angeles County (unincorporated)
Work Type
- Full-time
Experience Level
- Senior
- 6+ years
Salary/Compensations
- 111,760.00 - 153,670.00 USD Annual
Benefits
- Equity Compensation
- Bonus Incentive Compensation
About the Company
- Procore is committed to offering competitive, fair, and commensurate compensation.
Equal Opportunity
- Procore will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.
- A criminal history may have a direct, adverse, and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment: 1. appropriately managing, accessing, and handling confidential information including proprietary and trade secret information, as well as accessing Procore's information technology systems and platforms; 2. interacting with and occasionally having unsupervised contact with internal/external customers, stakeholders, and/or colleagues; and 3. exercising sound judgment.
