Turo
Senior Security GRC Analyst
San Francisco
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Senior
- Stated salary
- $131,000 – $164,000 per year
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 3 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About the team
Turo is searching for a highly motivated and versatile Senior Security GRC Analyst under the Enterprise Security team to lead security compliance programs as a senior individual contributor. This role carries primary ownership of SOC 2 Type II and PCI DSS audit readiness and coordination, and serves as the connective tissue between Engineering, IT, Finance, Legal, and business control owners. You will drive complex security compliance workstreams with limited oversight, exercising strong judgment and cross-functional influence to keep Turo audit-ready year-round.
What you will do
Security Compliance & Audit Readiness
- Own the compliance calendar and drive end-to-end audit readiness for SOC 2 Type II and PCI DSS, including scoping, control mapping, and continuous readiness between audit cycles.
- Coordinate evidence collection across Engineering, IT, Finance, and business teams; track control owners and close gaps ahead of audit windows.
- Serve as the primary day-to-day liaison with external auditors and assessors to manage requests, facilitate walkthroughs, and coordinate remediation of findings.
- Maintain and evolve the common control framework: map controls across SOC 2, PCI DSS, and other applicable standards; identify and eliminate redundant testing where possible.
- Lead compliance testing activities, document results, and maintain evidence repositories that support both internal review and external audit.
Findings, Remediation & Exception Management
- Track open audit findings and remediation commitments; provide status reporting to Security leadership and relevant stakeholders.
- Manage the security exception process and document risk acceptances, obtain appropriate approvals, and monitor exceptions through expiration or remediation.
- Identify control gaps proactively and partner with control owners to design and implement compensating or corrective controls.
Policy & Governance
- Develop, maintain, and enforce security policies, standards, and procedures; keep them current with regulatory change and evolving business needs.
- Partner with Legal on data-privacy obligations, subprocessor reviews, and breach-notification readiness.
- Establish and report on compliance metrics - audit readiness scores, open findings aging, exception inventory, and cycle time - to drive accountability and visibility.
- Identify and implement process and automation improvements that increase throughput and reduce manual effort across compliance workflows.
Your Profile
- 5+ years in security compliance, GRC, or IT audit, with hands-on experience running security audit programs from start to finish.
- Direct ownership of at least one full audit cycle under SOC 2 Type II and/or PCI DSS - from scoping through final report.
- Demonstrated ability to coordinate evidence collection and remediation across multiple engineering and business teams with limited oversight.
- Working knowledge of cloud security (AWS), IAM, and encryption frameworks - sufficient to assess controls and evaluate evidence critically.
- Strong written and verbal communication skills; able to translate technical compliance requirements into clear guidance for non-security stakeholders.
- Comfort operating independently in an ambiguous, fast-moving environment, managing competing deadlines without close supervision.
- Bachelor's degree in Computer Science, Information Security, Information Assurance or equivalent practical experience.
- Relevant certification: CISA, CISM, CISSP, or equivalent security certification.
- Experience scaling a security compliance program through initial certification and into annual renewal cycles.
- Familiarity with GRC tooling (e.g., Vanta, Drata, ZenGRC) and security-automation platforms.
- Experience in a regulated or high-trust industry - fintech, marketplace, or SaaS handling sensitive personal or financial data.
For this role, the target base salary range in San Francisco is $131,000-$164,000 annually. This role is also eligible for equity and benefits. In general, our ranges reflect the market-based target for new hire salaries based on the level and location of the role. Within the range, individual pay is determined by objective factors assessed during the application and interview process, such as job-related skills, experience, and relevant education or training. We encourage you to talk with your recruiter to learn more about the total compensation and benefits available for this role.
Turo highly values having employees working in-office to foster a collaborative work environment and company culture. This is central to how we work, and this role will be subject to our current in-office hybrid schedule that requires Turists to work in the office three days per week on Mondays, Wednesdays, and Thursdays. We expect that employees will meet these required in-office days consistently as part of their role. Your recruiter can share more information about this requirement and the in-office perks Turo offers.
Turo Recruiting Scam Alert:
We’ve learned that there are scammers targeting job candidates by impersonating Turo and its employees. We ask candidates to be careful of fraudulent job postings or suspicious recruiting activity during their job search, especially if they’re contacted through unofficial channels (such as Instagram, Telegram, MS Teams, etc.). In general, Turo interacts with candidates through our Careers page and via turo.com email addresses, and we don’t ask candidates for sensitive financial or personal info or request money as part of the hiring process (so an application fee or equipment costs). If candidates are not sure whether they’re dealing with an impersonator, they can contact Turo’s Recruiting Team at recruit@turo.com . Candidates can also report suspicious activity to the FTC or other appropriate authorities.
Turo AI Policy:
Turo may use AI-enabled tools to support our recruiting operations, including gathering information from candidates, drafting communications, helping with interview note-taking and assessment, and so on. These tools only supplement our team; all decisions to advance or hire candidates are made by Turo employees. While we welcome candidates to use AI-enabled tools to help prepare for their interviews, the use of such tools, including any AI chatbots or note-takers, is not permitted during live interviews or technical assessments. We want to see how you consider and solve problems in real-time, so interviews and assessments are all you (unless we indicate otherwise and ask you specifically to use an AI-enabled tool to answer a question). If during the application process you require the use of an AI-enabled tool as a reasonable accommodation for a disability, please let us know at PeopleOps@turo.com .
Benefits
Competitive salary, equity, benefits, and perks for all full-time employees
Employer-paid medical, dental, and vision insurance (Country specific)
Retirement employer match
Learning & Development stipend to invest in your professional development
Turo host matching program
Turo travel credit
Cell phone and internet stipend
Paid time off to relax and recharge
Paid holidays, volunteer time off, and parental leave
For those who are in the office full-time or hybrid we have in-office lunch, office snacks, and fun activities
We are committed to building a diverse team. If you are from a background that's underrepresented in tech, we'd love to meet you.
Aside from an award winning work environment and the opportunity to be part of the world’s largest car sharing marketplace, we are also growing the team quickly - join us! Even if you don't meet every qualification, we are looking for people with enthusiasm for what we do and we will consider you for this and other possibilities.
About Turo
Turo is the world’s largest car sharing marketplace where you can book the perfect car for wherever you’re going from a vibrant community of trusted h
Similar jobs
- Information Security GRC Analyst III -TPRM ExperienceCaresource · RemoteFirst seen yesterdayremote
- Sr. GRC Analyst, Common Control FrameworkSalesforce · 3 LocationsFirst seen 3d ago
- Sr. GRC Analyst, Policy OperationsSalesforce · 3 LocationsFirst seen 3d ago
- GRC Analyst Ambiencehealthcare · San FranciscoFirst seen 3d ago
- Information Security GRC Analyst III, Controls AssuranceFanatics Inc. · Jacksonville, FL, United States; New York, NY, United StatesFirst seen 5d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job