Procore
Senior Staff GRC Analyst
US - Texas - Austin
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 3 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Procore Technologies is the leading technology partner for every stage of construction. We empower construction teams to drive efficiency and mitigate risk through actionable AI & data-driven insights. For over 20 years, we have been transforming the industry with purpose-built solutions for construction professionals and we are looking for talented people to help us build together.
We are looking for a Senior Staff GRC Analyst to own Procore's Cyber Essentials and Cyber Essentials Plus certification program from end to end. As a Senior Staff GRC Analyst on our GRC team, you will be the program's hands-on owner and subject matter expert, working closely with IT, Security Engineering, and our external certification body to keep our controls audit-ready year-round and give our UK customers confidence that their project data is protected. Your strengths in security compliance program ownership, technical control validation, and influencing without authority will drive your success.
You will report to the Senior Manager, GRC and will be based in our Austin office.
What You Will Do
- Own the annual Cyber Essentials Plus certification cycle end to end, from scoping and self-assessment through independent technical verification and renewal. Continuous certification protects our ability to win and renew business with UK public sector and enterprise customers.
- Define and maintain the certification scope across devices, networks, cloud services, and user accounts. A clear, defensible scope keeps assessments predictable and focused on what matters most.
- Validate the five technical controls (firewalls, secure configuration, user access control, malware protection, and security update management) hands-on, partnering with IT and Security teams on design and operation. Strong fundamentals reduce the risk of common attacks that could disrupt our customers' projects.
- Drive remediation of control gaps by aligning with control owners on root cause and practical corrective actions. You will track fixes to closure well ahead of assessment deadlines.
- Serve as the primary contact for our certification body, coordinating assessments, evidence requests, and technical testing. Well-run audits mean less disruption for our engineering teams.
- Align Cyber Essentials with our broader compliance programs, such as ISO 27001 and SOC 2, to cut duplicate testing and evidence requests. This helps Procore scale compliance efficiently as we grow.
- Improve the program over time through automation, continuous control monitoring, and cleaner evidence processes. Each certification cycle should take less effort than the last.
- Report program status, risks, and readiness to leadership, turning technical detail into clear decisions and escalating when needed.
What You Bring
- 7+ years of experience in IT audit, GRC, security compliance, or security consulting, including end-to-end ownership of Cyber Essentials or Cyber Essentials Plus certifications. You will run this program independently from day one.
- Hands-on knowledge of endpoint and cloud security controls such as patch management, device configuration, and identity and access management, with experience validating them in tools like [Intune, Okta, AWS]. This lets you test controls directly rather than relying only on attestations.
- Familiarity with related frameworks such as ISO 27001, SOC 2, or NIST CSF, so you can connect Cyber Essentials to the rest of our control environment.
- Proven ability to lead through influence rather than authority, driving action across IT, Security, and business teams. As an individual contributor, you will move work forward through expertise and trusted relationships.
- Track record of independently planning and delivering compliance programs against firm external deadlines, because certification dates do not33 move.
- Proficiency with GRC platforms for evidence collection and control tracking, and interest in automating manual compliance work.
- Willingness to share your expertise and mentor other GRC analysts, raising the bar for the whole team.
- Degree in IT, Computer Science, Cybersecurity, or a related field, or equivalent relevant work experience. Certifications such as CISA, CISM, CISSP, or ISO 27001 Lead Auditor are a plus.
Strong-fit Background Might Include
- Senior or Staff Security Compliance Analyst
- Senior IT Auditor or IT Risk Consultant
- Security Compliance Engineer
- Cyber Essentials Assessor at a certification body
Discover our recruiting process and interview tips from our talent acquisition team on our #LifeAtProcore blog .
Additional Information
Base Pay Range:
163,040.00 - 224,180.00 USD Annual
This role may also be eligible for Equity Compensation and/or Bonus Incentive Compensation. Procore is committed to offering competitive, fair, and commensurate compensation. Actual compensation will be based on a candidate’s job-related skills, experience, education or training, and location.
For Los Angeles County (unincorporated) Candidates:
Procore will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.
A criminal history may have a direct, adverse, and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment: 1. appropriately managing, accessing, and handling confidential information including proprietary and trade secret information, as well as accessing Procore's information technology systems and platforms; 2. interacting with and occasionally having unsupervised contact with internal/external customers, stakeholders, and/or colleagues; and 3. exercising sound judgment.
Similar jobs
- Security GRC Analyst/Program Manager, BridgeStripe · New York First seen 3d ago
- Senior GRC Analyst, GRC Technology LeadIntegritymarketing · Dallas, TXFirst seen 6d ago
- Principal Security GRC AnalystRoblox · San Mateo, CA, United StatesFirst seen 31d agoremote
- Principal Security GRC AnalystRescale · Remote (United States)First seen 31d agoremote
- Senior Security GRC AnalystTuro · San FranciscoFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job