Insight Global logo

Policy Analyst

Insight Global

San Francisco, CAJobSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
San Francisco, CA
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The Security Governance team modernizes security policies, standards, requirements, and controls. This role supports a large‑scale governance modernization initiative, assessing, rewriting, and enhancing security governance content while aligning with the Common Controls Framework and major industry security frameworks.

Skills & qualifications

RequiredNice to have

Skills

Security GRCInformation SecuritySecurity GovernanceSecurity Policy DevelopmentSecurity Standards DevelopmentSecurity Controls DevelopmentNIST 800-53Security Controls MappingFramework HarmonizationGap AnalysisRemediation PlanningISO 27001FedRAMPPCI DSSSOC 2NIST CSFCIS ControlsPolicy ModernizationTechnical WritingGovernance DocumentationCommon Controls FrameworkArcherServiceNow GRCOneTrustLogicGateSalesforce eGRCCross-Functional Stakeholder Management

Qualifications

CISSP, CGRC, CISA, CISM, or CRISCSaaS, Cloud, or Enterprise Technology ExperienceFedRAMP or Public Sector Compliance ExperienceAudit Readiness and External Assessment SupportAI Governance or Responsible AI ExperienceSalesforce Platform Familiarity

Full job description

Job Description

The Security Governance team is responsible for maintaining and modernizing security policies, standards, requirements, and controls framework. This role will support a large-scale governance modernization initiative focused on assessing, rewriting, and enhancing security governance content while ensuring alignment across the Common Controls Framework (CCF) and major industry security frameworks.

Skills and Requirements

Must-Haves

  • 5+ years of Security GRC, Information Security, or Security Governance experience

  • Security policy, standards, and controls development

  • NIST 800-53 expertise

  • Security controls mapping and framework harmonization

  • Gap analysis and remediation planning

  • Experience with multiple frameworks:

  • ISO 27001

  • FedRAMP

  • PCI DSS

  • SOC 2

  • NIST CSF

  • CIS Controls

  • Policy, standards, or controls modernization experience

  • Technical writing and governance documentation

  • Common Controls Framework (CCF) experience

  • GRC platform experience (Archer, ServiceNow GRC, OneTrust, LogicGate, Salesforce eGRC, etc.)

  • Cross-functional stakeholder management (Security, Compliance, Risk, Engineering, Legal) Preferred Qualifications

  • CISSP, CGRC, CISA, CISM, or CRISC

  • SaaS, Cloud, or Enterprise Technology experience

  • FedRAMP or Public Sector compliance experience

  • Audit readiness and external assessment support

  • AI Governance or Responsible AI experience Salesforce platform familiarity

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.