About this role
Procore Technologies is the leading technology partner for every stage of construction. We empower construction teams to drive efficiency and mitigate risk through actionable AI & data-driven insights. For over 20 years, we have been transforming the industry with purpose-built solutions for construction professionals and we are looking for talented people to help us build together.
We are looking for a Senior Staff GRC Analyst to own Procore's Cyber Essentials and Cyber Essentials Plus certification program from end to end. As a Senior Staff GRC Analyst on our GRC team, you will be the program's hands-on owner and subject matter expert, working closely with IT, Security Engineering, and our external certification body to keep our controls audit-ready year-round and give our UK customers confidence that their project data is protected. Your strengths in security compliance program ownership, technical control validation, and influencing without authority will drive your success.
You will report to the Senior Manager, GRC and will be based in our Austin office.
What You Will Do
- Own the annual Cyber Essentials Plus certification cycle end to end, from scoping and self-assessment through independent technical verification and renewal. Continuous certification protects our ability to win and renew business with UK public sector and enterprise customers.
- Define and maintain the certification scope across devices, networks, cloud services, and user accounts. A clear, defensible scope keeps assessments predictable and focused on what matters most.
- Validate the five technical controls (firewalls, secure configuration, user access control, malware protection, and security update management) hands-on, partnering with IT and Security teams on design and operation. Strong fundamentals reduce the risk of common attacks that could disrupt our customers' projects.
- Drive remediation of control gaps by aligning with control owners on root cause and practical corrective actions. You will track fixes to closure well ahead of assessment deadlines.
- Serve as the primary contact for our certification body, coordinating assessments, evidence requests, and technical testing. Well-run audits mean less disruption for our engineering teams.
- Align Cyber Essentials with our broader compliance programs, such as ISO 27001 and SOC 2, to cut duplicate testing and evidence requests. This helps Procore scale compliance efficiently as we grow.
- Improve the program over time through automation, continuous control monitoring, and cleaner evidence processes. Each certification cycle should take less effort than the last.
- Report program status, risks, and readiness to leadership, turning technical detail into clear decisions and escalating when needed.
What You Bring
- 7+ years of experience in IT audit, GRC, security compliance, or security consulting, including end-to-end ownership of Cyber Essentials or Cyber Essentials Plus certifications. You will run this program independently from day one.
- Hands-on knowledge of endpoint and cloud security controls such as patch management, device configuration, and identity and access management, with experience validating them in tools like [Intune, Okta, AWS]. This lets you test controls directly rather than relying only on attestations.
- Familiarity with related frameworks such as ISO 27001, SOC 2, or NIST CSF, so you can connect Cyber Essentials to the rest of our control environment.
- Proven ability to lead through influence rather than authority, driving action across IT, Security, and business teams. As an individual contributor, you will move work forward through expertise and trusted relationships.
- Track record of independently planning and delivering compliance programs against firm external deadlines, because certification dates do not33 move.
- Proficiency with GRC platforms for evidence collection and control tracking, and interest in automating manual compliance work.
- Willingness to share your expertise and mentor other GRC analysts, raising the bar for the whole team.
- Degree in IT, Computer Science, Cybersecurity, or a related field, or equivalent relevant work experience. Certifications such as CISA, CISM, CISSP, or ISO 27001 Lead Auditor are a plus.
Strong-fit Background Might Include
- Senior or Staff Security Compliance Analyst
- Senior IT Auditor or IT Risk Consultant
- Security Compliance Engineer
- Cyber Essentials Assessor at a certification body
Discover our recruiting process and interview tips from our talent acquisition team on our #LifeAtProcore blog .
Additional Information
Base Pay Range:
163,040.00 - 224,180.00 USD Annual
This role may also be eligible for Equity Compensation and/or Bonus Incentive Compensation. Procore is committed to offering competitive, fair, and commensurate compensation. Actual compensation will be based on a candidate’s job-related skills, experience, education or training, and location.
For Los Angeles County (unincorporated) Candidates:
Procore will consider for employment all qualified applicants, including those with arrest or conviction records, in accordance with the requirements of applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.
A criminal history may have a direct, adverse, and negative relationship on the following job duties, potentially resulting in the withdrawal of the conditional offer of employment: 1. appropriately managing, accessing, and handling confidential information including proprietary and trade secret information, as well as accessing Procore's information technology systems and platforms; 2. interacting with and occasionally having unsupervised contact with internal/external customers, stakeholders, and/or colleagues; and 3. exercising sound judgment.