Staff Security GFC Analyst

SunoLos Angeles, San Francisco, CaliforniaOn-siteFull-timeStaff, 8–12 yearsListed 2 hours ago

Apply now

About this role

About Suno

We're building the world's first creative entertainment platform, where the entire world can feel the joy and fulfillment of making music. Music is for everyone: Our users include everyone from grandmothers creating songs for their loved ones, to Grammy winners using Suno Studio, our power tool, to make the most popular hits in the world.

Building the future of entertainment requires ambition. The pace is fast, the problems are hard, and the work demands ownership and intensity. For the right people, it’s incredibly rewarding: a chance to shape a new medium, work with a small team that cares deeply about quality, make music, drink too much coffee, and build something that millions of people use to express themselves in ways that were never before possible.

Suno is the fastest growing consumer entertainment company and the leader in AI music. We are backed by leading investors including Bond Capital, Menlo Ventures, Lightspeed Venture Partners, IVP, Forerunner, Union Square Ventures, Alkeon, Quiet, Matrix Partners, Schroders Capital and, NVentures (venture arm of NVIDIA).

About the Role

We're looking for a Staff Security GRC Analyst to build Suno's security compliance program from the ground up. You'll report to our CISO, work alongside our AppSec and InfraSec teams, and own the control framework that ties everything together: which controls we have, how they map to SOC 2 and NIST CSF, and whether they actually work. You're as comfortable reading a cloud config as an audit standard, and you'd rather automate evidence collection with AI than chase screenshots. It's a greenfield build with real stakes and a direct line to leadership.

Listen to the song we made about it: https://suno.com/s/8U6fbhqLEghsnRsm

What You'll Do

- Build and own Suno's security control framework, mapping controls to SOC 2, NIST CSF, and future frameworks, and writing control descriptions with the teams who run them.
- Lead SOC 2 preparation end to end, from gap assessments and readiness tracking to driving remediation with control owners and working with our external auditor.
- Automate evidence collection and control monitoring with scripts, integrations, and AI tools, deciding where human review stays in the loop.
- Run vendor security reviews, keep our security policies current, and answer customer security questionnaires alongside Product and Legal.
- Partner with the CISO to give leadership and the board a clear, evidence-backed view of our security posture, and lay the foundations of GRC as part of a growing Security team.
- Help earn the trust of the partners and customers who bring Suno to more people, so creating music can be part of everyone's day.

What You'll Need

Must-Haves

- 7–9 years in GRC, security compliance, or IT audit.
- Hands-on, end-to-end ownership of a security compliance program as its primary owner, ideally including taking a company through its first SOC 2.
- Deep working knowledge of SOC 2 and NIST CSF, including control mapping, audit mechanics (design vs. operating effectiveness, sampling, evidence), and staying current as requirements evolve.
- Enough technical fluency to read a cloud configuration, access setup, or pipeline and judge whether it enforces what the control says. You don't need to write production code.
- Comfort building your own automation with scripts or AI tools.

Nice-to-Haves

- Experience standing up continuous controls monitoring or automated evidence collection, including what it covered and what changed as a result.
- Experience applying LLMs to assurance work, such as control drafting, framework mapping, or evidence testing.
- Experience with cloud environments such as AWS or GCP, and with a modern GRC platform.
- Certifications such as CISA, CISSP, or CRISC.

Suno is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the Massachusetts Fair Chance in Employment Act, NYC Fair Chance Act, LA City Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.

Compensation

$276,960 – $363,510 • Offers Equity