About this role
About Pinterest:
Millions of people around the world come to our platform to find creative ideas, dream about new possibilities and plan for memories that will last a lifetime. At Pinterest, we’re on a mission to bring everyone the inspiration to create a life they love, and that starts with the people behind the product.
Discover a career where you ignite innovation for millions, transform passion into growth opportunities, celebrate each other’s unique experiences and embrace the flexibility to do your best work. Creating a career you love? It’s Possible.
At Pinterest, AI isn't just a feature, it's a powerful partner that augments our creativity and amplifies our impact, and we’re looking for candidates who are excited to be a part of that. To get a complete picture of your experience and abilities, we’ll explore your foundational skills and how you collaborate with AI.
Through our interview process, what matters most is that you can always explain your approach, showing us not just what you know, but how you think. You can read more about our AI interview philosophy and how we use AI in our recruiting process here .
Pinterest’s Security team (Pinfosec) is seeking an IC14 Security Engineer - Security Governance, Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and assurance programs. This role is ideal for someone who is detail-oriented, collaborative, and motivated by building scalable security processes that help the business manage risk effectively.
Reporting to the Interim Head of Security Governance, Risk & Compliance, this individual contributor will partner closely with Security, Engineering, IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve Pinterest’s security control environment. The role will contribute to core GRC activities including risk management, policy governance, control testing, audit support, awareness tracking, and internal risk assessments.
What you’ll do:
• Administer and maintain the security risk register, including tracking identified risks, updates, remediation activities, owners, and reporting outputs.
• Partner with stakeholders across Security and the business to identify, document, assess, and monitor security risks.
• Draft, review, update, and manage the lifecycle of security policies, standards, and supporting procedures.
• Support the planning, coordination, evidence collection, and follow-up activities for Pinterest’s annual SOC 2 Type 2 audit.
• Track and report on security awareness training metrics, completion rates, exceptions, and follow-up actions.
• Execute security control testing activities aligned to CIS Controls and document testing outcomes, findings, and remediation recommendations.
• Conduct and support risk assessments in partnership with internal Security colleagues and relevant business stakeholders.
• Help monitor control effectiveness and identify opportunities to impr