Über diese Senior Staff GRC Analyst - Strategic Account Partner Stelle bei Diligent Corporation
Most security assurance work is reactive: a customer asks, a team scrambles, an answer goes out. This role exists to end that cycle.
As a Senior Staff Analyst, you’ll own a named portfolio of our most significant customers from a security perspective, and get ahead of what they need — their regulatory environment, their audit calendar, their risk appetite, their control expectations — well enough to have the evidence ready before the request arrives. You’ll lead customer security audits hands-on, sit across from customer security teams as a peer rather than a form-filler, and build account security plans that make the next assessment predictable instead of painful.
This is deliberately a hands-on senior individual contributor role. You’ll spend your time in audits, in customer conversations, and in the detail of controls and evidence — not in a management chain. If you’ve got deep SOC 2 and ISO 27001 knowledge, real technical range across cloud architecture, identity and vulnerability management, and the presence to hold a room with a sceptical CISO, this is a portfolio you can genuinely own.
Here’s a breakdown of what you’ll do (not all of it, just the important stuff):
- Own a portfolio of strategic accounts as their dedicated security point of contact, building durable relationships with their security, risk, compliance and procurement teams.
- Lead customer security audits and assessments hands-on — scoping, preparing evidence, running the sessions, defending control design and driving findings to closure with internal owners.
- Build and maintain an account security plan for each account: their frameworks and regulators, audit and reassessment cycles, known concerns, open items and the roadmap commitments they care about.
- Anticipate requirements before they’re raised, tracking regulatory change, industry expectations and each account’s compliance calendar so documentation and evidence are staged in advance.
- Act as the escalation and expertise layer for complex assurance work — bespoke questionnaires, contractual security terms, incident and vulnerability inquiries, penetration tests and architecture-level questions.
- Partner with Sales, Customer Success and Renewals as the embedded security resource, and feed what you learn back into the security and compliance roadmap, the shared answer library and trust site content.
These are the essentials you’ll need to get an interview:
- 5+ years in security GRC, customer assurance, security consulting, IT audit or a closely related function, with meaningful time spent customer- or client-facing.
- Direct hands-on experience leading or defending security audits and assessments, on either side of the table.
- Deep working knowledge of SOC 2 and ISO 27001, plus the adjacent expectations strategic customers raise — NIST CSF, GDPR, HIPAA, DORA and sector-specific requirements.
- Genuine technical depth: you can discuss cloud architecture, encryption, identity, logging and vulnerability management with a customer’s security engineers without taking every question away.
- Excellent written communication, especially the ability to write precisely about controls for an expert audience.
- The judgment and presence to hold a room with a sceptical CISO, say “we don’t do that today, here’s why and here’s what we do instead,” and keep the relationship intact.
- A demonstrated bias toward anticipation over reaction — evidence you’ve built something that prevented fire drills rather than just handling them well.
It would be great if you had these to, but we’ll support you if you don’t:
- Prior experience in a GRC analyst, customer security officer, or named account security or customer success role.
- Experience in financial services, healthcare or the public sector, or supporting customers in heavily regulated industries.
- Certifications such as CISSP, CISA, CRISC or ISO 27001 Lead Auditor.
- Familiarity with trust center platforms and AI-assisted assurance tooling.
- Experience in a multi-product SaaS environment where certifications and control boundaries differ by product.
- Comfort with occasional travel for on-site customer audits and executive reviews.
About Us
Diligent is the AI leader in governance, risk and compliance (GRC) SaaS solutions, helping more than 1 million users and 700,000 board members to clarify risk and elevate governance. The Diligent One Platform gives practitioners, the C-Suite and the board a consolidated view of their entire GRC practice so they can more effectively manage risk, build greater resilience and make better decisions, faster.
Learn more at diligent.com or follow us on LinkedIn and Facebook
What Diligent Offers You
- Creativity is ingrained in our culture. We are innovative collaborators by nature. We thrive in exploring how things can be differently both in our internal processes and to help our clients
- We care about our people. Diligent offers a flexible work environment, global days of service, comprehensive health benefits, meeting free days, generous time off policy and wellness programs to name a few
- We have teams all over the world. We may be headquartered in New York City, but we have office hubs in Washington D.C., Vancouver, London, Galway, Budapest, Munich, Bengaluru, Singapore, and Sydney.
- Diversity is important to us. Growing, maintaining and promoting a diverse team is a top priority for us. We foster and encourage diversity through our Employee Resource Groups and provide access to resources and education to support the education of our team, facilitate dialogue, and foster understanding.
Diligent created the modern governance movement. Our world-changing idea is to empower leaders with the technology, insights and connections they need to drive greater impact and accountability – to lead with purpose. Our employees are passionate, smart, and creative people who not only want to help build the software company of the future, but who want to make the world a more sustainable, equitable and better place.
Headquartered in New York, Diligent has offices in Washington D.C., London, Galway, Budapest, Vancouver, Bengaluru, Munich, Singapore and Sydney. To foster strong collaboration and connection, this role will follow a hybrid work model. If you are within a commuting distance to one of our Diligent office locations, you will be expected to work onsite at least 50% of the time. We believe that in-person engagement helps drive innovation, teamwork, and a strong sense of community.
Diligent is proud to be an equal opportunity employer. We do not discriminate based on race, color, religious creed, sex, national origin, ancestry, citizenship status, pregnancy, childbirth, physical disability, mental disability, age, military status, protected veteran status, marital status, registered domestic partner or civil union status, gender (including sex stereotyping and gender identity or expression), medical condition (including, but not limited to, cancer related or HIV/AIDS related), genetic information, or sexual orientation in accordance with applicable federal, state and local laws. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also Diligent's EEO Policy and US EEOC’s Know Your Rights. We are a drug free workplace.
We are committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at [email protected].