Senior Staff InfoSec Risk Specialist (GRC)
What you'll need to apply
Fields this application requires
Company-specific questions
- Current Company
- GDPR
About this role
Employer-provided description, formatted for easier reading.
Our Purpose
At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow.
If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.
About Us
SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed.
By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.
Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.
What Are We Looking For?
We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.
As a Senior Staff, Information Security Risk, you will be tasked with owning SentinelOne's Security Risk Program outright, running the day-to-day cadence that identifies, scores, prioritizes, and drives down technical risk across the company.
You will build the governance, automation, and review that turn a functioning risk register into a genuinely predictive risk management capability, and you will be trusted to run the program without supervision and to stand in for GRC leadership when the situation calls for it.
Success in this role depends on credibility: knowing the technology, scoring risk fairly, and never bringing a problem to review without having already done the work.
What Will You Do?
Primary responsibilities include:
- Serve as the accountable owner for the Security Risk program, covering cadence, scoring methodology, reporting, escalation, and the standard operating procedure that governs it, and keep the program audit-ready with decisions documented, approvals logged, procedure current, and evidence retrievable.
- Contribute to the broader GRC functional strategy and multi-year roadmap, and advise leadership on how risk register data should inform security investment and resourcing decisions.
- Own the escalation path end-to-end, from critical-risk notification through executive resolution of cross-team prioritization conflicts, and provide day-to-day technical leadership and oversight for risk analysts at all levels.
- Own the intake pipeline for risks submitted from every source, including internal observation, audit findings, penetration tests, red team exercises, vulnerability scans, threat modeling, tabletop exercises, incidents, and compliance frameworks such as SOC 2, SOX, FedRAMP, IRAP, C5, UK Cyber, and NIST CSF.
- Validate and baseline likelihood and impact scoring using an ISO 27005-aligned methodology, and defend those ratings to engineering and security stakeholders who will not always agree with them.
- Enforce triage service levels, including same-day escalation for critical risks, expedited handling for the next tier, and standard bi-weekly handling for everything else, and hold the line on data quality and field completeness across the register.
- Prepare and facilitate the recurring risk review with security leadership, covering new and unreviewed risks, service-level breaches, in-flight risk health, and risks awaiting final acceptance, and drive mitigation plans to approval, ensuring every critical risk has an approved plan or full remediation within the program's commitment window.
- Adjudicate risk treatment decisions and make sure residual risk is documented, evidenced, and re-scored rather than quietly closed out.
- Build and present the Program Review to security and engineering leadership, covering program status, risk counts and quarter-over-quarter trends, critical category analysis, prior-quarter commitments delivered versus missed, and the top five to six efforts selected for the coming quarter, and run the baselining of the entire register against new results, backlog and active project review, and the current threat landscape.
- Build repeatable, queryable automation and AI-assisted workflows that generate review prep and quarterly metrics on demand, design and land program enhancements on the roadmap such as anonymous risk submission, a service-desk intake portal, executive-owner accountability tracking, application and system scope tracking, and re-modeling risk treatment status into the workflow itself, and extend the register into emerging domains, including AI risk, while integrating internal and external threat intelligence into the risk identification process.
What Skills and Knowledge Will You Bring?
Ideal candidates will have:
- At least 12 years of related experience with a Bachelor's degree; or 8 years with a Master's degree; or a PhD with 5 years of experience; or equivalent practical experience.
- Expert-level knowledge across multiple cybersecurity domains, for example application security, cloud security, identity and access management, network security, data protection, endpoint security, and third-party risk, with genuine depth in more than one niche rather than surface familiarity across all of them.
- Deep, hands-on experience with cybersecurity risk management, including risk identification, qualitative and quantitative scoring, treatment decisions, residual risk, and remediation tracking, grounded in a recognized methodology such as ISO 27005, ISO 27001, NIST RMF, NIST CSF, or FAIR.
- Demonstrated experience building or substantially maturing a GRC function or program, not just operating one that someone else designed, and a track record of leading projects that span multiple teams or sub-functions, executed with minimal supervision and delivered to a high standard.
- Experience mentoring and providing technical oversight to analysts, including senior analysts.
- Proven ability to communicate risk to executive audiences, translating technical findings into business impact, building the narrative, and defending the recommendation in the room.
- Working familiarity with at least one major compliance framework relevant to enterprise software, such as SOC 2, FedRAMP, ISO 27001, IRAP, C5, or similar, and practical fluency with Jira, including JQL, custom field schemas, workflow design, and permission and issue-security models.
- Experience running a risk register at scale, hundreds of concurrent risks across a large, distributed engineering organization, is preferred, as is experience standing in for or acting as a deputy to a GRC leader, including during incidents and other high-pressure situations.
- Automation and data skills such as SQL, Python, Google Apps Script, Jira automation, or AI-assisted workflow tooling used to eliminate recurring manual reporting are preferred, as is a background in a cybersecurity product company or another environment where the security team's own posture is subject to unusual external scrutiny.
- Experience assessing AI and machine learning risk, or integrating threat intelligence into a formal risk management process, is preferred, as are relevant certifications such as CISSP, CRISC, CISA, CISM, or an ISO 27001 Lead Auditor or Lead Implementer credential.
Why SentinelOne?
AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.
We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:
Equity & Rewards
- Restricted Stock Units (RSUs)
- Employee Stock Purchase Plan (ESPP)
Time Off & Wellbeing
- Competitive leave benefits
- Gender-neutral parental leave
Insurance & Financial Security
- Private medical, dental, and vision insurance
Work Perks & Flexibility
- Global home office allowance
- Internet or mobile phone allowance
- Hybrid work model with flexible hours
Wellness & Lifestyle
- Wellness programs
Growth & Community
- In-office lunch program
SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
SentinelOne participates in the E-Verify Program for all U. S. based roles.