Senior Staff GRC Analyst
procore · US - Texas - Austin · United States · On-site
Posted Oct 2, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Procore Technologies is the leading technology partner for every stage of construction. We empower construction teams to drive efficiency and mitigate risk through actionable AI & data-driven insights. For over 20 years, we have been transforming the industry with purpose-built solutions for construction professionals and we are looking for talented people to help us build together.
We are looking for a Senior Staff GRC Analyst to own Procore's Cyber Essentials and Cyber Essentials Plus certification program from end to end. As a Senior Staff GRC Analyst on our GRC team, you will be the program's hands-on owner and subject matter expert, working closely with IT, Security Engineering, and our external certification body to keep our controls audit-ready year-round and give our UK customers confidence that their project data is protected. Your strengths in security compliance program ownership, technical control validation, and influencing without authority will drive your success.
You will report to the Senior Manager, GRC and will be based in our Austin office.
What You Will Do
Own the annual Cyber Essentials Plus certification cycle end to end, from scoping and self-assessment through independent technical verification and renewal. Continuous certification protects our ability to win and renew business with UK public sector and enterprise customers.
Define and maintain the certification scope across devices, networks, cloud services, and user accounts. A clear, defensible scope keeps assessments predictable and focused on what matters most.
Validate the five technical controls (firewalls, secure configuration, user access control, malware protection, and security update management) hands-on, partnering with IT and Security teams on design and operation. Strong fundamentals reduce the risk of common attacks that could disrupt our customers' projects.
Drive remediation of control gaps by aligning with control owners on root cause and practical corrective actions. You will track fixes to closure well ahead of assessment deadlines.
Serve as the primary contact for our certification body, coordinating assessments, evidence requests, and technical testing. Well-run audits mean less disruption for our engineering teams.
Align Cyber Essentials with our broader compliance programs, such as ISO 27001 and SOC 2, to cut duplicate testing and evidence requests. This helps Procore scale compliance efficiently as we grow.
Improve the program over time through automation, continuous control monitoring, and cleaner evidence processes. Each certification cycle should take less effort than the last.
Report program status, risks, and readiness to leadership, turning technical detail into clear decisions and escalating when needed.
What You Bring
7+ years of experience in IT audit, GRC, security compliance, or security consulting, including end-to-end ownership of Cyber Essentials or Cyber Essentials Plus certifications. You will run this…