PitchMeAI
GitHub

Staff Security Analyst (GRCC)

GitHub · United States

  • Hybrid
  • Full-time
  • $372,300 / year
  • United States
Tailored resumekeyword-matched to this role.
Hiring managerwe find who's hiring.
Intro emaildrafted to reach them directly.

Job highlights

  • Analyze complex security issues.
  • Drive customer engagement on high-impact issues.
  • Lead security reviews and provide mentorship.
  • Manage complex security risks and threats.
  • Experience with regulated customer interactions.

About the role

Staff Security Analyst (GRCC)

About GitHub

GitHub is the world’s leading platform for agentic software development — powered by Copilot to build, scale, and deliver secure software. Over 180 million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate, and more than 77,000 organisations have adopted GitHub Copilot.

Locations

In this role you can work from Remote, United States

Overview

Do you love the opportunity to "Fix It, Build It, Understand It"? As a Staff Security Analyst under the Governance, Risk, Compliance and Customer Trust team within GitHub Security, you will build and execute strategy to meet compliance goals and build durable customer trust and engagement programs. You will serve as a "Human API," proactively analyzing highly complex issues to bridge the gap between business requirements and the technologists building solutions. This role is uniquely positioned to build relationships across Engineering, Infrastructure, and Legal to drive enterprise objectives and build trust in GitHub products.

This position may require travel several times per year, but is minimal.

Responsibilities

  • Security Issues Analysis: Proactively analyzes highly complex issues using multiple data sources to identify security problems and defines strategies for balancing security and operational needs.
  • Customer Engagement: Drives customer engagement for complex, high-impact issues that materially affect customer experience and business outcomes. Leads cross-functional coordination to assess, prioritize, and resolve escalations, creates and scales repeatable tooling, guidance and best practices that reduce recurring challenges, and enables teams to proactively identify risks, improve issue resolution, and strengthen customer trust and adoption.
  • Leadership & Review: Leads large-scale security, architectural, and design reviews for feature areas, ensuring best practices for security architecture, design, and development are in place.
  • Expertise & Mentorship: Helps others by sharing expertise to identify potential security issues, tools, and mitigations (e.g., threat modeling) and mentors others on determining the most appropriate format for communicating highly technical information.
  • Risk Management: Collaborates with leadership to resolve the most complex security issues and risks that require highly innovative solutions, identifying unique defects or threats in the product.

Qualifications

  • Required Qualifications: 10+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area OR Associate's Degree AND 9+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area OR Bachelor's Degree AND 8+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area OR Master's Degree AND 6+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area OR Doctorate AND 4+ years experience in security analysis, security research, cyber security, security engineering, software engineering, or relevant area OR equivalent experience.
  • 3+ years experience in a role with large enterprise, government, and/or highly regulated customer interactions, both asynchronous and synchronous.
  • Preferred Qualifications: Deep experience executing activities along the full audit life cycle (planning, execution, reporting, remediation) for FedRAMP Mod+ or equivalent frameworks.
  • Proven track record designing and testing Business Continuity and Disaster Recovery programs for large-scale SaaS environments.
  • Demonstrated ability to function as a bridge between business views and technical requirements, translating highly technical information to non-technical audiences. Very high comfort level working under ambiguous situations, with a natural drive to bring clarity and challenge assumptions.
  • 1+ year(s) leading a security function or program (e.g., Security Development Lifecycle, Governance, Risk, & Compliance [GRC]).

Compensation Range

The base salary range for this job is USD $140,400.00 - USD $372,300.00 /Yr.

These pay ranges are intended to cover roles based across the United States. An individual's base pay depends on various factors including geographical location and review of experience, knowledge, skills, abilities of the applicant. At GitHub certain roles are eligible for benefits and additional rewards, including annual bonus and stock. These rewards are allocated based on individual impact in role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee's role.

This position will be open for a minimum of 3 days, with applications accepted on an ongoing basis until the position is filled.

GitHub values

  • Customer-obsessed
  • Ship to learn
  • Growth mindset
  • Own the outcome
  • Better together
  • Diverse and inclusive

Manager fundamentals

  • Model
  • Coach
  • Care

Leadership principles

  • Create clarity
  • Generate energy
  • Deliver success

Who We Are

GitHub is the world’s leading AI-powered developer platform with 150 million developers and counting. We’re also home to the biggest open-source community on earth (and 99% of the world’s software has open-source code in its DNA). Many of the apps and programs you use every day are built on GitHub.

Our teams are dreamers, doers, and pioneers, leading the way in AI, driving humanitarian efforts around the globe, and even sending open source to Mars (and beyond!). At GitHub, our goal is to create the space you need to do your best work. We’re remote-first and offer competitive pay, generous learning and growth opportunities, and excellent benefits to support you, wherever you are—because we know that people flourish when they can work on their own terms.

Join us, and let’s change the world, together.

EEO Statement

GitHub is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life. We don't discriminate against employees or applicants based on gender identity or expression, sexual orientation, race, religion, age, national origin, citizenship, disability, pregnancy status, veteran status, or any other differences. Also, if you have a disability, please let us know if there's any way we can make the interview process better for you; we're happy to accommodate!

Key skills/competency

  • Staff Security Analyst
  • GRCC
  • Governance, Risk, Compliance and Customer Trust
  • Security Issues Analysis
  • Customer Engagement
  • Risk Management
  • FedRAMP
  • Business Continuity and Disaster Recovery
  • Security Development Lifecycle
  • Threat Modeling

Skills & topics

  • Security Analyst
  • GRCC
  • Governance
  • Risk
  • Compliance
  • Customer Trust
  • Cyber Security
  • FedRAMP
  • BCDR
  • SaaS Security

How to get hired

  • Customize your resume: Highlight experience in security analysis, risk management, and customer interactions, tailoring it to the Staff Security Analyst role.
  • Showcase regulatory depth: Emphasize experience with FedRAMP or similar frameworks and BCDR programs in your application.
  • Demonstrate leadership: Provide examples of leading security functions or programs, and your ability to bridge technical and business needs.
  • Prepare for behavioral questions: Be ready to discuss how you handle ambiguity, drive clarity, and collaborate with diverse teams.
  • Research GitHub's values: Align your application and interview responses with GitHub's core values like customer-obsession and growth mindset.

Technical preparation

Master FedRAMP and audit lifecycle processes.,Design and test BCDR programs for SaaS.,Develop skills in threat modeling.,Practice translating technical info for non-technical audiences.

Behavioral questions

Describe a complex security issue you resolved.,How do you handle ambiguous situations?,Share an example of driving customer trust.,How do you mentor others on security?

Frequently asked questions

What is the typical career path for a Staff Security Analyst at GitHub?
The Staff Security Analyst role at GitHub is a senior position. Career progression could lead to a Principal Security Analyst, Security Architect, or management roles within the GRCC or broader security teams. Your growth will be supported by GitHub's focus on learning and development, encouraging you to deepen your expertise and take on more complex challenges.
What are the key compliance frameworks relevant to this Staff Security Analyst role at GitHub?
For this Staff Security Analyst role at GitHub, deep experience with FedRAMP Mod+ or equivalent frameworks is preferred. This indicates a focus on government compliance and security standards for cloud services. Familiarity with other regulatory frameworks relevant to SaaS and enterprise-level customer interactions will also be beneficial.
How does GitHub support work-life balance for its remote employees, especially in a Staff Security Analyst position?
GitHub is a remote-first company that values employee well-being. They offer competitive pay, generous learning and growth opportunities, and excellent benefits to support employees wherever they are. The company culture emphasizes 'Own the outcome' and 'Better together,' suggesting a supportive environment where individuals can work on their own terms while collaborating effectively.
What are the most important technical skills for a Staff Security Analyst at GitHub?
Key technical skills for this Staff Security Analyst role include a strong foundation in security analysis, research, engineering, and software development. Preferred qualifications highlight experience with audit life cycles (planning, execution, reporting, remediation) for compliance frameworks like FedRAMP, and designing/testing Business Continuity and Disaster Recovery programs for SaaS environments.
How does GitHub's 'Human API' concept apply to the Staff Security Analyst role?
The 'Human API' concept for the Staff Security Analyst means you'll act as a crucial link between business requirements and technical teams. You'll analyze complex issues, translate highly technical information to non-technical audiences, and drive consensus to resolve security challenges, thereby building trust and ensuring business objectives are met.
What is the expected level of customer interaction for the Staff Security Analyst at GitHub?
The Staff Security Analyst role requires significant interaction with large enterprise, government, and/or highly regulated customers. You will drive customer engagement for complex, high-impact issues, manage escalations, and work to strengthen customer trust and adoption through proactive communication and problem-solving.
Does the Staff Security Analyst role at GitHub involve travel?
Yes, this Staff Security Analyst position may require travel several times per year. However, the description notes that travel is minimal, suggesting it's not a primary component of the role but may be necessary for specific, high-impact engagements or team meetings.
What kind of security issues will a Staff Security Analyst be analyzing at GitHub?
A Staff Security Analyst will proactively analyze highly complex issues using multiple data sources to identify security problems. This includes identifying unique defects or threats in the product and defining strategies that balance security needs with operational requirements, often requiring innovative solutions.