Information Security Analyst, GRC
Listed on 2026-10-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About XBOW
At XBOW, we’re redefining the future of cybersecurity by building the world's first autonomous pentester, powered by AI. Today, the gold standard for securing software systems is human pentesters, but with the rise of artificial intelligence, we’re stepping up to scale offensive security to meet the ever-growing demand.
AI is transforming the landscape of both cybersecurity and cyberattacks. While millions of people without security expertise are creating software, bad actors are using AI to launch more effective attacks. XBOW fights back with AI-driven superpowers, enabling security teams to stay one step ahead.
What makes XBOW truly unique? Like human experts, it forges creative attacks, adapts its learnings, and continuously works to find vulnerabilities faster than anyone ever could. We’re not only simulating threats—we’re also finding and responsibly disclosing real-world vulnerabilities, ensuring organizations can fix issues before they’re exploited. XBOW isn't just a tool; it’s a transformative force in the secure development lifecycle.
Backed by Sequoia Capital and a team that includes the creators of Git Hub Copilot and Git Hub Advanced Security, XBOW is not just keeping up with the times—we’re shaping the future of cybersecurity. Our mission is simple: to defeat the bad actors before they strike, using AI to revolutionize how we approach offensive security.
We’re building something that must be built, and we’re the team to do it. Join us in shaping the next frontier of autonomous security.
Your Role:Information Security Analyst, GRC
We’re looking for a detail-oriented, Information Security Analyst to help scale our security and trust function as we grow. In this role, you’ll play a key part in supporting customer and prospect security reviews, coordinating with legal on reviewing customer contracts, assessing third‑party vendor risk, supporting resolution of compliance alerts and continuously improving how we identify and manage risk across the business.
This is an individual contributor role with no initial people‑management responsibilities. However, as the risk and compliance function matures, there is a clear opportunity for this role to grow in scope and responsibility.
You’ll work closely with IT, Security, Engineering, Legal, Sales, and Customer teams, acting as a trusted partner in communicating our security posture and ensuring we meet customer and regulatory expectations.
What You’ll DoSupport customers and prospects by completing technical security questionnaires, risk assessments, and due‑diligence requests
Partner with Sales and Customer teams to explain XBOW’s security controls, architecture, and compliance posture
Assess and manage third‑party and vendor security risk, including reviews of SaaS providers and service partners
Investigate and resolve alerts to stay compliant with our compliance programmes using the Vanta product.
Help maintain and improve risk assessment frameworks, methodologies, and documentation
Track and support remediation of identified risks in collaboration with internal stakeholders
Contribute to compliance initiatives aligned with frameworks such as SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001
Maintain clear, well‑structured risk registers, policies, and supporting evidence
Coordinate risk management sessions and processes
Identify opportunities to streamline and automate risk and compliance processes as the company scales
Support audits, customer reviews, and internal assurance activities as needed
Essential
7+ years of experience in risk, compliance, security assurance, or related roles
Experience in hands‑on technical roles for example in Engineering, IT or operational security
Hands‑on experience completing or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).