SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
XBOW is an AI-powered cybersecurity company building the world's first autonomous pentester, backed by Sequoia Capital and founded by creators of GitHub Copilot and GitHub Advanced Security. The company is transforming offensive security by using AI to detect vulnerabilities faster and at scale.
As an Information Security Analyst in the GRC (Governance, Risk, and Compliance) function, you will be a key individual contributor supporting the company's security and trust operations as it scales. This role bridges internal security operations with external customer and regulatory requirements.
Key responsibilities include:
- Supporting customers and prospects through technical security questionnaires, risk assessments, and due-diligence requests
- Partnering with Sales and Customer teams to communicate XBOW's security controls, architecture, and compliance posture
- Assessing and managing third-party and vendor security risk, including SaaS provider reviews
- Investigating and resolving compliance alerts using Vanta to maintain compliance programs
- Maintaining and improving risk assessment frameworks, methodologies, and documentation
- Tracking and supporting remediation of identified risks in collaboration with internal teams
- Contributing to compliance initiatives aligned with SOC 2, FedRAMP 20x, ISO 27001, and ISO 42001
- Maintaining risk registers, policies, and supporting evidence
- Coordinating risk management sessions and processes
- Identifying opportunities to streamline and automate risk and compliance processes
- Supporting audits, customer reviews, and internal assurance activities
This is positioned as an individual contributor role with no initial people-management responsibilities, though the posting notes clear opportunity for scope and responsibility growth as the risk and compliance function matures. You will work closely with IT, Security, Engineering, Legal, Sales, and Customer teams.
The company operates as a remote-first organization with regular in-person collaboration opportunities. The environment is described as fast-moving, iterative, and command-line focused.
REQUIREMENTS:
Essential:
- 7+ years of experience in risk, compliance, security assurance, or related roles
- Experience in hands-on technical roles (e.g., Engineering, IT, or operational security)
- Hands-on experience completing or reviewing technical security questionnaires and customer risk assessments
- Familiarity and experience with common security compliance and data protection frameworks (SOC 2, ISO 27001, NIST, GDPR, HIPAA)
- Experience conducting or supporting vendor/third-party risk assessments
- Strong written communication skills with ability to explain complex security concepts clearly
- Highly organized and detail-oriented with pragmatic approach to risk
- Comfortable working in fast-moving, remote-first startup environment
- Familiar with using modern AI tooling to improve productivity whilst managing risk
Advantageous:
- Experience working in a SaaS or security-focused company
- Experience handling Subject Access Requests for GDPR
- Security or risk certifications (e.g., CRISC or CISSP)
- Knowledge of cloud security best practices