When you impact millions of people every day, you become a large target for adversaries of all types within all layers of the stack. Our job is to keep our users safe and make Yahoo one of the safest places on the Internet. We are the information security team at Yahoo, known as "The Paranoids."
Within the Paranoids, the Cyber Risk team exists to guide Yahoo to make reasonable, compliant, cyber risk-conscious decisions. We position security as a business advantage - surfacing actionable cyber risks, facilitating executive risk decisions, and ensuring that security and compliance are aligned with company goals.
We are looking for a Senior Security GRC Analyst to join the team. This role sits at the intersection of three critical GRC functions: exception management, security risk assessment, and policy and standards management.
You will work directly with business leaders, engineers, and Paranoids security teams to identify, assess, document, and communicate security risks - and then help the organization make informed decisions about them. Some days that means writing a risk evaluation memo that goes to the CISO. Other days it means assessing a property’s security posture against Paranoids policy, drafting a new standard, or working through the nuances of an exception request with a business unit that’s navigating a hard tradeoff.
We operate in a modern, fast-moving security landscape. We view AI as a force multiplier that allows us to scale governance, synthesize complex technical data faster, and deliver higher-impact risk insights. The work requires that you understand enough about technology to ask the right questions, exercise sound judgment when evaluating AI-generated outputs, and understand enough about the business to frame risk in terms that drive good decisions.