Build and own Suno's security compliance program as a Staff Security GRC Analyst in a fast-growing AI music company.
Posted by employer 12 hours ago
First seen on Joblaze 3 hours ago
Last verified on the company career page 3 hours ago
What you'll build
Must have
Nice to have
AI in the day-to-day
Automate evidence collection and control monitoring with scripts, integrations, and AI tools.
Requirements
Not disclosed in this posting: compensation, work arrangement, visa sponsorship.
Joblaze summary
The Staff Security GRC Analyst at Suno is responsible for establishing and managing the company's security compliance framework, ensuring alignment with SOC 2 and NIST CSF standards. This role requires a strong background in security compliance, with hands-on experience in leading SOC 2 preparations and automating evidence collection through scripts and AI tools. Ideal candidates will have 7-9 years of experience in GRC or IT audit, along with the technical fluency to assess cloud configurations. Suno's fast-paced environment offers a unique opportunity to build foundational security practices within a growing team.
Joblaze insights
Quick facts
From the original posting
We're looking for a Staff Security GRC Analyst to build Suno's security compliance program from the ground up. You'll report to our CISO, work alongside our AppSec and InfraSec teams, and own the control framework that ties everything together: which controls we have, how they map to SOC 2 and NIST CSF, and whether they actually work. You're as comfortable reading a cloud config as an audit standard, and you'd rather automate evidence collection with AI than chase screenshots. It's a greenfield build with real stakes and a direct line to leadership.
Listen to the song we made about it: https://suno.com/s/8U6fbhqLEghsnRsm
Build and own Suno's security control framework, mapping controls to SOC 2, NIST CSF, and future frameworks, and writing control descriptions with the teams who run them.
Lead SOC 2 preparation end to end, from gap assessments and readiness tracking to driving remediation with control owners and working with our external auditor.
Automate evidence collection and control monitoring with scripts, integrations, and AI tools, deciding where human review stays in the loop.
Run vendor security reviews, keep our security policies current, and answer customer security questionnaires alongside Product and Legal.
Partner with the CISO to give leadership and the board a clear, evidence-backed view of our security posture, and lay the foundations of GRC as part of a growing Security team.
Help earn the trust of the partners and customers who bring Suno to more people, so creating music can be part of everyone's day.
7–9 years in GRC, security compliance, or IT audit.
Hands-on, end-to-end ownership of a security compliance program as its primary owner, ideally including taking a company through its first SOC 2.
Deep working knowledge of SOC 2 and NIST CSF, including control mapping, audit mechanics (design vs. operating effectiveness, sampling, evidence), and staying current as requirements evolve.
Enough technical fluency to read a cloud configuration, access setup, or pipeline and judge whether it enforces what the control says. You don't need to write production code.
Comfort building your own automation with scripts or AI tools.
Experience standing up continuous controls monitoring or automated evidence collection, including what it covered and what changed as a result.
Experience applying LLMs to assurance work, such as control drafting, framework mapping, or evidence testing.
Experience with cloud environments such as AWS or GCP, and with a modern GRC platform.
Certifications such as CISA, CISSP, or CRISC.
Standard company text repeated across Suno's postings is omitted here.
Explore more