← Back to results

Staff Security GFC Analyst

Build and own Suno's security compliance program as a Staff Security GRC Analyst in a fast-growing AI music company.

Location
NYC, United States
Compensation
Not disclosed
Level
staff
Type
full time

Posted by employer 12 hours ago

First seen on Joblaze 3 hours ago

Last verified on the company career page 3 hours ago

Apply at Suno → Save job Scanned from suno.com

What you'll build

  • Build and own Suno's security control framework
  • Lead SOC 2 preparation end to end
  • Automate evidence collection and control monitoring
  • Run vendor security reviews
  • Partner with the CISO to provide security posture updates

Must have

  • 7–9 years in GRC, security compliance, or IT audit
  • Hands-on ownership of a security compliance program
  • Deep working knowledge of SOC 2 and NIST CSF
  • Technical fluency to read cloud configurations
  • Comfort building automation with scripts or AI tools

Nice to have

  • Experience with continuous controls monitoring
  • Experience applying LLMs to assurance work
  • Experience with cloud environments such as AWS or GCP
  • Experience with a modern GRC platform
  • Certifications such as CISA, CISSP, or CRISC

AI in the day-to-day

Automate evidence collection and control monitoring with scripts, integrations, and AI tools.

Requirements

Experience
7–9 years

Not disclosed in this posting: compensation, work arrangement, visa sponsorship.

Joblaze summary

The Staff Security GRC Analyst at Suno is responsible for establishing and managing the company's security compliance framework, ensuring alignment with SOC 2 and NIST CSF standards. This role requires a strong background in security compliance, with hands-on experience in leading SOC 2 preparations and automating evidence collection through scripts and AI tools. Ideal candidates will have 7-9 years of experience in GRC or IT audit, along with the technical fluency to assess cloud configurations. Suno's fast-paced environment offers a unique opportunity to build foundational security practices within a growing team.

Joblaze insights

  • Listed today — first seen on Joblaze October 9, 2026. Last confirmed on Suno's careers page October 9, 2026.
  • AWS appears in 37.6% of 109 comparable staff security roles in United States; NIST CSF appears in 1.8% of 109 comparable staff security roles in United States.

Quick facts

How much experience is required?
7–9 years of relevant experience for this Staff Security GFC Analyst role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AI, AWS, Automation, Cloud, GCP, NIST CSF.
What seniority level is this role?
Suno targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Staff Security GFC Analyst role at Suno.

From the original posting

About the Role

We're looking for a Staff Security GRC Analyst to build Suno's security compliance program from the ground up. You'll report to our CISO, work alongside our AppSec and InfraSec teams, and own the control framework that ties everything together: which controls we have, how they map to SOC 2 and NIST CSF, and whether they actually work. You're as comfortable reading a cloud config as an audit standard, and you'd rather automate evidence collection with AI than chase screenshots. It's a greenfield build with real stakes and a direct line to leadership.

Listen to the song we made about it: https://suno.com/s/8U6fbhqLEghsnRsm

What You'll Do

  • Build and own Suno's security control framework, mapping controls to SOC 2, NIST CSF, and future frameworks, and writing control descriptions with the teams who run them.

  • Lead SOC 2 preparation end to end, from gap assessments and readiness tracking to driving remediation with control owners and working with our external auditor.

  • Automate evidence collection and control monitoring with scripts, integrations, and AI tools, deciding where human review stays in the loop.

  • Run vendor security reviews, keep our security policies current, and answer customer security questionnaires alongside Product and Legal.

  • Partner with the CISO to give leadership and the board a clear, evidence-backed view of our security posture, and lay the foundations of GRC as part of a growing Security team.

  • Help earn the trust of the partners and customers who bring Suno to more people, so creating music can be part of everyone's day.

What You'll Need

Must-Haves

  • 7–9 years in GRC, security compliance, or IT audit.

  • Hands-on, end-to-end ownership of a security compliance program as its primary owner, ideally including taking a company through its first SOC 2.

  • Deep working knowledge of SOC 2 and NIST CSF, including control mapping, audit mechanics (design vs. operating effectiveness, sampling, evidence), and staying current as requirements evolve.

  • Enough technical fluency to read a cloud configuration, access setup, or pipeline and judge whether it enforces what the control says. You don't need to write production code.

  • Comfort building your own automation with scripts or AI tools.

Nice-to-Haves

  • Experience standing up continuous controls monitoring or automated evidence collection, including what it covered and what changed as a result.

  • Experience applying LLMs to assurance work, such as control drafting, framework mapping, or evidence testing.

  • Experience with cloud environments such as AWS or GCP, and with a modern GRC platform.

  • Certifications such as CISA, CISSP, or CRISC.

Standard company text repeated across Suno's postings is omitted here.

Similar positions

Suno
Suno