Senior Staff InfoSec Risk Specialist (GRC)

SentinelOne · Costa Rica · Operations

Posted 2026-09-17

Apply for this role →

As a Senior Staff, Information Security Risk, you will be tasked with owning SentinelOne's Security Risk Program outright, running the day-to-day cadence that identifies, scores, prioritizes, and drives down technical risk across the company. You will build the governance, automation, and review that turn a functioning risk register into a genuinely predictive risk management capability, and you will be trusted to run the program without supervision and to stand in for GRC leadership when the situation calls for it. Success in this role depends on credibility: knowing the technology, scoring risk fairly, and never bringing a problem to review without having already done the work.

What Will You Do?

Primary responsibilities include:

Serve as the accountable owner for the Security Risk program, covering cadence, scoring methodology, reporting, escalation, and the standard operating procedure that governs it, and keep the program audit-ready with decisions documented, approvals logged, procedure current, and evidence retrievable.

Contribute to the broader GRC functional strategy and multi-year roadmap, and advise leadership on how risk register data should inform security investment and resourcing decisions.

Own the escalation path end-to-end, from critical-risk notification through executive resolution of cross-team prioritization conflicts, and provide day-to-day technical leadership and oversight for risk analysts at all levels.

Own the intake pipeline for risks submitted from every source, including internal observation, audit findings, penetration tests, red team exercises, vulnerability scans, threat modeling, tabletop exercises, incidents, and compliance frameworks such as SOC 2, SOX, FedRAMP, IRAP, C5, UK Cyber, and NIST CSF.

Validate and baseline likelihood and impact scoring using an ISO 27005-aligned methodology, and defend those ratings to engineering and security stakeholders who will not always agree with them.

Enforce triage service levels, including same-day escalation for critical risks, expedited handling for the next tier, and standard bi-weekly handling for everything else, and hold the line on data quality and field completeness across the register.

Prepare and facilitate the recurring risk review with security leadership, covering new and unreviewed risks, service-level breaches, in-flight risk health, and risks awaiting final acceptance, and drive mitigation plans to approval, ensuring every critical risk has an approved plan or full remediation within the program's commitment window.

Adjudicate risk treatment decisions and make sure residual risk is documented, evidenced, and re-scored rather than quietly closed out.

Build and present the Program Review to security and engineering leadership, covering program status, risk counts and quarter-over-quarter trends, critical category analysis, prior-quarter commitments delivered versus missed, and the top five to six efforts selected for the coming quarter, and run the baselining of the entire register against new results, backlog and active project review, and the current threat landscape.

Build repeatable, queryable automation and AI-assisted workflows that generate review prep and quarterly metrics on demand, design and land program enhancements on the roadmap such as anonymous risk submission, a service-desk intake portal, executive-owner accountability tracking, application and system scope tracking, and re-modeling risk treatment status into the workflow itself, and extend the register into emerging domains, including AI risk, while integrating internal and external threat intelligence into the risk identification process.

What Skills and Knowledge Will You Bring?

Ideal candidates will have:

At least 12 years of related experience with a Bachelor's degree; or 8 years with a Master's degree; or a PhD with 5 years of experience; or equivalent practical experience.

Expert-level knowledge across multiple cybersecurity domains, for example application security, cloud security, identity and access management, network security, data protection, endpoint security, and third-party risk, with genuine depth in more than one niche rather than surface familiarity across all of them.

Deep, hands-on experience with cybersecurity risk management, including risk identification, qualitative and quantitative scoring, treatment decisions, residual risk, and remediation tracking, grounded in a recognized methodology such as ISO 27005, ISO 27001, NIST RMF, NIST CSF, or FAIR.

Demonstrated experience building or substantially maturing a GRC function or program, not just operating one that someone else designed, and a track record of leading projects that span multiple teams or sub-functions, executed with minimal supervision and delivered to a high standard.

Experience mentoring and providing technical oversight to analysts, including senior analysts.

Proven ability to communicate risk to executive audiences, translating technical findings into business impact, building the narrative, and defending the recommendation in the room.

Working familiarity with at least one major compliance framework relevant to enterprise software, such as SOC 2, FedRAMP, ISO 27001, IRAP, C5, or similar, and practical fluency with Jira, including JQL, custom field schemas, workflow design, and permission and issue-security models.

Experience running a risk register at scale, hundreds of concurrent risks across a large, distributed engineering organization, is preferred, as is experience standing in for or acting as a deputy to a GRC leader, including during incidents and other high-pressure situations.

Automation and data skills such as SQL, Python, Google Apps Script, Jira automation, or AI-assisted workflow tooling used to eliminate recurring manual reporting are preferred, as is a background in a cybersecurity product company or another environment where the security team's own posture is subject to unusual external scrutiny.

Experience assessing AI and machine learning risk, or integrating threat intelligence into a formal risk management process, is preferred, as are relevant certifications such as CISSP, CRISC, CISA, CISM, or an ISO 27001 Lead Auditor or Lead Implementer credential.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards

Restricted Stock Units (RSUs)

Employee Stock Purchase Plan (ESPP)

Time Off & Wellbeing

Competitive leave benefits

Gender-neutral parental leave

Insurance & Financial Security

Private medical, dental, and vision insurance

Work Perks & Flexibility

Global home office allowance

Internet or mobile phone allowance

Hybrid work model with flexible hours

Wellness & Lifestyle

Wellness programs

Growth & Community

In-office lunch program

Apply for this role →

← Back to all jobs