1

Security Questionnaire Analyst Jobs (NOW HIRING)

Senior Engineer, Security & Compliance (US)

Austin, TX ยท On-site

$113K - $155K/yr

Maintain and test incident response playbooks; lead technical response and forensic analysis during ... Contribute to the security questionnaire and RFP response library, serving as the technical author ...

... security questionnaire review, SOC 2 report review , architecture and access considerations ... Perform control gap analyses, document findings, assess control maturity, and develop remediation ...

GRC Analyst

Fairfax, VA ยท On-site

$75K - $95K/yr

Completed a customer or vendor security questionnaire using documented evidence. * Kept a tracker ... As GRC Analyst, you will see your work in every certification we hold and every customer ...

... analysis through audit and maintenance; familiar with GDPR, PCI DSS, and the EU AI Act. * Deep ... A strong writer and communicator who can turn around a 200-row security questionnaire quickly and ...

$75K - $95K/yr

Completed a customer or vendor security questionnaire using documented evidence. * Kept a tracker ... As GRC Analyst, you will see your work in every certification we hold and every customer ...

Security & Compliance Engineer

Seattle, WA ยท On-site

$150K - $215K/yr

Own the customer security-questionnaire pipeline so deals don't wait on engineering. Work directly ... You're not a spreadsheet-only GRC analyst, and you're not a strategy-only leader who won't get ...

... analysis, data processing agreement reviews, and security questionnaire management. [10%] Incident Response & Security Monitoring - Monitor AI platform security posture using Azure Sentinel (SIEM ...

... 2 report analysis, data processing agreement reviews, and security questionnaire management.**[10%] Incident Response & Security Monitoring**- Monitor AI platform security posture using Azure ...

The IT GRC Analyst will leverage GRC tooling to automate and streamline compliance monitoring ... Support third-party risk management activities including vendor intake, security questionnaire ...

next page

Showing results 1-20

Security Questionnaire Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do security questionnaire analyst jobs pay per year?

As of Sep 11, 2026, the average yearly pay for security questionnaire analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is a security questionnaire analyst?

Security Questionnaire Analysts are professionals responsible for reviewing, completing, and managing security questionnaires that assess an organization's cybersecurity posture. They typically respond to detailed inquiries from clients, partners, or regulatory bodies about the company's security controls, policies, and practices. Their work ensures that the organization can demonstrate compliance with industry standards and customer requirements, helping to build trust and support business relationships. These analysts often collaborate with IT, legal, and compliance teams to gather accurate information and provide thorough, timely responses.

What are common challenges faced by security questionnaire analysts when working with client security assessments?

Security Questionnaire Analysts often encounter challenges such as interpreting complex questions, gathering accurate information from various internal stakeholders, and meeting tight client deadlines. Navigating differing security standards and frameworks between clients can also require adaptability and strong communication skills. Additionally, ensuring consistency and accuracy in responses is crucial, as these assessments can directly impact business relationships and compliance outcomes.

What are the key skills and qualifications needed to thrive as a security questionnaire analyst, and why are they important?

To thrive as a Security Questionnaire Analyst, you need a solid understanding of information security principles, risk management, and compliance frameworks, typically supported by a degree in cybersecurity or related fields. Familiarity with security assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CISSP or CISA is often expected. Attention to detail, strong communication, and analytical thinking are crucial soft skills for efficiently interpreting requirements and collaborating with stakeholders. These skills ensure accurate evaluation of vendor security postures, effective risk mitigation, and clear communication of findings to protect organizational assets.

What are popular job titles related to Security Questionnaire Analyst jobs?

For Security Questionnaire Analyst jobs, the most frequently searched job titles are:

Infographic showing various Security Questionnaire Analyst job openings in the United States as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $107,334 per year, or $51.6 per hour.

Senior Engineer, Security & Compliance (US)

Austin, TX โ€ข On-site

$113K - $155K/yr

Other

Re-posted 7 days ago


Key responsibilities

  • Build and maintain security controls across cloud infrastructure and SaaS products, including identity and access, encryption, logging, monitoring, secrets management, and multi-tenancy patterns

  • Own the technical implementation of compliance standards such as SOC 2 Type II, ISO 27001, and ISO 42001 by building evidence pipelines, automating control testing, and maintaining audit artifacts

  • Instrument and operate security monitoring and alerting across cloud environments, including threat detection, log aggregation, and response


Job description

The Machine is the agentic operating system for marketing, built by Code & Theory. It plugs into the tools marketing teams use and turns disconnected workflows into a single intelligent system, connecting brand strategy, creative production, and media performance. The Machine helps power agencies across Stagwell's network and worldโ€‘leading brands.

We're looking for a Senior Security Engineer to be the handsโ€‘on technical backbone of our security and compliance program across our SaaS products and client delivery work. This role would own the implementation โ€” building the controls, tooling, automation, and processes that make our security program real. You'll work directly with engineering teams, embed into delivery workflows, and be the person who actually builds and runs the systems that keep our products and client data secure.

Our engineers are AI native and engage in and advance the state of the art in the practice of software development flow with AI.

WHAT YOU'LL DO
  • Build and maintain security controls across our cloud infrastructure and SaaS products โ€” identity and access, encryption, logging, monitoring, secrets management, and multiโ€‘tenancy patterns
  • Own the technical implementation of SOC 2 Type II, ISO 27001, and ISO 42001 compliance โ€” building evidence pipelines, automating control testing, and maintaining audit artifacts
  • Instrument and operate security monitoring and alerting across cloud environments (GCP, AWS, and/or Azure), with handsโ€‘on responsibility for threat detection, log aggregation, and response
  • Partner with engineering teams to embed security into CI/CD pipelines โ€” vulnerability scanning, SAST/DAST tooling, dependency management, container security, and secure code review
  • Implement privacy controls in product and client environments, including data classification, retention, access controls, and audit logging aligned to HIPAA, GDPR, and CCPA/CPRA requirements
  • Execute the client engagement security model โ€” provisioning and deprovisioning access, configuring environment segregation, and meeting clientโ€‘specific delivery security requirements
  • Conduct handsโ€‘on vendor security assessments, reviewing thirdโ€‘party architectures, configurations, and data handling practices
  • Maintain and test incident response playbooks; lead technical response and forensic analysis during security events
  • Build and maintain AIโ€‘specific security controls โ€” reviewing model inputs/outputs, securing agent workflows, managing prompt injection and data leakage risks in AIโ€‘enabled products
  • Contribute to the security questionnaire and RFP response library, serving as the technical author for detailed customer assurance requests
WHAT YOU'LL NEED
  • 5+ years of handsโ€‘on security engineering experience, ideally spanning SaaS product environments and/or professional services/agency delivery
  • Deep practical knowledge of cloud security in at least one major platform (GCP, AWS, or Azure) โ€” IAM, networking, secrets management, logging, and security tooling
  • Handsโ€‘on experience with SOC 2 Type II and ISO 27001 control implementation โ€” not just familiarity with frameworks, but actually building and operating the controls
  • Experience building security automation across CI/CD pipelines โ€” integrating vulnerability scanners, SAST/DAST tools, and policy enforcement into engineering workflows
  • Working knowledge of privacy regulations (HIPAA, GDPR, CCPA/CPRA) and experience implementing technical controls that operationalize compliance requirements
  • Proficiency with security monitoring and SIEM tooling โ€” building detection logic, tuning alerts, and responding to incidents with real technical depth
  • Strong communication skills โ€” you can explain a complex finding clearly to an engineer, a PM, or a client, and write a crisp, credible response to a security questionnaire
  • Comfort working across a distributed, fastโ€‘moving organization with multiple concurrent workstreams
  • Experience working with AIโ€‘enabled development tools and integrating security thinking into AIโ€‘assisted workflows
  • Handsโ€‘on experience reviewing and hardening AI agent workflows โ€” understanding risks like prompt injection, data leakage, and model misuse in production systems
  • Comfortable leveraging AIโ€‘enabled development tools and workflows to accelerate engineering, automation, debugging, and operational tasks
  • Experience orchestrating multiโ€‘step AI or agentโ€‘driven workflows, including selecting appropriate models, tools, and execution patterns for different use cases
  • Strong judgment reviewing and hardening AIโ€‘assisted output for security, scalability, maintainability, and architectural fit
  • Experience building or maintaining prompts, evaluation frameworks, documentation, or operational context systems that improve engineering velocity and reliability
  • Familiarity with automated evaluation and feedback loops for AIโ€‘enabled systems and workflows
NICE TO HAVE
  • Experience in agency, consultancy, or enterprise SaaS environments where you've had to meet varying client security requirements
  • Familiarity with ISO 42001 and AI governance frameworks
  • Experience securing multiโ€‘tenant SaaS architectures at the infrastructure and application layer
  • Relevant certifications: CISSP, CCSP, AWS/GCP/Azure Security Specialty, CIPP, or similar
  • Experience with infrastructureโ€‘asโ€‘code security tooling (e.g., Checkov, tfsec, OPA/Rego)
ABOUT US

Born in 2001, Code and Theory is a digitalโ€‘first creative agency that sits at the center of creativity and technology. We pride ourselves on not only solving consumer and business problems, but also helping to establish new capabilities for our clients. With a global client roster of Fortune 100s and startโ€‘ups alike, we crave the hardest problems to solve. We have teams distributed across North America, South America, Europe, and Asia. The Code and Theory global network of agencies is growing and includes Kettle, Instrument, Left Field Labs, Create Group, Current, and TrueLogic.

Striving never to be pigeonholed, we work across every major category: from tech to CPG, financial services to travel & hospitality, government and education to media and publishing. We value the collaboration with our client partners, including but not limited to Adidas, Amazon, Con Edison, Diageo, EY, J.P. Morgan Chase, Lenovo, Marriott, Mars, Microsoft, Thomson Reuters, and TikTok.

The Code and Theory network is comprised of nearly 2,000 people with 50% engineers and 50% creative talent. Weโ€™re always on the lookout for smart, driven, and forwardโ€‘thinking people to join our team.

The base compensation range for this role is $110,000 โ€“ $150,000 and spans multiple levels. We're open to hiring at the level that best matches the right candidate's experience. Actual compensation is influenced by a wide array of factors including but not limited to skill set, level of experience, budget, and location.

#J-18808-Ljbffr