Skip to content

Open nowPosted 14 hours ago

Staff Security GFC Analyst

Suno70 open roles

Pay
$276,960 – $363,510 a year
Where
NYC
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Security GFC AnalystSuno · NYC
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Suno's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Suno postings stay open a median of 30 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 14 hours ago

Suno median: 30 days open

The posting

ABOUT SUNO

We're building the world's first creative entertainment platform, where the entire world can feel the joy and fulfillment of making music. Music is for everyone: Our users include everyone from grandmothers creating songs for their loved ones, to Grammy winners using Suno Studio, our power tool, to make the most popular hits in the world.

Building the future of entertainment requires ambition. The pace is fast, the problems are hard, and the work demands ownership and intensity. For the right people, it’s incredibly rewarding: a chance to shape a new medium, work with a small team that cares deeply about quality, make music, drink too much coffee, and build something that millions of people use to express themselves in ways that were never before possible.

Suno is the fastest growing consumer entertainment company and the leader in AI music. We are backed by leading investors including Bond Capital, Menlo Ventures, Lightspeed Venture Partners, IVP, Forerunner, Union Square Ventures, Alkeon, Quiet, Matrix Partners, Schroders Capital and, NVentures (venture arm of NVIDIA).

ABOUT THE ROLE

We're looking for a Staff Security GRC Analyst to build Suno's security compliance program from the ground up. You'll report to our CISO, work alongside our AppSec and InfraSec teams, and own the control framework that ties everything together: which controls we have, how they map to SOC 2 and NIST CSF, and whether they actually work. You're as comfortable reading a cloud config as an audit standard, and you'd rather automate evidence collection with AI than chase screenshots. It's a greenfield build with real stakes and a direct line to leadership.

Listen to the song we made about it: https://suno.com/s/8U6fbhqLEghsnRsm

WHAT YOU'LL DO

- Build and own Suno's security control framework, mapping controls to SOC 2, NIST CSF, and future frameworks, and writing control descriptions with the teams who run them.

- Lead SOC 2 preparation end to end, from gap assessments and readiness tracking to driving remediation with control owners and working with our external auditor.

- Automate evidence collection and control monitoring with scripts, integrations, and AI tools, deciding where human review stays in the loop.

- Run vendor security reviews, keep our security policies current, and answer customer security questionnaires alongside Product and Legal.

- Partner with the CISO to give leadership and the board a clear, evidence-backed view of our security posture, and lay the foundations of GRC as part of a growing Security team.

- Help earn the trust of the partners and customers who bring Suno to more people, so creating music can be part of everyone's day.

WHAT YOU'LL NEED

MUST-HAVES

- 7–9 years in GRC, security compliance, or IT audit.

- Hands-on, end-to-end ownership of a security compliance program as its primary owner, ideally including taking a company through its first SOC 2.

- Deep working knowledge of SOC 2 and NIST CSF, including control mapping, audit mechanics (design vs. operating effectiveness, sampling, evidence), and staying current as requirements evolve.

- Enough technical fluency to read a cloud configuration, access setup, or pipeline and judge whether it enforces what the control says. You don't need to write production code.

- Comfort building your own automation with scripts or AI tools.

NICE-TO-HAVES

- Experience standing up continuous controls monitoring or automated evidence collection, including what it covered and what changed as a result.

- Experience applying LLMs to assurance work, such as control drafting, framework mapping, or evidence testing.

- Experience with cloud environments such as AWS or GCP, and with a modern GRC platform.

- Certifications such as CISA, CISSP, or CRISC.

Suno is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the Massachusetts Fair Chance in Employment Act, NYC Fair Chance Act, LA City Fair Chance Ordinance, and San Francisco Fair Chance Ordinance.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Suno's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Suno's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Suno's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.