Jobs
Required Skills
GRC
Risk Management
Compliance
Audit
Security Policy Development
At JFrog, we’re reinventing DevOps to help the world’s greatest companies innovate - and we want you along for the ride. This is a special place with a unique combination of brilliance, spirit, and just all-around great people. Here, if you’re willing to do more, your career can take off. And since software plays a central role in everyone’s lives, you’ll be part of an important mission. Thousands of customers, including 75% of the Fortune 100, trust JFrog to manage, accelerate, and secure their software delivery from code to production - a concept we call “liquid software.” Wouldn't it be amazing if you could join us in our journey?
We're looking for a Senior Governance, Risk, and Compliance (GRC) Specialist to join our global GRC team. In this critical role, you will help secure the JFrog platform that powers the software supply chain for thousands of the world's top organizations.
Reporting to the GRC Manager, you will work alongside a talented team to enhance our security posture, establish GRC best practices, and embed security governance into our fast-paced, DevOps-driven culture. You will be a key advisor, helping to translate complex risks and compliance requirements into actionable controls that support JFrog's mission.
As a Senior GRC specialist at JFrog you will...
-
Drive Security Framework Adoption (New Markets): Lead the strategic adoption of net-new security frameworks to unlock business markets.
-
Oversee the Security Certification Program: Oversee the end-to-end execution of our security assurance portfolio (ISO 27001, SOC 2).
-
Lead Security Audits: Serve as a primary GRC contact for internal and external audits. You'll coordinate evidence gathering, craft management responses, and drive the remediation of findings.
-
Lead Governance Initiatives: Develop, maintain, and enhance the enterprise-wide security GRC framework, policies, standards, and procedures, ensuring they align with our cloud-native and SaaS environment.
-
Risk Management & TPRM: Evolve our Third-Party (TPRM) and Internal Security Risk programs, including executing and documenting comprehensive risk assessments, ensuring that findings are remediated and clearly aligned with JFrog’s risk appetite.
-
Collaborate Cross-Functionally: Partner with engineering, product, IT, and legal teams to embed security controls into daily business operations, ideally automated.
-
Mentor & Advise: Act as a subject matter expert on governance and risk for the wider organization and provide mentorship to junior GRC team members.
To be a Senior GRC specialist at JFrog you need…
-
5+ years of direct experience in Information Security GRC, Risk Management, or Audit, preferably acquired within a high-growth SaaS or cloud-native environment.
-
A proactive, self-starting mentality with strong analytical, project management, and problem-solving skills, with proven ability to validate your own work and drive tasks to completion independently.
-
Demonstrable expertise in managing core compliance programs (SOC 2, ISO 27001)
-
Experience pursuing net-new compliance certifications and initiatives (e.g., R, C5, TISAX, IRAP).
-
Experience developing, drafting, and implementing security policies and standards from the ground up in a tech-focused environment, harmonizing controls across frameworks to create agile standards.
-
Experience leading complex security audits, serving as a primary liaison and "in-the-room" lead during internal and external audits.
-
Strong understanding of information security principles, risk management, and control frameworks in a cloud-first environment (AWS, GCP, Azure).
-
Exceptional communication and interpersonal skills, with a proven ability to build relationships and influence change across engineering, product, and business teams, and the ability to write concise, "Executive Ready" policies and risk reports.
-
Hands-on experience with GRC platforms and a drive to automate manual GRC workflows.
-
Bachelor’s degree in Cybersecurity, Information Technology, Law, or a related field, or equivalent practical experience.
Preferred Qualifications
-
Advanced Framework Knowledge: experience with pursuing and implementing advanced security frameworks such as IRAP, NIST CSF, and FedRAMP.
-
Experience leading formal risk assessments using established methodologies (e.g., NIST RMF).
-
Familiarity with emerging AI regulations (e.g., EU AI Act, NIST AI RMF) and experience applying governance and security frameworks to AI/ML models.
-
Familiarity with the intersection of privacy laws (GDPR, CCPA) and cybersecurity regulations (DORA, SEC Rules)
-
One or more of the following professional certifications, such as CISSP, CISM, CRISC, or CISA.
-
Knowledge of DevOps principles, CI/CD pipelines, and software supply chain security concepts
-
Experience with building automated workflows to streamline compliance tasks, scripting, and integrations.
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs
About JFrog

JFrog
PublicJFrog provides DevOps and DevSecOps platform solutions for software development and distribution. The company offers tools for artifact management, security scanning, and CI/CD pipeline automation.
1,001-5,000
Employees
Bozeman
Headquarters
$1.5B
Valuation
Reviews
2.6
9 reviews
Work Life Balance
2.3
Compensation
4.0
Culture
2.8
Career
3.2
Management
2.1
35%
Recommend to a Friend
Pros
Good compensation and benefits
Supportive team and welcoming environment
Fast-paced and innovative culture
Cons
Poor management and micromanagement
Toxic and fearful work environment
Fast-paced changes and unrealistic expectations
Salary Ranges
89 data points
Junior/L3
Senior/L5
Junior/L3 · Business Development Representative (BDR)
6 reports
$81,624
total / year
Base
$58,363
Stock
-
Bonus
-
$55,299
$124,042
Interview Experience
35 interviews
Difficulty
3.4
/ 5
Duration
14-28 weeks
Offer Rate
40%
Experience
Positive 62%
Neutral 22%
Negative 16%
Interview Process
1
Phone Screen
2
Technical Interview
3
Hiring Manager
4
Team Fit
Common Questions
Technical skills
Past experience
Team collaboration
Problem solving
News & Buzz
Teacher Retirement System of Texas Increases Stake in JFrog Ltd. $FROG - MarketBeat
Source: MarketBeat
News
·
5w ago
JFrog: Re-Accelerating Growth Supports Further Upside (NASDAQ:FROG) - Seeking Alpha
Source: Seeking Alpha
News
·
5w ago
JFrog Joins Rank Of Stocks With 95-Plus Composite Rating - Investor's Business Daily
Source: Investor's Business Daily
News
·
5w ago
Total Economic Impact Study: JFrog Unifies and Accelerates the Secure Software Supply Chain from Code to AI - Business Wire
Source: Business Wire
News
·
6w ago



