Security GRC Analyst
1 week ago
Company Description
When you join Turnitin, you'll be welcomed into a company that is a recognized innovator in the global education space. For over 25 years, Turnitin has partnered with educational institutions to promote honesty, consistency, and fairness across all subject areas and assessment types. Over 21,000 academic institutions, publishers, and corporations use our services: Feedback Studio, Originality, Gradescope, ExamSoft, Similarity, and iThenticate.
Experience a remote-centric culture that empowers you to work with purpose and accountability in a way that best suits you, supported by a comprehensive package that prioritizes your overall well-being. Our diverse community of colleagues are all unified by a shared desire to make a difference in education.
Turnitin is a global organization with team members in over 35 countries including the United States, Mexico, United Kingdom, Australia, Japan, India, and the Philippines.
Job Description
Turnitin is seeking an experienced Security GRC Analyst with Cloud/AWS skills to join our Security & Compliance team. The Security GRC Analyst will be responsible for ensuring that our information and cloud systems comply with relevant regulatory frameworks, industry standards, and internal policies. They will also collaborate with various departments, monitor compliance, conduct assessments, and support initiatives to identify and mitigate risks.
We are looking for someone who brings strong analytical ability, attention to detail, effective communication, compliance experience, and the willingness to continuously learn. This role requires hands-on work, critical thinking and the ability to find new solutions for compliance.
This role reports to the GRC Information Security Manager.
Responsibilities:
- Maintain compliance tracking capabilities to help ensure adherence with Turnitin's security program and industry standards such as NIST CSF, NIST 800-53, SOC 2, TX-RAMP and PCI DSS.
- Conduct risk and compliance assessments, audits, and risk evaluations to identify potential risk and compliance gaps.
- Lead preparation and audit activities required to maintain our SOC 2 Type 2.
- Collaborate with internal teams and external auditors for audit and compliance reviews.
- Collaborate with sales and customer support teams to respond to security questionnaires and security posture questions from customers.
- Support TPRM Program and conduct third-party risk assessments.
- Complete user access reviews.
- Administration of GRC platform.
- Participate in the development and documentation of security policy, standards and processes to align with company information security strategy.
- Provide security awareness and phishing training for employees and promote a culture of security and compliance.
- Coordinate phish testing.
- Collaborate with DevOps, IT, Legal, Engineering, People Team, and other departments to ensure security control and policy requirements are integrated into systems and business processes.
- Automate manual compliance tasks and improve team processes.
- Leverage AWS and Wiz for continuous monitoring.
- Measure effectiveness vs just implementation.
Work Hours:
Candidate must be willing to work according to U.S. Eastern Time (ET).
Qualifications
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent experience).
- 3+ years of experience in a role related to Information Security.
- 1+ years AWS Cloud Services and basic scripting.
- Professional certification such as CCSK, AWS Cloud Practitioner, or other related industry certification.
- Familiarity with cybersecurity frameworks and regulatory standards such as NIST, SOC 2, TX-RAMP, and PCI DSS.
- Familiarity of risk management and security best practices.
- Experience with assessing security controls, risk mitigation strategies, and audit procedures.
- Understanding of concepts related to AWS Cloud Infrastructure and security.
- Experience conducting security impact analysis for system changes.
- Experience conducting periodic internal security reviews or risk assessments to ensure that compliance procedures and technical configurations are followed.
- Experience conducting third-party risk assessments.
- Contract review experience for security requirements.
- Highly organized and proactive individual capable of managing multiple responsibilities and delivering results.
Preferred Skills:
- Experience running SOC 2 audits or NIST based authorizations.
- Experience using Jira and Confluence for project and task management.
- Hands-on experience with Wiz, KnowBe4, and Hyperproof.
- Experience conducting third-party risk assessments.
- Demonstrated knowledge of security assessment of cloud technology and services (AWS).
- Entry level cybersecurity certification such as Security+, GIAC GSEC, or ISC2 Certified in Cybersecurity.
Technical skills:
- Cloud Infrastructure with general knowledge of AWS services such as CloudFormation, Serverless, AWS Config, CloudTrail, IAM, and JSON
- Basic scripting
Additional Information
Total Rewards @ Turnitin
Turnitin maintains a Total Rewards package that is competitive within the local job market. People tend to think about their Total Rewards monetarily — solely as regular pay plus bonus or commission. This is what they earn in exchange for what they do. However, Turnitin delivers more than just these components. Beyond the intrinsic rewards of unleashing your potential to positively impact global education, and thriving in an organization that is free of politics and full of humble, inclusive and collaborative teammates, the extrinsic rewards at Turnitin include generous time off and health and wellness programs that offer choice and flexibility and provide a safety net for the challenges that life presents from time to time. Experience a remote-centric culture that empowers you to work with purpose and accountability in a way that best suits you, supported by a comprehensive package that prioritizes your overall well-being.
Our Mission
is to ensure the integrity of global education and meaningfully improve learning outcomes.
Our Values
underpin everything we do.
- Customer Centric
- We realize our mission to ensure integrity and improve learning outcomes by putting educators and learners at the center of everything we do.
- Passion for Learning
- We seek out teammates that are constantly learning and growing and build a workplace which enables them to do so.
- Integrity
- We believe integrity is the heartbeat of Turnitin. It shapes our products, the way we treat each other, and how we work with our customers and vendors.
- Action & Ownership
- We have a bias toward action and empower teammates to make decisions.
- One Team
- We strive to break down silos, collaborate effectively, and celebrate each other's successes.
- Global Mindset
- We respect local cultures and embrace diversity. We think globally and act locally to maximize our impact on education.
Global Benefits
- Remote First Culture
- Health Care Coverage*
- Education Reimbursement*
- Competitive Paid Time Off
- 4 Self-Care Days per year
- National Holidays*
- 2 Founder Days + Juneteenth Observed
- Paid Volunteer Time*
- Charitable contribution match*
- Monthly Wellness or Home Office Reimbursement/*
- Access to Modern Health (mental health platform)
- Parental Leave*
- Retirement Plan with match/contribution*
* varies by country
Seeing Beyond the Job Ad
At Turnitin, we recognize it's unrealistic for candidates to fulfill 100% of the criteria in a job ad. We encourage you to apply if you meet the majority of the requirements because we know that skills evolve over time. If you're willing to learn and evolve alongside us, join our team
Turnitin, LLC is committed to the policy that all persons have equal access to its programs, facilities and employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
-
Cyber Security Analyst
2 weeks ago
Manila, National Capital Region, Philippines Recoveriescorp Full time ₱40,000 - ₱80,000 per year493382Manila, Metro Manila, PhilippinesFull-timeClosing on: Nov At Symbos, security isn't just a function, it's the foundation of trust in everything we deliver. We create AI-led human experiences that connect people and technology with empathy and innovation. As part of our commitment to operational excellence, we're looking for a Cybersecurity Analyst who...
-
Cyber Security Consultant
2 weeks ago
Manila, National Capital Region, Philippines Risewave Consulting, Inc. Full time ₱600,000 - ₱1,200,000 per yearWe're Hiring: Cybersecurity ProfessionalsManila / Cebu / Quezon City|Onsite / Hybrid|Full-TimeJoin a growing cybersecurity team working on high-impact projects across multiple areas — from threat detection and automation to governance, risk, and intelligence.Cyber Security Engineer (SIEM/SOAR - Specialist to Manager Levels)Responsibilities:Manage and...
-
Technical Security
1 week ago
Manila, National Capital Region, Philippines eFlexervices Full time ₱900,000 - ₱1,200,000 per yearPlease submit your application via the link below:Who We AreeFlexervices is a BPO company with a legacy spanning 24 years. We've honed our craft in providing exceptional quality and building unshakable trust. At eFlex, we're not just a BPO company – we're your partners in success. Our approach is all about finding the perfect match between talent and the...
-
Security Analyst
2 weeks ago
Manila, National Capital Region, Philippines Cambridge University Press & Assessment Full time ₱60,000 - ₱81,000 per yearSalary:₱60,000 - ₱81,000- Location:Manila- Country:Philippines- Business Unit:Technology- Vacancy Type:Permanent- Closing Date:8 November 2025Meet the recruiterBeige SalesWork setup: We operate in a hybrid work environment, and we encourage applicants who are open to working in the office two days a week to apply.Work schedule: 15:00 to 23:00 Manila...
-
Sr. Manager, Information Security
2 weeks ago
Manila, National Capital Region, Philippines Dexcom Full time $100,000 - $150,000 per yearThe CompanyDexcom Corporation (NASDAQ DXCM) is a pioneer and global leader in continuous glucose monitoring (CGM). Dexcom began as a small company with a big dream: To forever change how diabetes is managed. To unlock information and insights that drive better health outcomes. Here we are 25 years later, having pioneered an industry. And we're just getting...
-
Security Analyst, InfoSec
2 weeks ago
Manila, National Capital Region, Philippines Kroll Global Solutions Inc. Full time $40,000 - $80,000 per yearOur professionals balance analytical skills, deep market insight and independence to deliver solid, defensible analysis and practical advice to our clients. As an organization, we think globally. We create transparency in an opaque world, and we encourage our people to do the same. That means when you take your place on our team, you'll discover a supportive...
-
Security Analyst
2 weeks ago
Manila, National Capital Region, Philippines Cambridge University Press & Assessment Full time ₱60,000 - ₱81,000 per yearWork setup: We operate in a hybrid work environment, and we encourage applicants who are open to working in the officetwo days a weekto apply.Work schedule: 15:00 to 23:00 Manila time, with flexibility during major incidents or to support shifting schedules.Employment type: PermanentLocation: Makati City, Metro ManilaPay range:We value transparency and want...
-
Senior Security and Operations Center Analyst
2 weeks ago
Manila, National Capital Region, Philippines UBX Full time ₱1,200,000 - ₱2,400,000 per yearThe SOC Analyst is responsible for monitoring, detecting and responding to security incidents. They will provide cybersecurity incident response support.Responsibilities:L1 to L3 Cybersecurity Incident Response SupportOn-call Incident Response support for Medium to Critical IncidentsDaily Cybersecurity Ticket ManagementDaily Cybersecurity Incident...
-
Security Operations Center Analyst
2 weeks ago
Manila, National Capital Region, Philippines Intelligent Technical Solutions Full time ₱680,320 per yearJob Description:As a SOC Analyst Level 1at Intelligent Technical Solutions, you will be the first line of defense in monitoring, analyzing, and responding to security threats. This position requires a hands-on approach to security operations, incident response, and threat detection. You will work closely with SOC leadership to ensure that security events...
-
Information Security Manager
2 weeks ago
Manila, National Capital Region, Philippines Nezda Global Full time ₱1,500,000 - ₱3,000,000 per yearAbout the RoleAsSecurity Engineer Manager – Safe Browsing, you'll lead a team of technical analysts and specialists focused on detecting and preventing web-based threats at scale. This role combines hands-on technical leadership with people management, process optimization, and collaboration across international security teams.Location:ManilaSetup:Hybrid...