LI

Senior Technical Risk & Compliance Analyst

Salary
$143K–$218K
USD
Hiring from
United States
Work type
Hybrid
Posted
Oct 1, 2026
Is this job info correct?

LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed.

Join us to transform the way the world works.

At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. The work location of this role is hybrid, meaning it will be performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team.

LinkedIn is seeking a Senior Technical Risk & Compliance Engineer to support the end-to-end GRACE lifecycle across Security. Governance, Risk, Automation, Compliance & Engineering (GRACE) helps LinkedIn build and maintain a secure, scalable, and sustainable compliance environment. We partner across Security, Engineering, Legal, Privacy, Audit, and other teams to translate risk and compliance requirements into controls that can be implemented, monitored, and continuously improved.

In this role, you will independently own defined Security risk and compliance areas, taking them from initial onboarding and risk assessment through control design, implementation partnership, assurance, continuous controls monitoring, and improvement.

You will work closely with Security and Engineering teams to translate security, regulatory, policy, and assurance requirements into actionable control requirements; evaluate how those controls are implemented across systems; identify and drive remediation of gaps; and establish monitoring that provides ongoing visibility into control health.

This role requires a combination of technical depth and risk and compliance expertise. The ideal candidate can understand modern security systems and technical architectures, analyze data and technical artifacts, and translate risk and compliance requirements into practical solutions that scale.

Our goal is to move compliance away from fragmented, point-in-time activities toward a lifecycle where requirements, risks, controls, evidence, and monitoring are connected, enabling compliance to scale with LinkedIn’s technology and business.

Responsibilities

Drive the End-to-End Technical Governance, Risk & Compliance Lifecycle for Security

  • Independently own defined Security areas through the GRACE lifecycle, from initial risk and compliance onboarding through continuous monitoring and improvement.
  • Evaluate applicable regulatory, security, policy, customer, and assurance requirements and map them to risks, control objectives, controls, systems, and accountable owners.
  • Assess current systems, processes, and existing controls to identify coverage and compliance gaps.
  • Translate identified risks and requirements into clear, measurable control objectives and technical control requirements.
  • Maintain accurate requirement-to-risk-to-control mappings and supporting documentation in compliance systems of record.

Design and Codify Controls

  • Partner with Security and Engineering teams to translate control requirements into practical, testable controls within systems and engineering workflows.
  • Evaluate system architecture, data flows, configurations, access models, logs, scripts, queries, code, and other technical artifacts to understand how controls address identified risks.
  • Review existing control design and implementation and recommend improvements where controls do not sufficiently address requirements or risks.
  • Identify opportunities to embed and automate controls within engineering workflows, platforms, infrastructure, and security systems.
  • Ensure controls have clear ownership, expected evidence, testable criteria, and monitoring requirements.

Establish Continuous Controls Monitoring

  • Translate control design and effectiveness criteria into measurable monitoring requirements.
  • Use system-generated data, dashboards, telemetry, logs, configurations, and other technical signals to monitor control execution, exceptions, and control health.
  • Partner with Engineering and Security teams to establish automated monitoring and evidence generation where feasible.
  • Identify control failures, anomalies, exceptions, and emerging compliance gaps and work with control owners to prioritize remediation based on risk.
  • Help transition assigned Security areas from point-in-time evidence collection and assessments toward continuous controls monitoring and audit-ready-by-default compliance.
  • Identify opportunities to reduce manual compliance activities through reusable control monitoring, evidence pipelines, and automation.

Assurance, Remediation & Improvement

  • Perform readiness assessments to evaluate whether controls are appropriately designed and operating as intended before relying on them for continuous monitoring and assurance.
  • Support internal and external assessments, certifications, audits, and regulatory requirements with reliable, reusable technical evidence and control documentation.
  • Coordinate remediation of identified control gaps and findings, including root-cause analysis, risk-based prioritization, and issue tracking through closure.
  • Analyze monitoring results, exceptions, findings, and recurring issues to identify systemic patterns and recommend durable improvements.
  • Feed insights from monitoring and assurance back into risk assessments, policies, control design, and monitoring requirements to continuously improve the Security compliance posture.

Security Compliance Coverage

The role may support risk and compliance activities across Security areas including:

  • Identity and Access Management and Privileged Access Management
  • Application Security and Secure Software Development
  • Cloud and Infrastructure Security
  • Vulnerability Management
  • Data Protection, Encryption, Key and Secrets Management
  • Security Logging, Monitoring, Detection, and Incident Response
  • Software Supply Chain and Third-Party Security
  • Security Resilience and Business Continuity
  • AI Security and emerging technology risk
  • Security governance, policies, standards, and exceptions

The successful candidate is not expected to be an expert in every Security domain, but should bring strong technical risk and compliance depth in one or more areas and be able to apply that foundation across adjacent Security domains.

Basic Qualifications:

  • BA/BS degree in Computer Science, Engineering, Information Systems, or a related technical discipline, or equivalent practical experience.
  • 5+ years of experience in technical risk, security compliance, technology compliance, security engineering, technical audit/assurance, or a related field.
  • Experience translating security, regulatory, policy, or assurance requirements into technical or operational controls.
  • Experience assessing technical control design and implementation and identifying control or compliance gaps.
  • Experience analyzing technical artifacts such as system designs, configurations, logs, data, scripts, queries, or code to understand control implementation.
  • Experience partnering with Engineering or Security teams to address technical risk and compliance requirements.
  • Ability to independently manage an assigned risk or compliance area, prioritize competing requirements, and clearly communicate technical risks and remediation needs.

Preferred Qualifications:

  • Experience across Security domains such as IAM, Application Security, Cloud and Infrastructure Security, Vulnerability Management, Data Protection, Security Operations, Resilience, or Software Supply Chain Security.
  • Experience with security and assurance frameworks such as ISO 27001, SOC 2, PCI DSS, NIST, or comparable regulatory and industry frameworks.
  • Experience working with large-scale distributed systems, cloud infrastructure, or modern software development environments.
  • Experience using data, telemetry, dashboards, and automated workflows to evaluate control effectiveness and identify risk.
  • Experience designing or supporting continuous controls monitoring, automated evidence collection, or compliance automation.
  • Experience with GRC systems, risk registers, control inventories, evidence pipelines, and compliance systems of record.
  • Experience supporting security assessments, certifications, audits, or regulatory reviews.
  • Ability to identify systemic patterns across control gaps and findings and translate them into scalable technical or process improvements.
  • Relevant professional certifications such as CISSP, CISA, or equivalent.

Suggested Skills:

  • Strong technical fluency across modern engineering and security environments.
  • Strong understanding of security risk, controls, and compliance principles.
  • Ability to connect requirements → risks → controls → evidence → monitoring → improvement.
  • Strong analytical skills and comfort working with technical and compliance data.
  • Ability to bridge risk and compliance requirements with Engineering and Security implementation.
  • Independent, pragmatic, and comfortable operating in evolving technical and regulatory environments.

You will Benefit from our Culture:

We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels.

LinkedIn is committed to fair and equitable compensation practices.

The pay range for this role is $143,000 to $218,000. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to skill set, depth of experience, certifications, and specific work location. This may be different in other locations due to differences in the cost of labor.

The total compensation package for this position may also include annual performance bonus, stock, benefits and/or other applicable incentive compensation plans. For more information, visit https://careers.linkedin.com/benefits.

Equal Opportunity Statement

We seek candidates with a wide range of perspectives and backgrounds and we are proud to be an equal opportunity employer. LinkedIn considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

LinkedIn is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. Our goal is to foster an inclusive and accessible workplace where everyone has the opportunity to be successful.

If you need a Reasonable Accommodation to search for a job opening, apply for a position, or participate in the interview process, connect with us and describe the specific Accommodation requested for a disability-related limitation.
Fill out an Accommodation request here: https://app.smartsheet.com/b/form/b660a0327d044969abfd7a4e73d15c36

Reasonable accommodations are modifications or adjustments to the application or hiring process that would enable you to fully participate in that process. Examples of reasonable accommodations include but are not limited to:

  • Documents in alternate formats or read aloud to you
  • Having interviews in an accessible location
  • Being accompanied by a service dog
  • Having a sign language interpreter present for the interview

A request for an accommodation will be responded to within three business days. However, non-disability related requests, such as following up on an application, will not receive a response.

LinkedIn will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by LinkedIn, or (c) consistent with LinkedIn's legal duty to furnish information.

San Francisco Fair Chance Ordinance ​

Pursuant to the San Francisco Fair Chance Ordinance, LinkedIn will consider for employment qualified applicants with arrest and conviction records.

Pay Transparency Policy Statement ​

As a federal contractor, LinkedIn follows the Pay Transparency and non-discrimination provisions described at this link: https://lnkd.in/paytransparency.

Global Data Privacy Notice and Compliance Posters for Job Candidates

Please use this link to access documents that provide information about how LinkedIn handles the personal data of employees and job applicants, as well as the E-Verify Participation Notice and the Department of Justice Immigrant and Employee Rights Section Right to Work posters: https://www.linkedin.com/legal/candidate-portal.

Similar jobs

Apply for this job