Senior Technical Risk & Compliance Analyst
Job Description
At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. The work location of this role is hybrid, meaning it will be performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team.
LinkedIn is seeking a Senior Technical Risk & Compliance Engineer to support the end-to-end GRACE lifecycle across Security. Governance, Risk, Automation, Compliance & Engineering (GRACE) helps LinkedIn build and maintain a secure, scalable, and sustainable compliance environment. We partner across Security, Engineering, Legal, Privacy, Audit, and other teams to translate risk and compliance requirements into controls that can be implemented, monitored, and continuously improved.
In this role, you will independently own defined Security risk and compliance areas, taking them from initial onboarding and risk assessment through control design, implementation partnership, assurance, continuous controls monitoring, and improvement.
You will work closely with Security and Engineering teams to translate security, regulatory, policy, and assurance requirements into actionable control requirements; evaluate how those controls are implemented across systems; identify and drive remediation of gaps; and establish monitoring that provides ongoing visibility into control health.
This role requires a combination of technical depth and risk and compliance expertise. The ideal candidate can understand modern security systems and technical architectures, analyze data and technical artifacts, and translate risk and compliance requirements into practical solutions that scale.
Our goal is to move compliance away from fragmented, point-in-time activities toward a lifecycle where requirements, risks, controls, evidence, and monitoring are connected, enabling compliance to scale with LinkedIn’s technology and business.
Responsibilities
Drive the End-to-End Technical Governance, Risk & Compliance Lifecycle for Security
• Independently own defined Security areas through the GRACE lifecycle, from initial risk and compliance onboarding through continuous monitoring and improvement.
• Evaluate applicable regulatory, security, policy, customer, and assurance requirements and map them to risks, control objectives, controls, systems, and accountable owners.
• Assess current systems, processes, and existing controls to identify coverage and compliance gaps.
• Translate identified risks and requirements into clear, measurable control objectives and technical control requirements.
• Maintain accurate requirement-to-risk-to-control mappings and supporting documentation in compliance systems of record.
Design and Codify Controls
• Partner with Security and Engineering teams to translate control requirements into practical, testable controls within systems and engineering workflows.
• Evaluate system architecture, data flows, configurations, access models, logs, scripts, queries, code, and other technical artifacts to understand how controls address identified risks.
• Review existing control design and implementation and recommend improvements where controls do not sufficiently address requirements or risks.
• Identify opportunities to embed and automate controls within engineering workflows, platforms, infrastructure, and security systems.
• Ensure controls have clear ownership, expected evidence, testable criteria, and monitoring requirements.
Establish Continuous Controls Monitoring
• Translate control design and effectiveness criteria into measurable monitoring requirements.
• Use system-generated data, dashboards, telemetry, logs, configurations, and other technical signals to monitor control execution, exceptions, and control health.
• Partner with Engineering and Security teams to establish automated monitoring and evidence generation where feasible.
• Identify control failures, anomalies, exceptions, and emerging compliance gaps and work with control owners to prioritize remediation based on risk.
• Help transition assigned Security areas from point-in-time evidence collection and assessments toward continuous controls monitoring and audit-ready-by-default compliance.
• Identify opportunities to reduce manual compliance activities through reusable control monitoring, evidence pipelines, and automation.
Assurance, Remediation & Improvement
• Perform readiness assessments to evaluate whether controls are appropriately designed and operating as intended before relying on them for continuous monitoring and assurance.
• Support internal and external assessments, certifications, audits, and regulatory requirements with reliable, reusable technical evidence and control documentation.
• Coordinate remediation of identified control gaps and findings, including root-cause analysis, risk-based prioritization, and issue tracking through closure.
• Analyze monitoring results, exceptions, findings, and recurring issues to identify systemic patterns and recommend durable improvements.
• Feed insights from monitoring and assurance back into risk assessments, policies, control design, and monitoring requirements to continuously improve the Security compliance posture.
Security Compliance Coverage
The role may support risk and compliance activities across Security areas including:
• Identity and Access Management and Privileged Access Management
• Application Security and Secure Software Development
• Cloud and Infrastructure Security
• Vulnerability Management
• Data Protection, Encryption, Key and Secrets Management
• Security Logging, Monitoring, Detection, and Incident Response
• Software Supply Chain and Third-Party Security
• Security Resilience and Business Continuity
• AI Security and emerging technology risk
• Security governance, policies, standards, and exceptions
The successful candidate is not expected to be an expert in every Security domain, but should bring strong technical risk and compliance depth in one or more areas and be able to apply that foundation across adjacent Security domains.
Requirements
Department: Engineering
Function: Sales
Experience Level: Mid-Senior Level