Sandisk

Sandisk

Senior Information Security Analyst, GRC/Responsible AI

Irvine, CA, United States · Senior

Sponsorship not specifiedDetected 1 day ago
CI/CDMachine LearningLLMsAgentic AICybersecurityComplianceSupply ChainProcurementCommunicationCISSP

About the role

  • With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we're living in and that we have the power to shape.
  • Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward.

Responsibilities

  • Drive security intake, risk assessment, and ongoing oversight of enterprise AI use cases, platforms, models, and third-party vendors.
  • Lead technical risk assessments and threat modeling covering data protection, identity and access, integration patterns, model and agent behavior, and emerging AI attack surfaces.
  • Design and recommend practical, scalable controls aligned with enterprise security standards and secure-by-design principles.
  • Partner with Legal, Privacy, Procurement, IT, Engineering, and business stakeholders to advance regulatory, contractual, and governance objectives related to AI.
  • Help build the end-to-end operating model for securing AI, from intake through approval and monitoring.
  • Apply program and system-level thinking across functions to drive consistency and scale.
  • Conduct technical and business process risk assessments and document treatment recommendations.
  • Support internal and external audits with metrics, evidence, and analysis, and drive remediation activities.
  • Familiarity with secure development practices, secure-by-design principles, and modern engineering environments such as cloud, APIs, containers, and CI/CD pipelines.
  • Ability to influence and drive outcomes in cross-functional, matrixed environments.

Requirements

  • Bachelor's degree in information security, Computer Science, Engineering, or a related discipline, or equivalent experience.
  • 6+ years of progressive experience in Information Security, including exposure to GRC, risk management, or security governance in a complex enterprise environment.
  • Demonstrated technical proficiency in security, including hands-on experience with threat modeling, technical risk assessment, or security architecture reviews.
  • Familiarity with AI governance standards such as NIST AI RMF and ISO/IEC 42001.

Nice to have

  • Background in software development, security engineering, application security, cloud security, or security architecture.
  • Experience applying threat modeling methodologies (such as STRIDE, PASTA, or attack tree analysis) to enterprise systems or AI workloads.
  • Professional certifications such as CISSP, CISM, CRISC, or GSNA.
  • Technical security certifications such as GCIH, GPEN, CEH, OSCP, GWAPT, or CSSLP.
  • Hands-on experience with AI, ML, or generative AI in a security, risk, engineering, or architecture capacity.
  • Exposure to emerging AI integration patterns, agentic systems, or AI red teaming.
  • Effective communication skills, with the ability to explain complex technical and AI concepts to a range of audiences.
  • Pragmatic, outcome-focused, and comfortable operating in ambiguity.

Skills

  • These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations.
  • This position requires five days per week on-site at either the Milpitas or Irvine office.
  • Senior Information Security Analyst, GRC and Responsible AI

Compensation

  • The salary range is what we believe to be the range of possible compensation for this role at the time of this posting.
  • We may ultimately pay more or less than the posted range and this range is only applicable for jobs to be performed in California, Colorado, New York or remote jobs that can be performed in California, Colorado and New York.
  • You will be eligible to participate in Sandisk's Short-Term Incentive (STI) Plan, which provides incentive awards based on Company and individual performance.
  • Depending on your role and your performance, you may be eligible to participate in our annual Long-Term Incentive (LTI) program, which consists of restricted stock units (RSUs) or cash equivalents, pursuant to the terms of the LTI plan.
  • Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission,

Benefits

  • Please note that not all roles are eligible to participate in the LTI program, and not all roles are eligible for equity under the LTI plan.
  • RSU awards are also available to eligible new hires, subject to Sandisk's Standard Terms and Conditions for Restricted Stock Unit Awards.
  • The amount and availability of any bonus, commission,
  • Strong intellectual curiosity and a self-driven approach to learning new technologies.

This listing is sourced directly from Sandisk's careers page and normalized into a canonical job model.