Senior Information Security Analyst, GRC/Responsible AI at Sandisk
Irvine, CA
—
Jul 19, 2026
Irvine, CA
Jul 21, 2026
What this job asks for AI summary
A senior individual-contributor role focused on two connected areas: governing the secure adoption of generative AI across the enterprise, and maintaining broader information security risk management practices. Day-to-day work spans AI risk assessments, threat modeling, control design, policy development, and audit support, with regular collaboration across Legal, IT, Procurement, and Engineering. Suits an experienced security professional comfortable bridging technical depth with cross-functional governance.
Senior level · 6+ years · San Jose-Sunnyvale-Santa Clara, CA · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
What the occupation pays Median $179,993 (middle half $128,832–$221,179).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (7)
The role is on-site five days per week at either Milpitas or Irvine, CA. The CBSA is set to San Jose-Sunnyvale-Santa Clara (Milpitas) as the first-listed location; Irvine falls under the Los Angeles-Long Beach-Anaheim CBSA — candidates may be based at either site.
No explicit salary range is stated in the posting; the compensation section describes the pay philosophy and eligibility for STI/LTI but provides no dollar figures.
The degree requirement is listed as 'Bachelor's degree … or equivalent experience,' so no hard degree gate is set.
CISSP, CISM, CRISC, and GSNA are grouped together as interchangeable preferred certifications; GCIH, GPEN, CEH, OSCP, GWAPT, and CSSLP are similarly grouped as a second preferred certification cluster — both sets appear under the Preferred section.
STRIDE and PASTA appear under Preferred as example threat modeling methodologies; they are listed as alternatives to each other since the JD treats them as interchangeable options for the same requirement.
AI red teaming and exposure to agentic/AI integration patterns appear only under Preferred.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): OWASP LLM Top 10.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.