Job Overview
Job description
- Location:
- Tel Aviv/ Netanya, Israel
- Work arrangement:
- On-site
Role Summary
At JFrog, we’re reinventing DevSecOps to help the world’s greatest companies innovate. Our team of industry-leading software security experts is a true pioneer, constantly pushing the boundaries with original research and technological innovation. JFrog is a special place with a unique combination of brilliance, spirit, and just all-around great people. Thousands of customers, including the majority of the Fortune 100, trust JFrog to manage, accelerate, and secure their software delivery from code to production – a concept we call “liquid software”. Wouldn't it be amazing if you could join us on our journey?
We are seeking a GRC Specialist (Governance, Risk, and Compliance) to join our growing GRC Team. This is a fantastic opportunity to be part of a growing team and support the company as it grows and matures. If you're a team player, self-driven, creative thinker, passionate about cybersecurity, and capable of blending a process-oriented mindset with a tech-oriented outlook, we are looking for you!
As a GRC specialist at JFrog you will...
- Maintain internal and external trust platforms, supporting ongoing customer due diligence activities including audits, questionnaires, and reviewing security contractual requirements.
- Provide training and guidance to sales teams on compliance-related matters and develop tools and resources to enable the Sales Team to efficiently respond to compliance inquiries from prospective and existing customers.
- Collaborate with cross-functional teams to support and enhance the overall GRC program.
- Ensure company policies, procedures, and controls are aligned with regulatory requirements and industry standards.
- Proactively gather customer feedback and stay abreast of industry trends to adapt and mature the GRC program accordingly.
- Implement improvements and updates to the program, based on regulatory changes and customer requirements.
- Participate in risk assessment and risk management processes.
To be a GRC specialist at JFrog you need...
- Minimum 1-2 years as a cyber security / GRC specialist, expert, or consultant
- Strong knowledge and hands-on experience with ISO 27001 and SOC 2 Type II
- Familiarity with additional security frameworks as well as privacy regulations and standards (NIST, CSA, CAIQ, SIG, GDPR, CCPA, ISO 27701) is an advantage.
- An excellent ability to communicate verbally and in writing
- Ability to work on multiple projects simultaneously
- Project management skills
- Self-driven and fast learner with a can-do approach
- Passionate about the team and responsibilities
- Experience with auditing cloud environments
- Experience in working with regulators and auditors
- Experience in working with GRC tools
- Role:
- GRC Specialist
Company profile

JFrog
jfrog.comJFrog is a software supply chain company whose platform lets organizations manage, secure and automate the delivery of software from code to production. Its products, including JFrog Artifactory, manage binaries and artifacts, secure releases and govern AI agents across any deployment model. The company began its Liquid Software journey in 2008 with the aim of making software updates flow continuously and securely. JFrog says it has more than 7,500 customers worldwide, including many Fortune 100 companies, along with millions of users.
- Company Size
- 1,000 - 5,000 employees
- Headquarters
- Sunnyvale, California, United States
- Founded
- 2008
- Founders
- Shlomi Ben Haim
- Funding Stage
- Public