1d ago

Security Risk and Compliance Analyst

San Francisco

$130k-$160k / year

full-timemid Hybridsoftware

๐Ÿ’ผ About This Role

You'll mature and operate Asana's compliance program across SOC 2, ISO 27001, and FedRAMP. You'll partner with Engineering, Legal, and Privacy to ensure controls are effective and evidence pipelines are reliable. This role combines traditional GRC with compliance automation in a high-growth SaaS environment.

๐ŸŽฏ What You'll Do

  • Maintain control frameworks for SOC 2, ISO 27001, FedRAMP.
  • Support external compliance audits end-to-end.
  • Own monthly FedRAMP ConMon package submission.
  • Drive evidence collection automation in GRC platform.

๐Ÿ“‹ Requirements

  • 3+ years in GRC, information security, or related field.
  • Foundational knowledge of SOC 2, ISO 27001, or FedRAMP.
  • Ability to translate compliance requirements to technical and non-technical teams.
  • Organized and deadline-driven with multiple workstreams.

โœจ Nice to Have

  • Exposure to compliance automation or evidence collection tooling.
  • Scripting or API integration skills.
  • Curiosity about modern SaaS engineering.

๐ŸŽ Benefits & Perks

  • ๐Ÿง  Mental health, wellness & fitness benefits
  • ๐ŸŽ“ Career coaching support
  • ๐Ÿ‘ถ Inclusive family building benefits
  • ๐Ÿ’ฐ Long-term savings or retirement plans
  • ๐Ÿฝ๏ธ In-office culinary options

๐Ÿ“จ Hiring Process

Estimated timeline: 2-4 weeks ยท AI estimate

  1. 1Recruiter Screenยท 30 min
  2. 2Hiring Manager Interviewยท 45 min
  3. 3Technical Interviewยท 60 min
0 0 0