1d ago
Security Risk and Compliance Analyst
San Francisco
$130k-$160k / year
full-timemid Hybridsoftware
๐ผ About This Role
You'll mature and operate Asana's compliance program across SOC 2, ISO 27001, and FedRAMP. You'll partner with Engineering, Legal, and Privacy to ensure controls are effective and evidence pipelines are reliable. This role combines traditional GRC with compliance automation in a high-growth SaaS environment.
๐ฏ What You'll Do
- Maintain control frameworks for SOC 2, ISO 27001, FedRAMP.
- Support external compliance audits end-to-end.
- Own monthly FedRAMP ConMon package submission.
- Drive evidence collection automation in GRC platform.
๐ Requirements
- 3+ years in GRC, information security, or related field.
- Foundational knowledge of SOC 2, ISO 27001, or FedRAMP.
- Ability to translate compliance requirements to technical and non-technical teams.
- Organized and deadline-driven with multiple workstreams.
โจ Nice to Have
- Exposure to compliance automation or evidence collection tooling.
- Scripting or API integration skills.
- Curiosity about modern SaaS engineering.
๐ Benefits & Perks
- ๐ง Mental health, wellness & fitness benefits
- ๐ Career coaching support
- ๐ถ Inclusive family building benefits
- ๐ฐ Long-term savings or retirement plans
- ๐ฝ๏ธ In-office culinary options
๐จ Hiring Process
Estimated timeline: 2-4 weeks ยท AI estimate
- 1Recruiter Screenยท 30 min
- 2Hiring Manager Interviewยท 45 min
- 3Technical Interviewยท 60 min
0 0 0