Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Analyst

$131.03k - $291.3k
Full-time

Navan

We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won’t just maintain compliance—you’ll scale and automate it to eliminate manual friction. In this role, you’ll manage our Information Security Management System (ISMS), lead internal and external audits, and serve as the primary bridge between external regulators and our internal teams. If you excel at translating deep technical expertise into practical, automated solutions, this is your chance to shape our security ecosystem across the organization.

What You'll Do:

Compliance Program Leadership (Primary Focus)

  • Multi-Framework Compliance Management : Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II)
  • ISMS Operations : Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processes
  • Audit Coordination & Management : Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessments
  • Risk Assessment & Adjustment : Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectives
  • Control Automation & Optimization : Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflows
  • Regulatory Compliance Strategy : Monitor regulatory changes and emerging compliance requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligations

Control Framework & Testing

  • Control Owner Enablement : Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence requirements
  • Control Testing Program : Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologies
  • Gap Assessment & Remediation : Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategies
  • Evidence Management : Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditability

Governance, Policy & Documentation

  • Policy Development & Maintenance : Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory requirements and industry best practices
  • Unified Control Framework (UCF) : Develop and maintain control mapping across multiple frameworks to identify overlapping requirements and optimize control implementation
  • Documentation Governance : Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change tracking
  • Compliance Reporting : Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committees

Cross-Functional Collaboration & Stakeholder Management

  • Executive Communication : Articulate complex compliance requirements and risk scenarios to C-level executives, board members, and non-technical stakeholders
  • Cross-Functional Partnership : Collaborate closely with Engineering, IT, Finance, Legal, People Ops, and Business Units to bridge control gaps and implement compliance solutions
  • Training & Awareness : Develop and deliver security compliance training programs for employees, contractors, and control owners; build compliance awareness throughout the organization

What We’re Looking For:

Experience & Background

  • 6-8+ years of progressive experience in security governance, risk and compliance (GRC), information security auditing, or compliance program management
  • Demonstrated experience working directly with Big Four or external auditors through full audit cycles
  • Control automation experience : Proven success implementing automated evidence collection, continuous control monitoring, and compliance workflow automation
  • ISMS management : Hands-on experience running an Information Security Management System (ISO 27001 ISMS or equivalent)

Framework & Regulatory Knowledge

  • Deep expertise in PCI DSS (all 12 requirements, SAQ types, ROC processes, compensating controls)
  • Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls, change management, backup/recovery, segregation of duties)
  • Proficiency with ISO 27001:2022 and ISO 42001:2023 (AI Management System) frameworks
  • Hands-on experience with SOC 1 (SSAE 18/ISAE 3402) and SOC 2 (Trust Services Criteria) audit requirements
  • Working knowledge of security frameworks including NIST CSF, NIST SP 800-53, CIS Controls, or COBIT

Technical & Cloud Security

  • Cloud security controls : Deep understanding of cloud security architecture, identity and access management (IAM), network security, data protection, and logging/monitoring within AWS (Azure or GCP experience is a strong plus)
  • Control implementation : Practical knowledge of technical control implementation including encryption, secure configuration management, vulnerability management, and incident response
  • Security architecture : Ability to review and assess security architectures, data flows, and system designs from a compliance perspective

Tools & Technology

  • GRC platforms : Hands-on experience with compliance automation platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, or similar)
  • Evidence collection automation : Experience implementing automated evidence collection using APIs, scripts, or integration platforms
  • Audit & assessment tools : Proficiency with vulnerability scanners, SIEM platforms, configuration management tools, and compliance scanning solutions

Education & Certifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field
  • Certifications (one or more):
    • CISA (Certified Information Systems Auditor)
    • CISM (Certified Information Security Manager)
    • CISSP (Certified Information Systems Security Professional)
    • ISO 27001 Lead Auditor or ISO 27001 Lead Implementer
    • CCSP (Certified Cloud Security Professional) or CCSK (Certificate of Cloud Security Knowledge)
    • PCI ISA (Internal Security Assessor) or PCI QSA (Qualified Security Assessor)

Specialized Experience

  • Regulated markets : Prior experience with FedRAMP (Low/Moderate/High), GovRAMP, CMMC (Level 1-3), StateRAMP, or TX-RAMP authorization processes
  • Government & defense : Experience with NIST SP 800-171, DFARS compliance, or DoD authorization frameworks
  • Unified Control Framework (UCF) : Demonstrated success building and maintaining unified or common control frameworks that map requirements across multiple standards
  • Consulting background : Previous experience with Big Four consulting firms (Deloitte, PwC, EY, KPMG) or specialized security/compliance consulting practices

The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.

For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.

Pay Range

$131,025—$291,300 USD

Navan uses AI-assisted Automated Employment Decision Tool (Metaview) to assist with evaluating resumes against job qualifications for this role. All final decisions are made by human recruiters and hiring managers.

Human oversight: Metaview does not automatically reject candidates or make final hiring decisions. Our recruiters and hiring managers review all outputs and make the final hiring decision regarding every application.

  • Your rights: If you prefer to have your application reviewed without AI assistance, you may request a human evaluation by entering your email here. Your decision to do so will not affect how your candidacy is evaluated.

Please refer to our Candidate Privacy Notice for more information about our processing of personal data, and your rights.

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Staff Security Analyst in Palo Alto, CA vacancy
  • $131.03k - $291.3k

    We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won’t just maintain compliance—you’ll scale and automate it to eliminate manual friction. In this role, you’ll manage our Information Security Management System (ISMS... 
    Suggested
    For contractors

    TripActions

    Palo Alto, CA
    2 days ago
  •  ...optimization, we help states deliver vital public benefits efficiently, securely, and at scale. At Vimo, we create practical, real-...  ...the place for you. About The Role: As a Security Analyst, you will be a crucial member of our Security Operations Center... 
    Suggested

    GetInsured

    Mountain View, CA
    2 days ago
  • $120k - $180k

     ...intermediaries. Aptos (Ohlone for \"The People\") encompasses our mission and ethos for why we build. Aptos Foundation is seeking a Security Analyst to help operate and scale security across the organization. Reporting to the Security Lead, this role will support core... 
    Suggested
    Full time
    Work experience placement
    Local area
    Remote work
    Flexible hours

    Multicoin

    Palo Alto, CA
    2 days ago
  •  ...VIMO INC in California is looking for a dedicated Security Analyst to join their Security Operations Center (SOC). You will monitor and analyze security events, ensuring the protection of our infrastructure and data. The ideal candidate will have over 6 years of experience... 
    Suggested
    Remote work

    VIMO INC

    Mountain View, CA
    4 days ago
  •  ...General Summary GENERAL SUMMARY The primary responsibility of the Information Technology (IT) Security Analyst is to assure the secure operation of the infrastructure, and oversee information security as it relates to business operations, telecommunications, network... 
    Suggested
    Flexible hours
    Night shift
    Weekend work

    Infor

    Palo Alto, CA
    12 hours ago
  • $85.2k - $115k

     ...first AI-driven digital work platform, built to support flexible, secure, work-from anywhere experiences. We integrate industry-leading...  ...organization at Omnissa is looking for an Information Security Analyst who is passionate about redefining, reimagining, and... 
    Work experience placement
    Local area
    Flexible hours

    Omnissa, LLC

    Mountain View, CA
    3 days ago
  • Omnissa is hiring an Information Security Analyst in Atlanta for a hybrid role within the Threat Management organization. The role focuses on monitoring, analyzing, and responding to security events from multiple sources, and driving incident response from detection through... 

    Omnissa, LLC

    Mountain View, CA
    4 days ago
  • $120k - $180k

    Aptos is seeking a Security Analyst to enhance security operations. This role involves managing phishing responses, overseeing the bug bounty program, and conducting user access reviews. The ideal candidate will have over 2 years of relevant experience, strong communication... 
    Remote work

    Multicoin

    Palo Alto, CA
    3 days ago
  • GetInsured is seeking a Security Analyst in Mountain View, California. The role involves monitoring, analyzing, and responding to security events across the network, working within the Security Operations Center (SOC) to ensure system protection. Candidates should have... 

    GetInsured

    Mountain View, CA
    6 days ago
  • $110k - $140k

    23andMe Research Institute is looking for an experienced Senior Security Analyst to join our Security Operations team. In this role you will lead security incident response as Incident Commander, triage and investigate alerts, and design and build threat detection to help... 
    Local area

    23andMe Research Institute

    Palo Alto, CA
    3 days ago
  • 23andMe is seeking a Senior Security Analyst in Palo Alto to lead the Security Operations team as Incident Commander during security events. You will triage alerts, investigate incidents, and design threat detection to protect customer and corporate data. The role requires... 

    23andMe, Inc.

    Palo Alto, CA
    2 days ago
  •  ...A consulting firm in Mountain View is hiring for a Mid-Senior level role focusing on enhancing data-driven security training processes. The ideal candidate will lead quality assurance testing, manage compliance monitoring, and collaborate with multiple departments. They... 
    Hourly pay
    Temporary work
    3 days per week

    Excelerate

    Mountain View, CA
    20 hours ago
  • Omnissa is seeking an Information Security Analyst in Atlanta, GA to monitor security events from hosts, networks, and threat intel, and respond to alerts with containment, eradication, and recovery actions. You will contribute to building detections, playbooks, and SOPs... 

    Omnissa, LLC in

    Mountain View, CA
    2 days ago
  • $103k - $154k

     ...Job DescriptionWho You’ll Work WithYou will join our Operational Security team, a group of dedicated professionals who serve as our...  ...this collaborative environment, you will work closely with senior analysts to monitor security alerts across our enterprise telemetry, investigate... 
    Local area
    Flexible hours

    Arista Networks

    Santa Clara, CA
    2 days ago
  • $94.2k - $141.2k

     ...employees are not only part of history, they're making history.Northrop Grumman Mission Systems is seeking a Sr. Principal Industrial Security Analyst (4) or Principal Industrial Security Analyst (3) in Sunnyvale, CA. This is a multi-faceted security position, for the support... 
    Full time
    Work experience placement
    Work at office
    Relocation package
    Shift work

    Northrop Grumman

    Sunnyvale, CA
    1 day ago
  •  ...Software Development, Software Consultancy, and Information Technology Enabled Services.Job DescriptionAt least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis)Hands-on security tester with proficiency in tools like HP Fortify,... 
    Permanent employment
    Full time
    H1b

    Sonsoft

    Sunnyvale, CA
    4 days ago
  •  ...We are seeking a Senior Security Analyst for a Direct Hire/FTE position in Redwood City, CA. This position is onsite in Redwood City, CA. Summary: We are seeking an experienced Senior Security Analyst to join our team in ensuring the security and integrity of our... 
    Full time

    The Mice Groups, Inc.

    Redwood City, CA
    20 hours ago
  •  ...An established industry player is looking for a Senior Security Analyst to enhance the security and integrity of their systems and data. This role involves designing and implementing security solutions, managing vendor relationships, and collaborating with various teams... 

    The Mice Groups, Inc.

    Redwood City, CA
    12 hours ago
  •  ...business requirements and insure compliance with industry and company security standards. • Complete access request processing as per...  ...Agreements (SLA), resolve problem tickets and assist other security analysts as needed • Document access management procedures for assigned... 
    Work at office
    Flexible hours

    Atria Group

    Foster, CA
    3 days ago
  •  ...Senior Information Security AnalystLocation: Baton Rouge Louisiana Duration: 08/17/2020 and end 08/17/2022 Pay Rate: $43/hr on w2 all...  ...inclusive Client: State of LouisianaSenior Information Security Analyst Positions: Expertise and/or relevant experience in the following... 

    Omega Solutions

    Santa Clara, CA
    3 days ago
  • ServiceNow's Global Security Support Centre (GSSC) is hiring an Information Security professional to own, triage, and respond to security incidents while collaborating with internal teams and customers to improve security posture. The role emphasizes communication, on-... 

    ServiceNow

    Santa Clara, CA
    3 days ago
  •  ...investments while minimizing costs and risks and increasing cash flow and profitability. Job Description JOB DETAILS: Job title: Info Security Analyst Location : 6 months Potential to extend duration Duration: Redwood City, CA JOB DESCRIPTION: High Level Responsibilities:... 
    Flexible hours

    Softpath System

    Redwood City, CA
    4 days ago
  • Everpure is seeking a Customer Trust Analyst to bridge between enterprise customers and internal teams, accelerating deals by turning complex security requirements into compelling trust assets. You will manage the Trust Center, respond to inquiries, and collaborate with... 

    Everpure LLC

    Santa Clara, CA
    4 days ago
  • A technology company is seeking a Cybersecurity Analyst to review and analyze threat feeds, validate security incidents, and advise on IT initiatives. The ideal candidate will have a strong networking background and experience in vulnerability assessments. Effective communication... 

    Bay Side

    Santa Clara, CA
    4 days ago
  • $96.4k - $117.5k

     ...future of AI-powered business communications. At RingCentral, security, global availability, and always-on reliability are...  ...customers, partners, and the public. The Associate Security Trust Analyst plays a critical role in helping ensure the security, reliability... 
    Full time
    Local area
    Flexible hours

    RingCentral

    Belmont, CA
    6 days ago
  • $127.6k - $216.9k

     ...will be considered. PLEASE NO NOT APPLY if you cannot meet this Federal Requirement. Thank you in advance. The ServiceNow Security Organization (SSO) The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk... 
    Permanent employment
    Full time
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Weekend work

    ServiceNow

    Santa Clara, CA
    6 days ago
  • $127.6k - $216.9k

     ...Salary: $127,600 - 216,900 per year Requirements: We require 3-5+ years of professional experience in information security, application security, or closely related work, or equivalent experience paired with relevant education. We require ServiceNow Certified System... 
    Full time
    Work at office
    Remote work
    Flexible hours

    ServiceNow, Inc.

    Santa Clara, CA
    3 days ago
  • RingCentral is seeking an Associate Security Trust Analyst to help ensure the security, reliability, and integrity of products, services, and vendors. You will translate complex legal, regulatory, and security requirements into actionable controls and documentation for... 

    RingCentral, Inc

    Belmont, CA
    3 days ago
  • ServiceNow's Global Security Support Centre (GSSC) is seeking an Information Security and Application Security professional to join the distributed, follow-the-sun team in the United States. You will own and triage security matters on the ServiceNow platform, communicate... 
    Remote job

    Carra

    Santa Clara, CA
    3 days ago
  • RingCentral is seeking an Associate Security Trust Analyst to help ensure the security, reliability, and integrity of products, services, and vendors. You will translate complex legal, regulatory, and security requirements into actionable controls, assessments, and documentation... 

    RingCentral

    Belmont, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Analyst. Be the first to apply!