Staff Security Analyst
$131.03k - $291.3kNavan
We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won’t just maintain compliance—you’ll scale and automate it to eliminate manual friction. In this role, you’ll manage our Information Security Management System (ISMS), lead internal and external audits, and serve as the primary bridge between external regulators and our internal teams. If you excel at translating deep technical expertise into practical, automated solutions, this is your chance to shape our security ecosystem across the organization.
What You'll Do:
Compliance Program Leadership (Primary Focus)
- Multi-Framework Compliance Management : Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II)
- ISMS Operations : Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processes
- Audit Coordination & Management : Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessments
- Risk Assessment & Adjustment : Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectives
- Control Automation & Optimization : Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflows
- Regulatory Compliance Strategy : Monitor regulatory changes and emerging compliance requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligations
Control Framework & Testing
- Control Owner Enablement : Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence requirements
- Control Testing Program : Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologies
- Gap Assessment & Remediation : Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategies
- Evidence Management : Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditability
Governance, Policy & Documentation
- Policy Development & Maintenance : Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory requirements and industry best practices
- Unified Control Framework (UCF) : Develop and maintain control mapping across multiple frameworks to identify overlapping requirements and optimize control implementation
- Documentation Governance : Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change tracking
- Compliance Reporting : Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committees
Cross-Functional Collaboration & Stakeholder Management
- Executive Communication : Articulate complex compliance requirements and risk scenarios to C-level executives, board members, and non-technical stakeholders
- Cross-Functional Partnership : Collaborate closely with Engineering, IT, Finance, Legal, People Ops, and Business Units to bridge control gaps and implement compliance solutions
- Training & Awareness : Develop and deliver security compliance training programs for employees, contractors, and control owners; build compliance awareness throughout the organization
What We’re Looking For:
Experience & Background
- 6-8+ years of progressive experience in security governance, risk and compliance (GRC), information security auditing, or compliance program management
- Demonstrated experience working directly with Big Four or external auditors through full audit cycles
- Control automation experience : Proven success implementing automated evidence collection, continuous control monitoring, and compliance workflow automation
- ISMS management : Hands-on experience running an Information Security Management System (ISO 27001 ISMS or equivalent)
Framework & Regulatory Knowledge
- Deep expertise in PCI DSS (all 12 requirements, SAQ types, ROC processes, compensating controls)
- Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls, change management, backup/recovery, segregation of duties)
- Proficiency with ISO 27001:2022 and ISO 42001:2023 (AI Management System) frameworks
- Hands-on experience with SOC 1 (SSAE 18/ISAE 3402) and SOC 2 (Trust Services Criteria) audit requirements
- Working knowledge of security frameworks including NIST CSF, NIST SP 800-53, CIS Controls, or COBIT
Technical & Cloud Security
- Cloud security controls : Deep understanding of cloud security architecture, identity and access management (IAM), network security, data protection, and logging/monitoring within AWS (Azure or GCP experience is a strong plus)
- Control implementation : Practical knowledge of technical control implementation including encryption, secure configuration management, vulnerability management, and incident response
- Security architecture : Ability to review and assess security architectures, data flows, and system designs from a compliance perspective
Tools & Technology
- GRC platforms : Hands-on experience with compliance automation platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, or similar)
- Evidence collection automation : Experience implementing automated evidence collection using APIs, scripts, or integration platforms
- Audit & assessment tools : Proficiency with vulnerability scanners, SIEM platforms, configuration management tools, and compliance scanning solutions
Education & Certifications
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field
- Certifications (one or more):
- CISA (Certified Information Systems Auditor)
- CISM (Certified Information Security Manager)
- CISSP (Certified Information Systems Security Professional)
- ISO 27001 Lead Auditor or ISO 27001 Lead Implementer
- CCSP (Certified Cloud Security Professional) or CCSK (Certificate of Cloud Security Knowledge)
- PCI ISA (Internal Security Assessor) or PCI QSA (Qualified Security Assessor)
Specialized Experience
- Regulated markets : Prior experience with FedRAMP (Low/Moderate/High), GovRAMP, CMMC (Level 1-3), StateRAMP, or TX-RAMP authorization processes
- Government & defense : Experience with NIST SP 800-171, DFARS compliance, or DoD authorization frameworks
- Unified Control Framework (UCF) : Demonstrated success building and maintaining unified or common control frameworks that map requirements across multiple standards
- Consulting background : Previous experience with Big Four consulting firms (Deloitte, PwC, EY, KPMG) or specialized security/compliance consulting practices
The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.
For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.Pay Range
$131,025—$291,300 USD
Navan uses AI-assisted Automated Employment Decision Tool (Metaview) to assist with evaluating resumes against job qualifications for this role. All final decisions are made by human recruiters and hiring managers.
Human oversight: Metaview does not automatically reject candidates or make final hiring decisions. Our recruiters and hiring managers review all outputs and make the final hiring decision regarding every application.
-
Your rights: If you prefer to have your application reviewed without AI assistance, you may request a human evaluation by entering your email here. Your decision to do so will not affect how your candidacy is evaluated.
Please refer to our Candidate Privacy Notice for more information about our processing of personal data, and your rights.
$131.03k - $291.3k
We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won’t just maintain compliance—you’ll scale and automate it to eliminate manual friction. In this role, you’ll manage our Information Security Management System (ISMS...SuggestedFor contractors- ...optimization, we help states deliver vital public benefits efficiently, securely, and at scale. At Vimo, we create practical, real-... ...the place for you. About The Role: As a Security Analyst, you will be a crucial member of our Security Operations Center...Suggested
$120k - $180k
...intermediaries. Aptos (Ohlone for \"The People\") encompasses our mission and ethos for why we build. Aptos Foundation is seeking a Security Analyst to help operate and scale security across the organization. Reporting to the Security Lead, this role will support core...SuggestedFull timeWork experience placementLocal areaRemote workFlexible hours- ...VIMO INC in California is looking for a dedicated Security Analyst to join their Security Operations Center (SOC). You will monitor and analyze security events, ensuring the protection of our infrastructure and data. The ideal candidate will have over 6 years of experience...SuggestedRemote work
- ...General Summary GENERAL SUMMARY The primary responsibility of the Information Technology (IT) Security Analyst is to assure the secure operation of the infrastructure, and oversee information security as it relates to business operations, telecommunications, network...SuggestedFlexible hoursNight shiftWeekend work
$85.2k - $115k
...first AI-driven digital work platform, built to support flexible, secure, work-from anywhere experiences. We integrate industry-leading... ...organization at Omnissa is looking for an Information Security Analyst who is passionate about redefining, reimagining, and...Work experience placementLocal areaFlexible hours- Omnissa is hiring an Information Security Analyst in Atlanta for a hybrid role within the Threat Management organization. The role focuses on monitoring, analyzing, and responding to security events from multiple sources, and driving incident response from detection through...
$120k - $180k
Aptos is seeking a Security Analyst to enhance security operations. This role involves managing phishing responses, overseeing the bug bounty program, and conducting user access reviews. The ideal candidate will have over 2 years of relevant experience, strong communication...Remote work- GetInsured is seeking a Security Analyst in Mountain View, California. The role involves monitoring, analyzing, and responding to security events across the network, working within the Security Operations Center (SOC) to ensure system protection. Candidates should have...
$110k - $140k
23andMe Research Institute is looking for an experienced Senior Security Analyst to join our Security Operations team. In this role you will lead security incident response as Incident Commander, triage and investigate alerts, and design and build threat detection to help...Local area- 23andMe is seeking a Senior Security Analyst in Palo Alto to lead the Security Operations team as Incident Commander during security events. You will triage alerts, investigate incidents, and design threat detection to protect customer and corporate data. The role requires...
- ...A consulting firm in Mountain View is hiring for a Mid-Senior level role focusing on enhancing data-driven security training processes. The ideal candidate will lead quality assurance testing, manage compliance monitoring, and collaborate with multiple departments. They...Hourly payTemporary work3 days per week
- Omnissa is seeking an Information Security Analyst in Atlanta, GA to monitor security events from hosts, networks, and threat intel, and respond to alerts with containment, eradication, and recovery actions. You will contribute to building detections, playbooks, and SOPs...
$103k - $154k
...Job DescriptionWho You’ll Work WithYou will join our Operational Security team, a group of dedicated professionals who serve as our... ...this collaborative environment, you will work closely with senior analysts to monitor security alerts across our enterprise telemetry, investigate...Local areaFlexible hours$94.2k - $141.2k
...employees are not only part of history, they're making history.Northrop Grumman Mission Systems is seeking a Sr. Principal Industrial Security Analyst (4) or Principal Industrial Security Analyst (3) in Sunnyvale, CA. This is a multi-faceted security position, for the support...Full timeWork experience placementWork at officeRelocation packageShift work- ...Software Development, Software Consultancy, and Information Technology Enabled Services.Job DescriptionAt least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis)Hands-on security tester with proficiency in tools like HP Fortify,...Permanent employmentFull timeH1b
- ...We are seeking a Senior Security Analyst for a Direct Hire/FTE position in Redwood City, CA. This position is onsite in Redwood City, CA. Summary: We are seeking an experienced Senior Security Analyst to join our team in ensuring the security and integrity of our...Full time
- ...An established industry player is looking for a Senior Security Analyst to enhance the security and integrity of their systems and data. This role involves designing and implementing security solutions, managing vendor relationships, and collaborating with various teams...
- ...business requirements and insure compliance with industry and company security standards. • Complete access request processing as per... ...Agreements (SLA), resolve problem tickets and assist other security analysts as needed • Document access management procedures for assigned...Work at officeFlexible hours
- ...Senior Information Security AnalystLocation: Baton Rouge Louisiana Duration: 08/17/2020 and end 08/17/2022 Pay Rate: $43/hr on w2 all... ...inclusive Client: State of LouisianaSenior Information Security Analyst Positions: Expertise and/or relevant experience in the following...
- ServiceNow's Global Security Support Centre (GSSC) is hiring an Information Security professional to own, triage, and respond to security incidents while collaborating with internal teams and customers to improve security posture. The role emphasizes communication, on-...
- ...investments while minimizing costs and risks and increasing cash flow and profitability. Job Description JOB DETAILS: Job title: Info Security Analyst Location : 6 months Potential to extend duration Duration: Redwood City, CA JOB DESCRIPTION: High Level Responsibilities:...Flexible hours
- Everpure is seeking a Customer Trust Analyst to bridge between enterprise customers and internal teams, accelerating deals by turning complex security requirements into compelling trust assets. You will manage the Trust Center, respond to inquiries, and collaborate with...
- A technology company is seeking a Cybersecurity Analyst to review and analyze threat feeds, validate security incidents, and advise on IT initiatives. The ideal candidate will have a strong networking background and experience in vulnerability assessments. Effective communication...
$96.4k - $117.5k
...future of AI-powered business communications. At RingCentral, security, global availability, and always-on reliability are... ...customers, partners, and the public. The Associate Security Trust Analyst plays a critical role in helping ensure the security, reliability...Full timeLocal areaFlexible hours$127.6k - $216.9k
...will be considered. PLEASE NO NOT APPLY if you cannot meet this Federal Requirement. Thank you in advance. The ServiceNow Security Organization (SSO) The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk...Permanent employmentFull timeWork at officeImmediate startRemote workFlexible hoursWeekend work$127.6k - $216.9k
...Salary: $127,600 - 216,900 per year Requirements: We require 3-5+ years of professional experience in information security, application security, or closely related work, or equivalent experience paired with relevant education. We require ServiceNow Certified System...Full timeWork at officeRemote workFlexible hours- RingCentral is seeking an Associate Security Trust Analyst to help ensure the security, reliability, and integrity of products, services, and vendors. You will translate complex legal, regulatory, and security requirements into actionable controls and documentation for...
- ServiceNow's Global Security Support Centre (GSSC) is seeking an Information Security and Application Security professional to join the distributed, follow-the-sun team in the United States. You will own and triage security matters on the ServiceNow platform, communicate...Remote job
- RingCentral is seeking an Associate Security Trust Analyst to help ensure the security, reliability, and integrity of products, services, and vendors. You will translate complex legal, regulatory, and security requirements into actionable controls, assessments, and documentation...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Analyst. Be the first to apply!
- senior information security analyst Palo Alto, CA
- network security consultant Palo Alto, CA
- security coordinator Palo Alto, CA
- security specialist Palo Alto, CA
- security consultant Palo Alto, CA
- security advisor Palo Alto, CA
- rate analyst
- work from home security analyst
- data security analyst
- entry level information security analyst



