Staff Security Analyst
$131.03k - $291.3kNavan
We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won’t just maintain compliance—you’ll scale and automate it to eliminate manual friction. In this role, you’ll manage our Information Security Management System (ISMS), lead internal and external audits, and serve as the primary bridge between external regulators and our internal teams. If you excel at translating deep technical expertise into practical, automated solutions, this is your chance to shape our security ecosystem across the organization.What You'll Do:Compliance Program Leadership (Primary Focus)Multi-Framework Compliance Management: Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II)ISMS Operations: Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processesAudit Coordination & Management: Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessmentsRisk Assessment & Adjustment: Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectivesControl Automation & Optimization: Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflowsRegulatory Compliance Strategy: Monitor regulatory changes and emerging compliance requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligationsControl Framework & TestingControl Owner Enablement: Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence requirementsControl Testing Program: Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologiesGap Assessment & Remediation: Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategiesEvidence Management: Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditabilityGovernance, Policy & DocumentationPolicy Development & Maintenance: Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory requirements and industry best practicesUnified Control Framework (UCF): Develop and maintain control mapping across multiple frameworks to identify overlapping requirements and optimize control implementationDocumentation Governance: Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change trackingCompliance Reporting: Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committeesCross-Functional Collaboration & Stakeholder ManagementExecutive Communication: Articulate complex compliance requirements and risk scenarios to C-level executives, board members, and non-technical stakeholdersCross-Functional Partnership: Collaborate closely with Engineering, IT, Finance, Legal, People Ops, and Business Units to bridge control gaps and implement compliance solutionsTraining & Awareness: Develop and deliver security compliance training programs for employees, contractors, and control owners; build compliance awareness throughout the organizationWhat We’re Looking For:Experience & Background6-8+ years of progressive experience in security governance, risk and compliance (GRC), information security auditing, or compliance program managementDemonstrated experience working directly with Big Four or external auditors through full audit cyclesControl automation experience: Proven success implementing automated evidence collection, continuous control monitoring, and compliance workflow automationISMS management: Hands-on experience running an Information Security Management System (ISO 27001 ISMS or equivalent)Framework & Regulatory KnowledgeDeep expertise in PCI DSS (all 12 requirements, SAQ types, ROC processes, compensating controls)Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls, change management, backup/recovery, segregation of duties)Proficiency with ISO 27001:2022 and ISO 42001:2023 (AI Management System) frameworksHands-on experience with SOC 1 (SSAE 18/ISAE 3402) and SOC 2 (Trust Services Criteria) audit requirementsWorking knowledge of security frameworks including NIST CSF, NIST SP 800-53, CIS Controls, or COBITTechnical & Cloud SecurityCloud security controls: Deep understanding of cloud security architecture, identity and access management (IAM), network security, data protection, and logging/monitoring within AWS (Azure or GCP experience is a strong plus)Control implementation: Practical knowledge of technical control implementation including encryption, secure configuration management, vulnerability management, and incident responseSecurity architecture: Ability to review and assess security architectures, data flows, and system designs from a compliance perspectiveTools & TechnologyGRC platforms: Hands-on experience with compliance automation platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, or similar)Evidence collection automation: Experience implementing automated evidence collection using APIs, scripts, or integration platformsAudit & assessment tools: Proficiency with vulnerability scanners, SIEM platforms, configuration management tools, and compliance scanning solutionsEducation & CertificationsBachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related fieldCertifications (one or more):CISA (Certified Information Systems Auditor)CISM (Certified Information Security Manager)CISSP (Certified Information Systems Security Professional)ISO 27001 Lead Auditor or ISO 27001 Lead ImplementerCCSP (Certified Cloud Security Professional) or CCSK (Certificate of Cloud Security Knowledge)PCI ISA (Internal Security Assessor) or PCI QSA (Qualified Security Assessor)Specialized ExperienceRegulated markets: Prior experience with FedRAMP (Low/Moderate/High), GovRAMP, CMMC (Level 1-3), StateRAMP, or TX-RAMP authorization processesGovernment & defense: Experience with NIST SP 800-171, DFARS compliance, or DoD authorization frameworksUnified Control Framework (UCF): Demonstrated success building and maintaining unified or common control frameworks that map requirements across multiple standardsConsulting background: Previous experience with Big Four consulting firms (Deloitte, PwC, EY, KPMG) or specialized security/compliance consulting practicesThe posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.Pay Range$131,025—$291,300 USD
- ...GetInsured is seeking a Security Analyst in Mountain View, California. The role involves monitoring, analyzing, and responding to security events across the network, working within the Security Operations Center (SOC) to ensure system protection. Candidates should have...Suggested
$90k - $120k
...optimization, we help states deliver vital public benefits efficiently, securely, and at scale. At Vimo, we create practical, real‑world... ..., Vimo may be the place for you. About The Role As a Security Analyst, you will be a crucial member of our Security Operations Center...SuggestedRemote work- VIMO INC in California is looking for a dedicated Security Analyst to join their Security Operations Center (SOC). You will monitor and analyze security events, ensuring the protection of our infrastructure and data. The ideal candidate will have over 6 years of experience...SuggestedRemote job
$120k - $180k
...intermediaries. Aptos (Ohlone for \"The People\") encompasses our mission and ethos for why we build. Aptos Foundation is seeking a Security Analyst to help operate and scale security across the organization. Reporting to the Security Lead, this role will support core...SuggestedFull timeWork experience placementLocal areaRemote workFlexible hours$103k - $154k
...Description Who You'll Work With You will join our Operational Security team, a group of dedicated professionals who serve as our... ...collaborative environment, you will work closely with senior analysts to monitor security alerts across our enterprise telemetry, investigate...SuggestedLocal areaFlexible hours- ...We are seeking a Senior Security Analyst for a Direct Hire/FTE position in Redwood City, CA. This position is onsite in Redwood City, CA. Summary: We are seeking an experienced Senior Security Analyst to join our team in ensuring the security and integrity of our systems...Full time
- ...Associate Security Analyst 1504938 ~ Hourly pay: $55-$75/hr ~ Worksite: Leading university (Redwood City 94063 - Hybrid) ~ W2 Employment, Group Medical, Dental, Vision, Life, Retirement Savings Program, PSL ~40 hours/week, 11 Month Assignment A leading...Hourly payRemote workMonday to FridayShift work
$103k - $154k
...looking for a skilled cybersecurity professional to join their Operational Security team. In this role, you will monitor security alerts, conduct incident response, and collaborate with senior analysts to enhance security protocols. The ideal candidate has a Bachelor's...- ...business requirements and insure compliance with industry and company security standards. • Complete access request processing as per... ...Agreements (SLA), resolve problem tickets and assist other security analysts as needed • Document access management procedures for assigned...Work at officeFlexible hours
$127.6k - $216.9k
...talent are unstoppable together. And we're just getting started. Join us to put AI to work for people. Job Description The ServiceNow Security Organization (SSO) The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk...Work at officeImmediate startRemote workFlexible hoursWeekend work$94.2k - $141.2k
...employees are not only part of history, they're making history.Northrop Grumman Mission Systems is seeking a Sr. Principal Industrial Security Analyst (4) or Principal Industrial Security Analyst (3) in Sunnyvale, CA. This is a multi-faceted security position, for the support...Full timeWork experience placementWork at officeRelocation packageShift work$117k - $166k
...silicon products that empower people's digital lives. Come join us and do something wonderful. Who we Are: Intel's Information Security organization enables Intel to provide secure products, solutions, and services which meet U.S. regulatory requirements. The...InternshipLocal areaShift work- ...Software Development, Software Consultancy, and Information Technology Enabled Services.Job DescriptionAt least 2 years of experience in Security Testing (Web & Network Pen testing and Secure code analysis)Hands-on security tester with proficiency in tools like HP Fortify,...Permanent employmentFull timeH1b
- ...expeditionary squadrons alternate with shore tours focused on training, staff work, or further education. Work Environment Work primarily at... ...qualification tests for officer programs Eligibility for a security clearance when required for your rating or designator...ApprenticeshipNight shift
$110k - $130k
...We are hiring immediately for a Financial Analyst position. Location : Mountain View CA. Schedule : Monday - Friday Pay Range: $110,000.00 - $130,000.00 annually We Make Applying Easy! Want to apply to this job via text messaging? Text JOB to 7...Full timePart timeWork at officeLocal areaImmediate startRemote workMonday to FridayFlexible hoursShift work$67.14k - $133.26k
...strategic partnerships across the Aramco ecosystem put us in the room for the most competitive deals in the market. The Investment Analyst supports deal execution, market analysis, and competitor analysis for Prosperity7 Ventures in North America, working closely with the...$112k - $117k
...Position Summary The Investment Analyst role is a generalist position, working broadly on investments across the portfolio and with various... .... The Packard Foundation’s current Hybrid Work Policy is that staff are expected to be in the office on Tuesdays and Wednesdays each...Full timeWork experience placementWork at office3 days per week- ...Security Assistant This is an open continuous announcement and may be posted up to September 01, 2026. The initial cut-off date for referral of eligible applications will be August 13, 2026. Eligible applications received after that date will be referred at regular intervals...For contractorsWork at officeLocal areaMonday to Friday
- About Us Hippocratic AI is the leading generative AI company in healthcare. We have the only system that can have safe, autonomous, clinical conversations with patients. We have trained our own LLMs as part of our Polaris constellation, resulting in a system with over...Contract workWork at office
- Investment Banking Analyst Responsibilities Two-year investment banking financial analyst position based in Menlo Park, CA. Work directly with senior partners across the U.S. with deep global client relationships. Direct day-to-day interactions with clients, counterparties...Full timeWork experience placementBank staffWork at officeImmediate startWork visa
$22 - $23 per hour
Job Description The Food Service Worker will assist the manager with food/meal preparation; maintain cash receipts and meal records. Assist manager in completing daily reports. Maintain high standards of quality in food production, sanitation, and kitchen safety practices...Hourly payFull time- ...As a Security Officer at SR Global Security, you will play a crucial role in protecting our clients, their assets, and their employees... ...Conduct training and drills for emergency procedures with other staff members Requirements Current Guard Card High school diploma or...Flexible hoursNight shift
$100k - $132.81k
...Implement and assist in developing effective site security, traffic management, and emergency management/preparedness programs. Manage... ...and outdoor work are required. Core Duties Supervise security staff; provide direction, train, evaluate and counsel. Ensure all security...Local areaShift workWeekend workAfternoon shift- ...We Are Accenture Security helps organizations prepare, protect, detect, respond, and recover along with all points of the security lifecycle. Cybersecurity challenges are different for every business in every industry. Leveraging our global resources and advanced technologies...Work experience placementLive inWork at officeLocal area
$167k - $220k
...life, come join us. About the Role: Wing is looking for a Staff Recruiter to serve as a cornerstone of our Talent organization... ...hiring process and through automation that empowers the team to secure top talent quickly and more effectively What You’ll Need:...Full timeLocal area- ...Role Overview ID.me is looking for a Senior Financial Analyst to join a high-impact Finance team operating at the center of the business. This role spans financial planning and forecasting, business partnering across GTM and R&D, and executive and investor reporting, with...Shift work
$104.1k - $143.1k
...Bellevue, Washington; Mountain View, California; San Francisco, California; Seattle, Washington. Databricks is looking for a Financial Analyst to join the Sales Finance team in the FP&A organization. You will report to the Senior Manager, Finance. The Sales Finance team’s...Worldwide$110k - $150k
...accountability and autonomy while driving financial performance through value-based operating strategies. Position Summary The Financial Analyst is a key member of the finance organization responsible for partnering with business unit leadership to improve financial...Full time$120k - $144k
...recommendations to determine approach to managing and completing processes. May supervise, train, coach, and review the work of other staff, as needed. Contribute primarily through applying individual expertise. Manage the use and administration of meal plan and credit...Work at officeRemote work$80k - $100k
...with local expertise to drive long‑term value. Position Overview DL Investments is seeking a motivated and detail‑oriented Financial Analyst with 2–3 years of experience to support our finance and accounting operations. This role will assist with day‑to‑day financial...Full timeWork at officeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Security Analyst. Be the first to apply!



