Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Risk and Compliance Analyst

$130k - $160k

Asana

Role Overview

As a Security Risk and Compliance Analyst you will play a hands-on role in maturing and operating Asana's compliance and certification programme-specifically across controls maturity, policy governance, and audit execution. This role sits at the intersection of traditional GRC work and compliance engineering: you will help maintain our control frameworks and run our audit cycles, while also contributing to the automation initiatives that make our compliance programme scalable and repeatable.

This is an excellent opportunity for someone with early-career GRC experience who is excited to grow their technical skills and help shape how a high-growth SaaS company approaches compliance automation. You will partner closely with Security Engineering, Legal, Privacy, and R&D to ensure our controls are effective, our evidence pipelines are reliable, and our certifications-SOC 2, ISO 27001, and FedRAMP-are maintained with rigour.

This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. If you're interviewing for this role, your recruiter will share more about the in-office requirements.
What You'll Achieve

Controls Maturity & Certifications
  • Support the maintenance and continuous improvement of Asana's control framework, tracking control effectiveness across SOC 2, ISO 27001, FedRAMP Moderate, and other applicable standards.
  • Proactively engage with a wide range of teams-including Engineering, IT, and People-to work through controls maturity activities, close existing gaps, and drive remediation efforts to completion with clear documentation of progress.
  • Build strong working relationships across the business so that control owners feel supported and accountability is shared, not siloed within the compliance team.
  • Contribute to controls maturity scoring and reporting, providing ongoing visibility into programme health for senior leadership.
  • Support external compliance audits end-to-end: coordinating evidence requests, liaising with auditors, and tracking findings through to closure.
FedRAMP Continuous Monitoring
  • Own the monthly FedRAMP ConMon package submission, ensuring it is accurate, complete, and delivered on time every month.
  • Track and drive completion of all timebound FedRAMP requirements by working closely with Engineering, People, and other responsible teams.
  • Maintain a clear calendar of FedRAMP deliverables and proactively flag risks to timelines, escalating where needed to ensure nothing slips.
  • Serve as a day-to-day point of contact for FedRAMP-related queries from internal teams, helping them understand their obligations and what good looks like.
Evidence Collection & Automation
  • Own evidence collection workflows within our GRC platform, ensuring controls are reliably mapped, evidence is current, and audit artefacts are ready year-round.
  • Where possible, identify opportunities to automate repetitive evidence-gathering tasks-this is a nice-to-have rather than a core requirement, but curiosity and initiative here will be valued.
  • Document evidence collection procedures so that processes are transparent, auditable, and maintainable by the broader team.
About You
  • 3+ years of experience in Governance, Risk, and Compliance (GRC), information security, or a closely related field-internships and co-ops count.
  • Foundational knowledge of security compliance frameworks such as SOC 2, ISO 27001, NIST CSF, or FedRAMP; you don't need to be an expert in all of them.
  • Comfortable engaging with a wide variety of teams-Engineering, People, IT, Legal-to explain compliance requirements, gather evidence, and build the relationships needed to close control gaps.
  • Organised and deadline-driven: you can manage multiple workstreams, track time-sensitive obligations (like monthly FedRAMP submissions), and keep audit artefacts tidy without being reminded.
  • A clear communicator who can translate compliance requirements into plain language for both technical and non-technical stakeholders.
  • Exposure to compliance automation or evidence collection tooling (GRC platforms, scripting, API integrations) is a plus, but not essential-curiosity and a willingness to grow technically matter more.
  • Curious about how modern SaaS engineering works-comfortable asking questions and learning the technical context behind a control.
At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.
What We'll Offer

Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we're committed to looking at market value, which is why we check ourselves and conduct a yearly pay equity audit.

For this role, the estimated base salary range is between $130,000-$160,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. In addition to base salary, your compensation package may include equity and benefits. Speak with your Talent Acquisition Partner to learn more.

We strive to provide equitable and competitive benefits packages that support our employees worldwide and include:
  • Mental health, wellness & fitness benefits
  • Career coaching & support
  • Inclusive family building benefits
  • Long-term savings or retirement plans
  • In-office culinary options to cater to your dietary preferences

These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations.

About Asana

Asana helps teams orchestrate their work, from small projects to strategic initiatives. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named a Top 10 Best Workplace for 5 years in a row, is Fortune's #1 Best Workplace in the Bay Area, and one of Glassdoor's and Inc.'s Best Places to Work.

We believe in supporting people to do their best work and thrive, and building a diverse, equitable, and inclusive company is core to our mission. Our goal is to ensure that Asana upholds an inclusive environment where all people feel equally respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, colour, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law. We also comply with the San Francisco Fair Chance Ordinance and similar laws in other locations.

#LI-Hybrid

About us

Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.

Join Asana's Talent Network to stay up to date on job opportunities and life at Asana.
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Security Risk and Compliance Analyst in San Francisco, CA vacancy
  • $88k - $124k

     ...IG Compliance & Security Analyst Cooley is seeking an IG Compliance & Security Analyst to join the Information Governance & Data Privacy team....  ...responding to client security requests. This role tracks risks, monitors adherence to policies and frameworks (e.g., ISO... 
    Suggested
    Full time
    Contract work
    Temporary work
    Work experience placement
    Work at office
    Flexible hours
    Weekend work

    Cooley

    San Francisco, CA
    2 days ago
  • $110k - $140k

     ...Security Compliance Analyst We are looking for a highly motivated individual with information security governance and compliance experience to...  ...Our ideal candidate should be able to assist in running the risk management program that is managed by the Information Security... 
    Suggested

    Hive

    San Francisco, CA
    1 day ago
  •  ...cybersecurity for the world’s most critical organizations. We build security compliance software delivered as managed services sold directly, with...  ...customers first. About the Role As a Cybersecurity Analyst will work closely with customers to help them implement and... 
    Suggested
    Full time

    Atomus

    San Francisco, CA
    3 hours ago
  • $150k

    Crusoe Energy Systems LLC is looking for a GRC Analyst in San Francisco, CA to support their Governance, Risk, and Compliance program. The role includes managing user...  ...have 5-7 years of experience in information security or related compliance roles and familiarity with... 
    Suggested

    Crusoe Energy Systems LLC

    San Francisco, CA
    4 days ago
  • Title : Senior GRC Analyst Location : Hybrid- New York, NY or Tempe, AZ About Us Wealth...  ....com combines proprietary AI, robust security, and deep technological and legal...  ...motivated and experienced Senior Governance, Risk, and Compliance (GRC) Analyst to join our team. In... 
    Suggested
    Temporary work
    Remote work
    Flexible hours

    Wealth.com

    San Francisco, CA
    4 days ago
  • $161.6k - $202k

     ...for millions of patients - and that responsibility demands a security and compliance program that scales with the business. We're building out...  ...certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk... 
    Work from home
    Flexible hours

    Headway - Design & Development

    San Francisco, CA
    21 hours ago
  •  ...ll Do Validate and verify Lambda's security controls and practices meet the...  ...the update and maintenance of Lambda's IT Risk Register across the full risk lifecycle:...  ...information security control maturity, compliance status, risks, performance and findings... 
    Work at office
    Local area
    Work from home
    Flexible hours

    Lambda

    San Francisco, CA
    1 day ago
  •  ...NAVA Software solutions is looking for a Security GRC Analyst Details: Security GRC Analyst Location:...  ...and with good understanding of security controls and compliance Experience GRC in Risk Management (identify, assess, monitor, and report risks... 

    Nava Software Solutions

    San Francisco, CA
    5 days ago
  •  ...supports the ITRC goal to ensure risk inherent to technology...  ...Bank’s risk appetite. The ITRC Analyst is responsible for monitoring...  ...public data, and information security used to protect against current...  ...key stakeholders to ensure compliance with the IS and IT frameworks... 
    Work at office

    ATR International

    San Francisco, CA
    3 days ago
  •  ...Compliance Officer This position is within the Administrative Services Group Compliance...  ...Monitors major and critical compliance risks issues Oversees the implementation of...  ...Examination Council guidance on information security standards, BSA/AML, Privacy, OFAC,... 

    Direct Staffing Inc

    San Francisco, CA
    1 day ago
  •  ...Title: GRC Analyst Location: San Francisco, CA (4 days onsite) Duration: 6+ months Key Responsibilities: • Conduct technical vendor risk assessments (security, privacy, architecture, data handling) for new and existing third parties • Review security... 

    Winmax Systems

    San Francisco, CA
    1 day ago
  • $130k - $150k

     .... About This Role We're seeking a GRC Analyst to support the day-to-day execution of our Governance, Risk, and Compliance program. Reporting to the Head of GRC, this...  ..., updating policies, responding to customer security inquiries, and helping improve processes within... 
    Temporary work

    Crusoe

    San Francisco, CA
    5 days ago
  • $193.8k - $228k

    Senior GRC Analyst II job at Carta. San Francisco, CA. The Problems You'll Solve As a Senior GRC Analyst II...  ...accordingly establish and maintain governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance... 
    Full time

    Itlearn360

    San Francisco, CA
    1 day ago
  •  ...time, ~20 hrs/week) to build and own our compliance function. Freed operates in a highly...  ...single accountable owner for Governance, Risk, and Compliance, responsible for maintaining...  ...vendor compliance intake (BAAs, DPAs, security reviews) Build and maintain a centralized... 
    Part time
    Work at office
    Immediate start
    3 days per week

    FREED

    San Francisco, CA
    5 days ago
  • $159k - $305k

     ...Senior Lead Compliance Officer Wells Fargo is seeking a highly experienced Senior Lead Compliance Officer to operate at the Executive...  ...complex business units, rules and regulations on moderate to high risk compliance matters Interface with Audit, Legal, external... 
    Work experience placement

    Wells Fargo

    San Francisco, CA
    4 days ago
  •  ...candidate will have experience equivalent to a GS-12, conducting risk assessments and addressing vulnerabilities while adhering to IT...  ...understanding of cybersecurity processes and the ability to integrate security requirements effectively. #J-18808-Ljbffr US Federal Student... 

    US Federal Student Aid

    San Francisco, CA
    5 days ago
  • $90k - $100k

    A leading consulting firm located in San Francisco is seeking a Legal & Compliance Associate to join their global Client Protection team. The role involves monitoring projects, providing guidance to delivery teams, and implementing compliance policies. Candidates should... 
    Remote job

    AlphaSights

    San Francisco, CA
    2 days ago
  •  ...join their San Francisco office. In this client-facing role, you will lead engagements that deliver impactful solutions across risk, compliance, and operations. The ideal candidate will have 1-4 years of consulting experience and a strong grasp of industry challenges.... 
    Work at office

    Sia Partners'

    San Francisco, CA
    5 days ago
  • $93.8k - $116.3k

     ...adapted to their culture and working methods. We help clients strategize and scale leveraging deep expertise and solutions in compliance and risk management, strategic technology partnerships, data science, operations and business analysis and mergers and acquisitions.... 
    Work at office
    Remote work
    Worldwide
    Visa sponsorship
    Work visa
    Flexible hours
    3 days per week

    SIA

    San Francisco, CA
    11 days ago
  • $100 - $120 per hour

     ...rule comment letters, regulatory-change analyses, exam responses, compliance memos, policy drafts, enforcement-defense briefs, and email...  ...Westlaw , LexisNexis , Refinitiv World-Check , Dow Jones Risk & Compliance , and CUBE . Design multi-step tasks grounded... 
    Hourly pay
    Full time
    Contract work
    Summer work
    Remote work

    Mercor

    San Francisco, CA
    5 days ago
  •  ...Saudi Arabia. It is a permanent full‑time expatriate position with an attractive relocation package. The role is a Governance, Risk & Compliance Specialist in the Digital & IT (D&IT) Strategy & Investment Department, within the D&IT Governance Risk & Compliance Division.... 
    Permanent employment
    Full time
    Local area
    Relocation
    Relocation package

    aramco

    San Francisco, CA
    1 day ago
  • $140k

     ...Requisition ID # 171354  Job Category: Accounting / Finance  Job Level: Manager/Principal Business Unit: Gen Counsel, Ethics, Risk & Compliance Work Type: Hybrid Job Location: Oakland    Department Overview The Office of the Chief Risk Officer is responsible... 
    Work at office
    Remote work

    PG&E Corporation

    Oakland, CA
    1 day ago
  •  ...We are currently seeking a "Compliance Analyst" for a Contract role and its Remote. Please apply if you would be interested and available for it. Duration: 06+ Months Contract Pay Range: $80/Hr on W2 Location: Remote Job Description: Track, analyze, and... 
    Contract work
    Remote work

    Artech

    San Francisco, CA
    5 days ago
  •  ...Our client in the investment banking space is looking for an analyst to support the firm's compliance function. This person will focus on conflicts clearance, restricted/watch lists, and information wall management. This position requires strong analytical skills, sound... 

    Insight Global

    San Francisco, CA
    1 day ago
  •  ...organize, and maintain audit-ready evidence across all active compliance frameworks Update and maintain quality metrics dashboards and...  ...framework audits Help complete and respond to customer security questionnaires and due diligence requests Track audit finding... 
    Full time
    Part time
    For contractors
    Flexible hours

    Unlearn

    San Francisco, CA
    4 days ago
  • $20.21 per hour

     ...support services - focusing on the U.S. Departments of Homeland Security and Treasury. We strive to hire only ethical, talented,...  ...status of new applicant, contractor, and federal employee files. Compliance and Training: Stay up to date with relevant policies, regulations... 
    Full time
    For contractors
    Local area
    Immediate start
    Flexible hours

    Citizant

    Oakland, CA
    a month ago
  • $93.8k - $116.3k

     ...adapted to their culture and working methods. We help clients strategize and scale leveraging deep expertise and solutions in compliance and risk management, strategic technology partnerships, data science, operations and business analysis and mergers and acquisitions.... 
    H1b
    Work at office
    Worldwide
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work
    3 days per week

    SIA

    San Francisco, CA
    1 day ago
  • $96k - $144k

     ...to own their own destiny. Compliance is critical to Klaviyo's success...  ...ecosystem. We balance risk mitigation with customer experience...  .... The Compliance Operations Analyst plays a key role in reducing...  ...Partner with Engineering and Security to test and implement signal... 
    Temporary work

    Klaviyo

    San Francisco, CA
    5 days ago
  • A globally leading consumer device company based in San Francisco, CA is seeking Compliance Analyst to join their team! You will automate compliance workflows, close data governance gaps, and build monitoring dashboards across a large-scale, multi-team data ecosystem.... 
    Contract work

    OSI Engineering

    San Francisco, CA
    4 days ago
  • A technology consulting firm in California is seeking a Business Analyst to enhance IT Hygiene practices across the organization. The role involves developing reporting mechanisms, assessing compliance, and collaborating with IT leaders for governance improvement. Candidates... 
    Long term contract

    InfoVision Inc.

    San Francisco, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Risk and Compliance Analyst. Be the first to apply!