Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Risk and Compliance Analyst

$130k - $160k

Decisive Point

Role Overview As a Security Risk and Compliance Analyst you will play a hands‑on role in maturing and operating Asana’s compliance and certification programme—specifically across controls maturity, policy governance, and audit execution. This role sits at the intersection of traditional GRC work and compliance engineering: you will help maintain our control frameworks and run our audit cycles, while also contributing to the automation initiatives that make our compliance programme scalable and repeatable. This is an excellent opportunity for someone with early‑career GRC experience who is excited to grow their technical skills and help shape how a high‑growth SaaS company approaches compliance automation. You will partner closely with Security Engineering, Legal, Privacy, and R&D to ensure our controls are effective, our evidence pipelines are reliable, and our certifications—SOC 2, ISO 27001, and FedRAMP—are maintained with rigour. This role is based in our San Francisco office with an office‑centric hybrid schedule. The standard in‑office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. If you’re interviewing for this role, your recruiter will share more about the in‑office requirements. What You’ll Achieve Controls Maturity & Certifications Support the maintenance and continuous improvement of Asana’s control framework, tracking control effectiveness across SOC 2, ISO 27001, FedRAMP Moderate, and other applicable standards. Proactively engage with a wide range of teams—including Engineering, IT, and People—to work through controls maturity activities, close existing gaps, and drive remediation efforts to completion with clear documentation of progress. Build strong working relationships across the business so that control owners feel supported and accountability is shared, not siloed within the compliance team. Contribute to controls maturity scoring and reporting, providing ongoing visibility into programme health for senior leadership. Support external compliance audits end‑to‑end: coordinating evidence requests, liaising with auditors, and tracking findings through to closure. FedRAMP Continuous Monitoring Own the monthly FedRAMP ConMon package submission, ensuring it is accurate, complete, and delivered on time every month. Track and drive completion of all timebound FedRAMP requirements by working closely with Engineering, People, and other responsible teams. Maintain a clear calendar of FedRAMP deliverables and proactively flag risks to timelines, escalating where needed to ensure nothing slips. Serve as a day‑to‑day point of contact for FedRAMP‑related queries from internal teams, helping them understand their obligations and what good looks like. Evidence Collection & Automation Own evidence collection workflows within our GRC platform, ensuring controls are reliably mapped, evidence is current, and audit artefacts are ready year‑round. Where possible, identify opportunities to automate repetitive evidence‑gathering tasks—this is a nice‑to‑have rather than a core requirement, but curiosity and initiative here will be valued. Document evidence collection procedures so that processes are transparent, auditable, and maintainable by the broader team. About You 3+ years of experience in Governance, Risk, and Compliance (GRC), information security, or a closely related field—internships and co‑ops count. Foundational knowledge of security compliance frameworks such as SOC 2, ISO 27001, NIST CSF, or FedRAMP; you don’t need to be an expert in all of them. Comfortable engaging with a wide variety of teams—Engineering, People, IT, Legal—to explain compliance requirements, gather evidence, and build the relationships needed to close control gaps. Organised and deadline‑driven: you can manage multiple workstreams, track time‑sensitive obligations (like monthly FedRAMP submissions), and keep audit artefacts tidy without being reminded. A clear communicator who can translate compliance requirements into plain language for both technical and non‑technical stakeholders. Exposure to compliance automation or evidence collection tooling (GRC platforms, scripting, API integrations) is a plus, but not essential—curiosity and a willingness to grow technically matter more. Curious about how modern SaaS engineering works—comfortable asking questions and learning the technical context behind a control. What We’ll Offer Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we’re committed to looking at market value, which is why we check ourselves and conduct a yearly pay equity audit. For this role, the estimated base salary range is between $130,000–$160,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. In addition to base salary, your compensation package may include equity and benefits. Speak with your Talent Acquisition Partner to learn more. Mental health, wellness & fitness benefits Career coaching & support Inclusive family building benefits Long‑term savings or retirement plans In‑office culinary options to cater to your dietary preferences Equal Employment Opportunity We provide equal employment opportunities to all applicants without regard to race, colour, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law. We also comply with the San Francisco Fair Chance Ordinance and similar laws in other locations. #J-18808-Ljbffr Decisive Point

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Risk and Compliance Analyst in San Francisco, CA vacancy
  • $135k - $165k

     ...how organizations review, negotiate, and manage contracts. Security, privacy, and trust are foundational to our platform and...  ...scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk... 
    Suggested
    Contract work
    Flexible hours

    IVO Inc

    San Francisco, CA
    1 day ago
  •  ...Ivo is looking for a proactive GRC Analyst to enhance its compliance programs including SOC 2 Type II and ISO 2...  ...for managing compliance initiatives and risk assessments while ensuring close collaboration with teams across Security, Engineering, IT, and Operations. This... 
    Suggested

    IVO Inc

    San Francisco, CA
    23 hours ago
  • $135k - $165k

     ...Ivo AI, Inc. is looking for a Governance, Risk & Compliance (GRC) Analyst based in San Francisco. This role involves supporting compliance programs, conducting risk assessments, and maintaining security policies. The ideal candidate has 3–5 years of related experience... 
    Suggested
    Flexible hours

    Ivo AI, Inc.

    San Francisco, CA
    4 days ago
  • Ivo Inc. is seeking a GRC Analyst to support compliance and risk management initiatives in their San Francisco office. This is a crucial role designed to maintain Ivo's security compliance across multiple standards including SOC 2 Type II and ISO 27001. The successful candidate... 
    Suggested
    Work at office

    Ivo Inc.

    San Francisco, CA
    2 days ago
  • $110k - $140k

     ...Security Compliance Analyst We are looking for a highly motivated individual with information security governance and compliance experience to...  ...Our ideal candidate should be able to assist in running the risk management program that is managed by the Information Security... 
    Suggested

    Hive

    San Francisco, CA
    1 day ago
  • $135k - $165k

     ...Icehouseventures is seeking a proactive GRC Analyst to join our team in San Francisco. This role will support compliance and risk management initiatives essential for maintaining high security standards. The ideal candidate will have 3–5 years of experience in GRC and... 
    Contract work

    Icehouseventures

    San Francisco, CA
    3 days ago
  • $125k - $200k

     ...Your mission is straightforward: making stuff secure and compliant. You will connect governance, risk management, and compliance to protect our organization and our...  ...Compliance & Audits: Act as a Customer Trust Analyst to address security-related inquiries. Track... 
    Flexible hours

    Simile

    San Francisco, CA
    16 hours ago
  • Ivo is looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst in San Francisco. The ideal candidate will support compliance programs such as SOC 2 Type II and ISO 27001 while managing audits and risk assessments. This onsite role offers a competitive... 

    Ivo

    San Francisco, CA
    3 days ago
  • $150k

    Crusoe Energy Systems LLC is looking for a GRC Analyst in San Francisco, CA to support their Governance, Risk, and Compliance program. The role includes managing user...  ...have 5-7 years of experience in information security or related compliance roles and familiarity with... 

    Crusoe Energy Systems LLC

    San Francisco, CA
    4 days ago
  • $65 - $85 per hour

     ...Job Description Job Description Senior GRC Analyst - Security & Compliance LHH Recruitment Solutions is partnering with a high-growth, cloud...  ...unique opportunity to take ownership of a growing governance, risk, and compliance program within an innovative technology... 
    Hourly pay
    Contract work
    Temporary work
    Work at office
    Local area

    LHH US

    San Francisco, CA
    7 days ago
  •  ...Associate GRC Analyst The Associate GRC Analyst willsupport our Governance, Risk, and Compliance program. This role iswell-suitedfor anearly careerprofessional looking to gainhands-onexperience with security frameworks, risk assessments, audits, and compliance operations... 
    Internship

    Dormont Manufacturing Company

    San Francisco, CA
    3 days ago
  •  ...Lambda, a leader in AI cloud infrastructure in San Francisco, is seeking a Cybersecurity Risk Manager. You’ll validate security controls, assist with risk management, and collaborate with engineering teams to enhance cybersecurity practices. Ideal candidates will have... 
    Flexible hours

    Lambda

    San Francisco, CA
    3 days ago
  • $95k - $130k

     ...LiveRamp is seeking a Security GRC Analyst in San Francisco to support security risk management, compliance, and reporting efforts. You will collaborate closely with various teams to address and mitigate risks while maintaining high compliance standards. The ideal candidate... 
    Remote work

    Itlearn360

    San Francisco, CA
    4 days ago
  •  ...NAVA Software solutions is looking for a Security GRC Analyst Details: Security GRC Analyst Location:...  ...and with good understanding of security controls and compliance Experience GRC in Risk Management (identify, assess, monitor, and report risks... 

    Nava Software Solutions

    San Francisco, CA
    16 hours ago
  •  ...ll Do Validate and verify Lambda's security controls and practices meet the...  ...the update and maintenance of Lambda's IT Risk Register across the full risk lifecycle:...  ...information security control maturity, compliance status, risks, performance and findings... 
    Work at office
    Local area
    Work from home
    Flexible hours

    Lambda Corporation

    San Francisco, CA
    22 days ago
  • $95k - $130k

    Overview Security GRC Analyst job at LiveRamp. San Francisco, CA. LiveRamp is the data collaboration...  ...on the forefront of rapidly evolving compliance and privacy requirements. The LiveRamp...  ...program is designed to reduce risk in alignment with business goals by establishing... 
    Work at office
    Remote work
    Work from home
    Flexible hours
    Night shift

    Itlearn360

    San Francisco, CA
    3 days ago
  • $161.6k - $202k

     ...for millions of patients — and that responsibility demands a security and compliance program that scales with the business. We're building out...  ...certifications (HITRUST, SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness training, and technical risk... 
    Full time
    Work from home
    Flexible hours

    Headway

    San Francisco, CA
    3 days ago
  • $100k - $140k

     ...Affirm is looking for a Compliance Analyst II in San Francisco to enhance its compliance governance program. This role involves reviewing internal compliance processes, investigating consumer complaints, and collaborating with cross-functional teams to ensure adherence... 
    Remote work

    Affirm

    San Francisco, CA
    4 days ago
  • $140k

    Requisition ID # 172735 Job Category: Compliance / Risk / Quality Assurance; Accounting / Finance; Business Operations / Strategy Job Level: Manager/Principal Business Unit: Strategy & Growth Work Type: Hybrid Job Location: Oakland; Alameda; Alta; American Canyon... 
    Work at office
    Flexible hours

    PG&E Corporation

    San Francisco, CA
    4 days ago
  •  ...candidate has experience supporting security audits, managing evidence collection, conducting risk assessments, maintaining...  ...experience in Governance, Risk & Compliance (GRC), Information Security, IT...  ...detail-oriented and proactive GRC Analyst to support the company's... 

    Ivo

    San Francisco, CA
    3 days ago
  • $175k - $220k

     ...Monday.com, Nvidia, and Bridgewater. About the Team The Security team at LangChain treats compliance as a business enabler, not a checkbox. We move fast,...  ...confidence in our security posture. Support vendor privacy risk assessments during onboarding and renewals. What you’ll... 
    Contract work
    Work at office
    Flexible hours

    LangChain

    San Francisco, CA
    4 days ago
  • $130k - $150k

     ...Crusoe. About This Role We’re seeking a GRC Analyst to support the day-to-day execution of our Governance, Risk, and Compliance program. Reporting to the Head of GRC, this...  ..., updating policies, responding to customer security inquiries, and helping improve processes within... 
    Temporary work

    Crusoe Energy Systems LLC

    San Francisco, CA
    4 days ago
  • $193.8k - $228k

     ...Senior GRC Analyst II job at Carta. San Francisco, CA. The Problems You'll Solve As a Senior GRC Analyst II...  ...accordingly establish and maintain governance and risk frameworks. You will build and run security compliance programs to measure and reduce risk, report compliance... 
    Full time

    Itlearn360

    San Francisco, CA
    3 days ago
  •  ...Francisco, California is looking for an Associate GRC Analyst to support their Governance, Risk, and Compliance program. This position is ideal for early career professionals seeking hands-on experience with security frameworks and compliance operations. You will work... 

    Dormont Manufacturing Company

    San Francisco, CA
    1 day ago
  • $70 - $80 per hour

     ...Title: GRC Analyst Location: San Francisco, CA (4 days onsite) Duration: 6+ months Key Responsibilities: • Conduct technical vendor risk assessments (security, privacy, architecture, data handling) for new and existing third parties • Review security... 
    Hourly pay
    Full time
    Local area

    Winmax Systems

    San Francisco, CA
    1 day ago
  •  ...LIS Solutions is seeking a Junior Compliance Officer to assist with data evaluation and compliance support for federal law enforcement missions, specifically under the Department of Homeland Security. Responsibilities include data entry, database queries, and assisting... 
    Work at office

    LIS Solutions

    San Francisco, CA
    3 days ago
  •  ...Role We are looking for a GRC Specialist to join our Security team. Your mission is to scale our compliance frameworks and ensure we maintain a "continuously...  ...providing accurate security documentation to prospects. Risk Management: Conduct internal risk assessments and... 
    Worldwide
    Shift work

    Happy Robot

    San Francisco, CA
    3 days ago
  •  ...new positions become available. Junior Compliance Officer - West Coast+HI: San Diego, Los...  ...to support of the Department of Homeland Security, Immigration and Customs Enforcement, Homeland...  ...security vetting for a Tier 4 / High Risk Public Trust position. Preferred... 
    For contractors
    Work at office
    Local area

    LIS Solutions

    San Francisco, CA
    3 days ago
  • $93.8k - $116.3k

     ...adapted to their culture and working methods. We help clients strategize and scale leveraging deep expertise and solutions in compliance and risk management, strategic technology partnerships, data science, operations and business analysis and mergers and acquisitions.... 
    Work at office
    Remote work
    Worldwide
    Visa sponsorship
    Work visa
    Flexible hours
    3 days per week

    SIA

    San Francisco, CA
    7 days ago
  •  ...in San Francisco is looking for an Associate GRC Analyst to join our security team. In this role, you will support cybersecurity governance, compliance, and audit functions by gathering evidence, conducting vendor risk assessments, and maintaining documentation. This position... 

    IXL Learning

    San Francisco, CA
    6 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Risk and Compliance Analyst. Be the first to apply!