Skip to content
HiveHive

Security Compliance Analyst

Manages risk programs, audits, and compliance initiatives including ISO 27001/SOC audits and privacy laws like GDPR/CCPA. Collaborates with engineering teams on process improvements and supports information security governance. Requires 4+ years in risk assessments and GRC experience.

About the job

Responsibilities

  • Manage Hive’s current risk management program
  • Manage external and internal audits, including reviewing materials that require attention for accuracy and properly adhering to regulatory expectations
  • Implement ISMS in coordination with executive and mid-level management
  • Participate in building a comprehensive Governance, Risk and Compliance program
  • Work with Engineering and Product teams to identify process improvements and efficiencies in areas change management, access management and general technology process controls
  • Provide compliance, risk, and controls expertise to support information security and compliance initiatives
  • Protect the business by assisting with cyber security risk assessments
  • Maintain awareness of industry best practices for data maintenance handling as it relates to your role
  • Manage security and privacy training programs
  • Adhere to and champion policies, guidelines and procedures pertaining to the protection of information assets
  • Manage external security, privacy, and compliance requirements, including both internal requirements for vendors as well as external requirements placed on Hive
  • Report actual or suspected security and/or policy violations/breaches to an appropriate authority
  • Define, develop, implement, and maintain our policies and processes that enable consistent, effective privacy practices that minimize risk and ensure the confidentiality of protected information, paper and/or electronic, across all media types and comply with applicable privacy laws and regulations

Requirements

  • Bachelor's degree or related experience
  • Minimum 4+ years experience related to conducting risk-based assessment for information systems and/or operations
  • Minimum 1+ years experience running a comprehensive Governance, Risk and Compliance program
  • Minimum 2+ years experience leading industry standard (ISO 27001 or SOC 1/2) audits from either side
  • Strong knowledge of applicable privacy laws (CCPA/CPRA, GDPR)
  • Ability to communicate in a written and oral format to technical and non-technical audiences in a business-friendly manner
  • Demonstrated success in a competitive environment
  • Highly self-motivated and ambitious in achieving goals
  • Strong team player, but can work and execute independently
  • Driven; no one needs to push you to excel; that’s just who you are
  • Hungry to learn and actively look for opportunities to contribute
  • Highly organized and detail-oriented; can handle multiple projects and dynamic priorities without missing a beat

Skills

ISO 27001, Soc 1, SOC 2, GDPR, CCPA, Cpra, Isms, GRC, Risk Assessment, Cyber Security

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

Figma

Figma

San Francisco, CA
Security Scientist
$140k+/yrRemoteSecurity Engineering

Security Scientist analyzing attacker and user behavior, building data-driven detections, and leading security investigations and design reviews. Requires strong security and anti-abuse knowledge, SQL fluency, scripting proficiency, and experience with distributed data systems and statistical methods.

hud

hud

San Francisco, CA

Security Engineer
No salary listedOn-siteSecurity Engineering

Own and build the company’s security program as its first full-time security hire, covering product, cloud, infrastructure, incident response, compliance, and customer trust. The role requires hands-on security engineering and incident leadership, with experience operating SOC 2 or comparable frameworks.

Stripe

Stripe

United States

Abuse Research Engineer
No salary listedRemote5+ YOESecurity Engineering

Conduct proactive threat hunting and adversary simulation to uncover financial fraud tactics, enrich threat intelligence, and improve platform controls. The role requires at least five years of relevant cybersecurity, abuse, or trust experience plus strong Python, SQL, investigative, and data-analysis skills.

Anthropic

Anthropic

San Francisco, CA
Security Engineer, Offensive Security
$300k+/yrHybrid5+ YOESecurity Engineering

Conduct offensive security operations, red-team engagements, penetration testing, and adversarial simulations across cloud, endpoint, and bare-metal environments. The role requires at least five years of experience, strong engineering skills, and expertise across multiple security domains.