# Staff Security Analyst

**Company:** [Navan](https://hotfix.jobs/companies/navan)
**Location:** Palo Alto, CA
**Role:** Security Engineering
**Salary:** $131k – $291k/yr
**Experience:** 7+ years
**Skills:** pci dss, sox itgc, ISO 27001, iso 42001, soc 1, SOC 2, nist csf, AWS, GRC, vanta, drata, cisa, cism, cissp, ccsp
**Posted:** 2026-07-29

> Lead and scale compliance architecture by owning the ISMS, managing multi-framework audits (PCI, SOX, SOC, ISO), automating controls, and bridging regulators with internal teams. Requires 6-8+ years GRC experience, deep framework expertise, cloud security knowledge, and relevant certifications.

## Job Description

## What You'll Do

### Compliance Program Leadership (Primary Focus)
- Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II)
- Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processes
- Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessments
- Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectives
- Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflows
- Monitor regulatory changes and emerging compliance requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligations

### Control Framework & Testing
- Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence requirements
- Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologies
- Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategies
- Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditability

### Governance, Policy & Documentation
- Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory requirements and industry best practices
- Develop and maintain control mapping across multiple frameworks to identify overlapping requirements and optimize control implementation
- Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change tracking
- Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committees

### Cross-Functional Collaboration & Stakeholder Management
- Articulate complex compliance requirements and risk scenarios to C-level executives, board members, and non-technical stakeholders
- Collaborate closely with Engineering, IT, Finance, Legal, People Ops, and Business Units to bridge control gaps and implement compliance solutions
- Develop and deliver security compliance training programs for employees, contractors, and control owners; build compliance awareness throughout the organization

## What We’re Looking For

### Experience & Background
- 6-8+ years of progressive experience in security governance, risk and compliance (GRC), information security auditing, or compliance program management
- Demonstrated experience working directly with Big Four or external auditors through full audit cycles
- Control automation experience: Proven success implementing automated evidence collection, continuous control monitoring, and compliance workflow automation
- ISMS management: Hands-on experience running an Information Security Management System (ISO 27001 ISMS or equivalent)

### Framework & Regulatory Knowledge
- Deep expertise in PCI DSS (all 12 requirements, SAQ types, ROC processes, compensating controls)
- Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls, change management, backup/recovery, segregation of duties)
- Proficiency with ISO 27001:2022 and ISO 42001:2023 (AI Management System) frameworks
- Hands-on experience with SOC 1 (SSAE 18/ISAE 3402) and SOC 2 (Trust Services Criteria) audit requirements
- Working knowledge of security frameworks including NIST CSF, NIST SP 800-53, CIS Controls, or COBIT

### Technical & Cloud Security
- Deep understanding of cloud security architecture, identity and access management (IAM), network security, data protection, and logging/monitoring within AWS (Azure or GCP experience is a strong plus)
- Practical knowledge of technical control implementation including encryption, secure configuration management, vulnerability management, and incident response
- Ability to review and assess security architectures, data flows, and system designs from a compliance perspective

### Tools & Technology
- Hands-on experience with compliance automation platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, or similar)
- Experience implementing automated evidence collection using APIs, scripts, or integration platforms
- Proficiency with vulnerability scanners, SIEM platforms, configuration management tools, and compliance scanning solutions

### Education & Certifications
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field
- Certifications (one or more): CISA, CISM, CISSP, ISO 27001 Lead Auditor or Lead Implementer, CCSP or CCSK, PCI ISA or QSA

### Specialized Experience
- Prior experience with FedRAMP (Low/Moderate/High), GovRAMP, CMMC (Level 1-3), StateRAMP, or TX-RAMP authorization processes
- Experience with NIST SP 800-171, DFARS compliance, or DoD authorization frameworks
- Demonstrated success building and maintaining unified or common control frameworks that map requirements across multiple standards
- Previous experience with Big Four consulting firms (Deloitte, PwC, EY, KPMG) or specialized security/compliance consulting practices

## Similar roles

- [Staff Cross Domain Solution Engineer](https://hotfix.jobs/jobs/7f8aab9b-de06-4349-9324-7a06a9d6111d) - Shield AI - Dallas, TX - $130k – $200k/yr
- [Staff Security Engineer](https://hotfix.jobs/jobs/5b580478-4136-48f8-bf55-d821d66f2a52) - Okta - San Francisco, CA - $134k – $185k/yr
- [Staff Security Operations Engineer](https://hotfix.jobs/jobs/d4ba9090-7583-438e-87fe-eafcdc2da5e9) - Cribl - Remote - $128k – $200k/yr
- [Staff Security Architect](https://hotfix.jobs/jobs/bb106601-c89c-4669-93cf-d7f23dfb0b6c) - Kraken - Remote - $127k – $254k/yr
- [Security Software Engineer, Infrastructure Security (Staff or Senior)](https://hotfix.jobs/jobs/f000eb12-58fe-45b4-a3d5-ff318709d9fb) - MongoDB - Remote - $127k – $249k/yr

**Apply:** https://hotfix.jobs/jobs/594d6d79-81b6-47a9-b3d9-4d7126e84c8d
**Canonical:** https://hotfix.jobs/jobs/594d6d79-81b6-47a9-b3d9-4d7126e84c8d