Senior Security Assurance Analyst
Leads security assurance, governance, risk, and compliance programs across ISO 27001, PCI DSS, SOC 2, HIPAA, and international frameworks. The role manages audits, policies, risk treatment, automated evidence collection, customer questionnaires, and cross-functional advisory work.
About the job
Responsibilities
Program & Audit Ownership
- Own and lead the ISO 27001 compliance program end-to-end, from certification planning and internal audit through surveillance cycles and Statement of Applicability updates.
- Drive execution across a multi-program compliance portfolio spanning SOC 2, PCI DSS, HIPAA, NIST CSF, UK Cyber Essentials, Spain ENS, the Cyber Resilience Act (CRA), Radio Equipment Directive (RED), and NIS2.
- Serve as the primary liaison to external auditors, Qualified Security Assessors (QSAs), and certification bodies, managing concurrent audit engagements and stakeholder timelines.
Risk, Policy & Stakeholder Advisory
- Own the Security Risk Management Framework, including risk identification, treatment, reporting, tracking, and communication.
- Develop, review, and maintain information security and data protection policies, standards, and procedures.
- Advise Engineering, Legal, Privacy, and Sales on complex compliance requirements and translate technical risk into actionable guidance.
- Review security provisions in customer contracts, MSAs, DPAs, and security exhibits with Legal and Sales.
Evidence, Automation & Tooling
- Drive evidence collection and continuous control testing using Jira and Confluence.
- Partner with Engineering to implement automated evidence collection, continuous control testing, and remediation tracking.
- Use AI tools and LLM-based workflows to improve evidence review, policy drafting, control testing, questionnaire responses, and other assurance processes.
Customer-Facing Assurance
- Own responses to customer security questionnaires, including CAIQ and SIG.
- Manage the external trust center through SafeBase.
Requirements
- 5+ years of experience in security governance, risk, and compliance (GRC), IT audit, or a related security assurance role.
- 5+ years of hands-on experience with ISO 27001 and PCI DSS.
- In-depth knowledge of SOC 2, HIPAA, and NIST CSF.
- Experience managing compliance portfolios involving EU and UK frameworks, standards, or regulations.
- Experience managing, reviewing, and drafting information security policies and procedures.
- Strong technical background and ability to communicate and negotiate effectively with Engineering.
- Strong cross-functional communication, leadership, organization, and prioritization skills.
- Ability to manage competing priorities amid resource constraints and tight deadlines.
- Excellent written and verbal communication skills across technical, business, and executive audiences.
Preferred Qualifications
- Experience with two or more of ISO 27001, SOC 2, PCI DSS, and SOX ITGC.
- Experience with GDPR, the EU AI Act, NIS2, or other international privacy and security compliance requirements.
- Experience testing, designing, or documenting vulnerability management programs.
- Experience reviewing customer contract security provisions and providing actionable feedback to Legal and Sales.
- Experience with GRC platforms such as AuditBoard CrossComply, Vanta, or Drata; Jira; and SafeBase.
- Experience using AI tools or LLMs to automate compliance and assurance processes, documentation, or controls.
- Certifications such as CISA, CISSP, CISM, CRISC, or ISO 27001 Lead Auditor/Implementer.
- Big Four or Big Three consulting experience.
- Scripting and automation experience.
- Experience with AWS, Google Cloud, or Azure.
Compensation & Benefits
- Medical, dental, and vision insurance options.
- Mental health benefits.
- Family building, child care, and pet benefits.
- 401(k) plan with company match.
- Paid holidays and paid time off.
- 18 weeks of paid parental leave for biological, adoptive, and foster parents.
- Subsidized commuter benefits.
- Monthly Lyft credits and complimentary Lyft Pink membership.
- Hybrid schedule requiring in-office work three days per week; hybrid roles may work from anywhere for up to four weeks per year.
Skills
ISO 27001, Pci Dss, SOC 2, HIPAA, Nist Csf, GRC, Security Risk Management, Jira, Confluence, Safebase, Vulnerability Management, AWS, GCP, Azure, LLMs
Similar jobs
Security Engineering jobsLeads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.