# Senior Security Assurance Analyst

**Company:** [Lyft](https://hotfix.jobs/companies/lyft)
**Location:** New York, NY
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** ISO 27001, Pci Dss, SOC 2, HIPAA, Nist Csf, GRC, Security Risk Management, Jira, Confluence, Safebase, Vulnerability Management, AWS, GCP, Azure, LLMs
**Posted:** 2026-08-10

> Leads security assurance, governance, risk, and compliance programs across ISO 27001, PCI DSS, SOC 2, HIPAA, and international frameworks. The role manages audits, policies, risk treatment, automated evidence collection, customer questionnaires, and cross-functional advisory work.

## Job Description

## Responsibilities

### Program & Audit Ownership
- Own and lead the ISO 27001 compliance program end-to-end, from certification planning and internal audit through surveillance cycles and Statement of Applicability updates.
- Drive execution across a multi-program compliance portfolio spanning SOC 2, PCI DSS, HIPAA, NIST CSF, UK Cyber Essentials, Spain ENS, the Cyber Resilience Act (CRA), Radio Equipment Directive (RED), and NIS2.
- Serve as the primary liaison to external auditors, Qualified Security Assessors (QSAs), and certification bodies, managing concurrent audit engagements and stakeholder timelines.

### Risk, Policy & Stakeholder Advisory
- Own the Security Risk Management Framework, including risk identification, treatment, reporting, tracking, and communication.
- Develop, review, and maintain information security and data protection policies, standards, and procedures.
- Advise Engineering, Legal, Privacy, and Sales on complex compliance requirements and translate technical risk into actionable guidance.
- Review security provisions in customer contracts, MSAs, DPAs, and security exhibits with Legal and Sales.

### Evidence, Automation & Tooling
- Drive evidence collection and continuous control testing using Jira and Confluence.
- Partner with Engineering to implement automated evidence collection, continuous control testing, and remediation tracking.
- Use AI tools and LLM-based workflows to improve evidence review, policy drafting, control testing, questionnaire responses, and other assurance processes.

### Customer-Facing Assurance
- Own responses to customer security questionnaires, including CAIQ and SIG.
- Manage the external trust center through SafeBase.

## Requirements
- 5+ years of experience in security governance, risk, and compliance (GRC), IT audit, or a related security assurance role.
- 5+ years of hands-on experience with ISO 27001 and PCI DSS.
- In-depth knowledge of SOC 2, HIPAA, and NIST CSF.
- Experience managing compliance portfolios involving EU and UK frameworks, standards, or regulations.
- Experience managing, reviewing, and drafting information security policies and procedures.
- Strong technical background and ability to communicate and negotiate effectively with Engineering.
- Strong cross-functional communication, leadership, organization, and prioritization skills.
- Ability to manage competing priorities amid resource constraints and tight deadlines.
- Excellent written and verbal communication skills across technical, business, and executive audiences.

## Preferred Qualifications
- Experience with two or more of ISO 27001, SOC 2, PCI DSS, and SOX ITGC.
- Experience with GDPR, the EU AI Act, NIS2, or other international privacy and security compliance requirements.
- Experience testing, designing, or documenting vulnerability management programs.
- Experience reviewing customer contract security provisions and providing actionable feedback to Legal and Sales.
- Experience with GRC platforms such as AuditBoard CrossComply, Vanta, or Drata; Jira; and SafeBase.
- Experience using AI tools or LLMs to automate compliance and assurance processes, documentation, or controls.
- Certifications such as CISA, CISSP, CISM, CRISC, or ISO 27001 Lead Auditor/Implementer.
- Big Four or Big Three consulting experience.
- Scripting and automation experience.
- Experience with AWS, Google Cloud, or Azure.

## Compensation & Benefits
- Medical, dental, and vision insurance options.
- Mental health benefits.
- Family building, child care, and pet benefits.
- 401(k) plan with company match.
- Paid holidays and paid time off.
- 18 weeks of paid parental leave for biological, adoptive, and foster parents.
- Subsidized commuter benefits.
- Monthly Lyft credits and complimentary Lyft Pink membership.
- Hybrid schedule requiring in-office work three days per week; hybrid roles may work from anywhere for up to four weeks per year.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/ff5639d1-b2d5-40ba-a88e-0fb9148fab57
**Canonical:** https://hotfix.jobs/jobs/ff5639d1-b2d5-40ba-a88e-0fb9148fab57