Security Risk and Compliance Analyst
Asana · San Francisco, CA · Infrastructure Engineering
About this role
Asana is hiring a mid-level Security Analyst based in San Francisco, CA. The posting calls out experience with API Development, Security, Compliance, SaaS. Compensation is listed at $130,000–$160,000 per year.
- Role
- Security Analyst
- Function
- security
- Level
- mid
- Track
- Individual contributor
- Employment
- Full-time
- Location
- San Francisco, CA
- Department
- Infrastructure Engineering
More roles at Asana
Job description
from Asana careersRole Overview
As a Security Risk and Compliance Analyst you will play a hands-on role in maturing and operating Asana’s compliance and certification programme—specifically across controls maturity, policy governance, and audit execution. This role sits at the intersection of traditional GRC work and compliance engineering: you will help maintain our control frameworks and run our audit cycles, while also contributing to the automation initiatives that make our compliance programme scalable and repeatable.
This is an excellent opportunity for someone with early-career GRC experience who is excited to grow their technical skills and help shape how a high-growth SaaS company approaches compliance automation. You will partner closely with Security Engineering, Legal, Privacy, and R&D to ensure our controls are effective, our evidence pipelines are reliable, and our certifications—SOC 2, ISO 27001, and FedRAMP—are maintained with rigour.
This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. If you’re interviewing for this role, your recruiter will share more about the in-office requirements.
What You’ll Achieve
Controls Maturity & Certifications
- Support the maintenance and continuous improvement of Asana’s control framework, tracking control effectiveness across SOC 2, ISO 27001, FedRAMP Moderate, and other applicable standards.