Назад
обновлено 8 дней назад

Security Risk and Compliance Lead (FedRAMP)

158 000 - 180 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Risk and Compliance Lead (FedRAMP): Operating Asana’s FedRAMP continuous monitoring and authorization programme while supporting SOC 2 and ISO 27001 control frameworks with an accent on compliance operations, evidence collection, and audit readiness. Focus on managing monthly FedRAMP submissions, closing control gaps, coordinating audits, and improving evidence workflows across Engineering, IT, People, Legal, Privacy, and R&D.

Location: San Francisco office with an office-centric hybrid schedule; in-office days are Monday, Tuesday, and Thursday. Most employees may work from home on Wednesdays, while Fridays depend on the role and team.

Base salary: $158,000–$180,000 per year, plus potential equity and benefits.

Company

Asana is a SaaS platform for human and AI collaboration used by teams worldwide to manage important goals and work.

What you will do

  • Own monthly FedRAMP Continuous Monitoring package submissions and maintain the calendar of time-bound deliverables.
  • Coordinate with Engineering, IT, People, Legal, Privacy, and R&D to mature FedRAMP controls, close gaps, and complete remediation.
  • Support SOC 2, ISO 27001, and other applicable control frameworks and coordinate external compliance audits.
  • Manage evidence collection workflows in the GRC platform and keep audit artifacts current and mapped to controls.
  • Document evidence procedures and identify opportunities to automate repetitive collection tasks.
  • Report controls maturity and programme health to senior leadership while supporting control owners across the business.

Requirements

  • 5+ years of experience in GRC, information security, or a closely related field; internships and co-ops count.
  • Hands-on FedRAMP experience is required, ideally involving Continuous Monitoring, evidence collection, or a FedRAMP Moderate or High boundary.
  • Foundational knowledge of SOC 2, ISO 27001, or NIST CSF.
  • Ability to manage multiple workstreams, track monthly obligations, and maintain accurate audit artifacts.
  • Clear communication skills and the ability to explain compliance requirements to technical and non-technical stakeholders.
  • Comfort working with SaaS engineering concepts and collaborating across Engineering, People, IT, Legal, Privacy, and R&D.

Nice to have

  • Experience with GRC platforms, compliance automation, scripting, or API integrations.
  • Curiosity about AI tools and emerging technologies and a willingness to use them to improve productivity and decision-making.

Culture & Benefits

  • Office-centric hybrid working model with global collaboration.
  • Mental health, wellness, and fitness benefits.
  • Career coaching and professional support.
  • Inclusive family-building benefits and long-term savings or retirement plans.
  • In-office culinary options supporting different dietary preferences.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →