Назад
Company hidden
6 дней назад

Security Risk and Compliance Analyst (SaaS)

130 000 - 160 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Security Risk and Compliance Analyst (GRC): Maturing and operating the compliance and certification program with an accent on controls maturity, policy governance, and audit execution. Focus on automating evidence pipelines, maintaining SOC 2, ISO 27001, and FedRAMP certifications, and coordinating audit cycles.

Location: Must be based in the San Francisco office (Hybrid: Monday, Tuesday, and Thursday in-office).

Salary: $130,000–$160,000

Company

hirify.global is a leading platform for human and AI collaboration helping millions of teams orchestrate their work from small projects to strategic initiatives.

What you will do

  • Maintain and improve the control framework tracking effectiveness across SOC 2, ISO 27001, and FedRAMP Moderate.
  • Partner with Engineering, IT, and People teams to close control gaps and drive remediation efforts.
  • Manage external compliance audits end-to-end, including evidence coordination and finding closure.
  • Own the monthly FedRAMP Continuous Monitoring (ConMon) package submission and deliverables.
  • Optimize evidence collection workflows within the GRC platform to ensure audit readiness.

Requirements

  • 3+ years of experience in GRC, information security, or a closely related field.
  • Foundational knowledge of security compliance frameworks (SOC 2, ISO 27001, NIST CSF, or FedRAMP).
  • Ability to translate complex compliance requirements into plain language for various stakeholders.
  • Strong organizational skills to manage time-sensitive obligations and audit artefacts.
  • Must be based in San Francisco for an office-centric hybrid schedule.

Nice to have

  • Exposure to compliance automation, GRC platforms, scripting, or API integrations.
  • Interest in modern SaaS engineering and the technical context behind security controls.

Culture & Benefits

  • Comprehensive compensation package including base salary and equity.
  • Mental health, wellness, and fitness benefits.
  • Career coaching and professional support.
  • Inclusive family building benefits.
  • Retirement plans and in-office culinary options.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →