Posted by employer 4 months ago
First seen on Joblaze 4 months ago
Last verified on the company career page 11 hours ago
Requirements
Not disclosed in this posting: visa sponsorship.
Benefits
Joblaze summary
The Security Risk and Compliance Analyst at Asana is responsible for enhancing and managing the company's compliance and certification programs, focusing on controls maturity and audit execution. This role requires familiarity with compliance frameworks like SOC 2 and ISO 27001, along with strong organizational skills to manage multiple deadlines and collaborate with various teams. Ideal candidates have early-career experience in Governance, Risk, and Compliance, and a willingness to develop their technical skills in a dynamic SaaS environment.
Joblaze insights
Quick facts
From the original posting
As a Security Risk and Compliance Lead you will play a hands-on role in maturing and operating Asana's compliance and certification programme—with a primary focus on FedRAMP Continuous Monitoring and authorization activities. This role sits at the intersection of traditional GRC work and compliance engineering: you will own our FedRAMP programme day-to-day, while also supporting our broader audit cycles and control frameworks across SOC 2 and ISO 27001.
This is an excellent opportunity for someone with early-career GRC experience who has a strong grounding in FedRAMP and is excited to grow their technical skills in a high-growth SaaS environment. You will partner closely with Security Engineering, Legal, Privacy, and R&D to ensure our FedRAMP obligations are met with rigour, our controls are effective, and our certifications are maintained.
This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.
FedRAMP Continuous Monitoring
Controls Maturity & Broader Certifications
Evidence Collection & Automation
At Asana, we’re committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you’re interested in this role and don’t meet every listed requirement, we still encourage you to apply.
Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we’re committed to looking at market value, which is why we check ourselves and conduct a yearly pay equity audit.
For this role, the estimated base salary range is between $158,000–$180,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. In addition to base salary, your compensation package may include equity and benefits. Speak with your Talent Acquisition Partner to learn more.
These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations.
#LI-Hybrid
About us
Standard company text repeated across Asana's postings is omitted here.