Talent.com
Security Risk and Compliance Analyst
Security Risk and Compliance AnalystAsana • San Francisco, CA, United States
Security Risk and Compliance Analyst

Security Risk and Compliance Analyst

Asana • San Francisco, CA, United States
12 days ago
Job type
  • Full-time
Job description

At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance with legal and regulatory requirements, and fostering a culture of security throughout our product and operations. We are a team of security engineers and risk and compliance practitioners who build innovative safeguards and collaborate across the organization to build and maintain trust at scale.

As a Security Risk and Compliance Analyst at Asana, you'll play a critical and high-impact role in building and maintaining trust with Asana's global customers. You will be responsible for initiatives that continuously improve our vendor risk assessment and security risk management programs, ensuring we maintain a strong security posture and meet both compliance requirements and customer expectations.

This is a highly cross-functional role where you'll partner closely with Legal, Privacy, Finance, R&D, and other key stakeholders. You'll help evolve our programs with a strategic, risk-based mindset-balancing operational excellence with agility as we grow and scale.

This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.

What you'll achieve :

  • Vendor Risk Management : Own and operate Asana's vendor risk management program, including performing due diligence for new vendors, managing ongoing monitoring and reporting, and reviewing vendor contracts for security and compliance requirements.
  • Security Risk Management : Support the execution of periodic assessments across the organization to identify, evaluate, and track risks-driving mitigation and treatment efforts with business and technical owners.
  • Risk Register Maintenance : Assist in maintaining the central security risk register to promote and drive accountability across the organization.
  • FedRAMP Compliance : Support FedRAMP continuous monitoring activities to ensure ongoing compliance with FedRAMP moderate requirements.
  • Compliance Audit Support : Partner with internal teams to support external compliance audits such as FedRAMP, SOC 2, and ISO 27001, providing evidence and program documentation as needed.
  • Policy Management : Help to draft, update, and maintain security policies, standards, and procedures that align with evolving business needs and industry best practices.

About you :

  • 3+ years of experience in Governance Risk and Compliance, with a focus on risk assessments and security risk management.
  • Demonstrated understanding of security compliance frameworks and audits (e.g., SOC 2, ISO 27001, PCI DSS, NIST, HIPAA, FedRAMP, etc.).
  • Experience with enterprise SaaS applications hosted on public cloud platforms such as AWS.
  • Experience performing third-party vendor security reviews and due diligence processes
  • Proven ability to drive operational process improvements and develop metrics for tracking success.
  • Excellent communicator and influencer, with the ability to translate complex security and compliance requirements to both technical and non-technical stakeholders.
  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.
  • At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.

    What we'll offer

    Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we're committed to looking at market value which is why we check ourselves and conduct a yearly pay equity audit.

    For this role, the estimated base salary range is between $130,000-$160,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base salary range for this role may be modified.

    In addition to base salary, your compensation package may include additional components such as equity, sales incentive pay (for most sales roles), and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.

    We strive to provide equitable and competitive benefits packages that support our employees worldwide and include :

  • Mental health, wellness & fitness benefits
  • Career coaching & support
  • Inclusive family building benefits
  • Long-term savings or retirement plans
  • In-office culinary options to cater to your dietary preferences
  • These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.

    #LI-Hybrid

    About us

    Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.

    Join Asana's Talent Network to stay up to date on job opportunities and life at Asana.

    Create a job alert for this search

    Risk Compliance Analyst • San Francisco, CA, United States

    Related jobs
    Lead Governance, Risk, and Compliance (GRC) Analyst

    Lead Governance, Risk, and Compliance (GRC) Analyst

    Morrison & Foerster LLP • San Francisco, CA, United States
    Full-time
    Lead Governance, Risk, and Compliance (GRC) Analyst.Position Type : Information Technology.At MoFo, we couldn't write our own success story without yours. This role can be based in San Francisco, Pal...Show more
    Last updated: 7 days ago • Promoted
    Security Compliance Senior Analyst

    Security Compliance Senior Analyst

    Coinbase • Oakland, CA, United States
    Full-time
    Ready to be pushed beyond what you think you're capable of?.At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, ...Show more
    Last updated: 16 days ago • Promoted
    Compliance Analyst

    Compliance Analyst

    Rose International • Oakland, CA, US
    Full-time +1
    Hybrid - 3 days onsite, 2 days remote.Standard work week - 8 hours per day, 5 days per week.Estimated Duration (In months) : . Analysis, Compliance, Documentation, Finance, MS Excel, MS Office, MS Wor...Show more
    Last updated: 7 days ago • Promoted
    Associate Application Security Engineer

    Associate Application Security Engineer

    PG Forsta • Emeryville, CA, United States
    Full-time
    PG Forsta is the leading experience measurement, data analytics, and insights provider for complex industries-a status we earned over decades of deep partnership with clients to help them understan...Show more
    Last updated: 30+ days ago • Promoted
    Governance, Risk & Compliance Lead

    Governance, Risk & Compliance Lead

    Perplexity AI Inc. • San Francisco, CA, United States
    Full-time
    Perplexity is seeking a highly experienced Governance, Risk & Compliance Analyst to join our world-class team.You will help shape our compliance and risk management program.If you are a self-motiva...Show more
    Last updated: 20 days ago • Promoted
    Lead Governance, Risk, and Compliance (GRC) Analyst

    Lead Governance, Risk, and Compliance (GRC) Analyst

    Morrison Foerster • San Francisco, CA, United States
    Full-time
    Lead Governance, Risk, and Compliance (GRC) Analyst.This role can be based in San Francisco, Palo Alto, Los Angeles, San Diego, Denver, Austin, Boston, New York or Washington, D.This role requires ...Show more
    Last updated: 10 days ago • Promoted
    Security Researcher & Analyst - Application Security

    Security Researcher & Analyst - Application Security

    Cloudflare Inc • San Francisco, CA, United States
    Full-time
    At Cloudflare, we are on a mission to help build a better Internet.Today the company runs one of the world's largest networks that powers millions of websites and other Internet properties for cust...Show more
    Last updated: 30+ days ago • Promoted
    Hybrid GRC Security Analyst — Cyber Risk & Compliance

    Hybrid GRC Security Analyst — Cyber Risk & Compliance

    San Francisco • San Francisco, CA, United States
    Full-time
    A major city government in San Francisco is seeking a Business Analyst for the cybersecurity team.This full-time position involves performing risk assessments, vendor evaluations, and developing re...Show more
    Last updated: 3 days ago • Promoted
    (Agile1)Compliance Analyst

    (Agile1)Compliance Analyst

    Abacus Service Corporation • Oakland, CA, US
    Full-time
    Only submit local candidates near Oakland work location / Bay Area (otherwise candidate will be rejected).Required in office at Oakland go 3 days a week and remote 2 days a week.If PPE is required at...Show more
    Last updated: 6 days ago • Promoted
    Security GRC Analyst

    Security GRC Analyst

    Nava Software Solutions • San Francisco, CA, United States
    Full-time
    NAVA Software solutions is looking for a Security GRC Analyst.Location : San Francisco , CA - Hybrid.Analyst with 2+ years' experience and with good understanding of security controls and compliance...Show more
    Last updated: 13 days ago • Promoted
    Senior Product Manager, AI-Driven Security Operations

    Senior Product Manager, AI-Driven Security Operations

    Anomali • Redwood City, CA, United States
    Full-time
    Anomali is headquartered in Silicon Valley and is the Leading AI-Powered Security Operations Platform that is modernizing security operations. At the center of it is an omnipresent, intelligent, and...Show more
    Last updated: 3 days ago • Promoted
    Registry Data Systems Analyst- Remote - 136400

    Registry Data Systems Analyst- Remote - 136400

    UC San Diego Health • Richmond, CA, United States
    Remote
    Full-time
    This position is limited to California Residents and may require travel to Richmond and / or Sacramento, California.UCSD Layoff from Career Appointment. Apply by 8 / 27 / 2025 for consideration with prefe...Show more
    Last updated: 23 days ago • Promoted
    Target Security Specialist

    Target Security Specialist

    Target • Sausalito, CA, US
    Full-time
    Starting Hourly Rate / Salario por Hora Inicial : $23.Working at Target means helping all families discover the joy of everyday life. We bring that vision to life through our values and culture.ALL A...Show more
    Last updated: 1 day ago • Promoted
    (Agile1)Compliance Analyst

    (Agile1)Compliance Analyst

    Staffing • Oakland, CA, US
    Full-time
    Top things looking for in a candidate (top skill sets) : 1) Problem-solving : Analyzing complex issues, identifying root causes, and developing and implementing effective solutions.Critical thinking : ...Show more
    Last updated: 5 days ago • Promoted
    Risk and Compliance Analyst II

    Risk and Compliance Analyst II

    Munger, Tolles & Olson • San Francisco, CA, United States
    Full-time
    Full Time, Non-exempt, Offsite (in-office based on business needs).Must be within commutable distance to the office.Los Angeles, CA or San Francisco, CA or Washington, D. Maryland, or Virginia and w...Show more
    Last updated: 10 days ago • Promoted
    Security Risk Analyst

    Security Risk Analyst

    Anthropic • San Francisco, CA, United States
    Full-time
    Anthropic's mission is to create reliable, interpretable, and steerable AI systems.We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group ...Show more
    Last updated: 16 days ago • Promoted
    Security Analyst

    Security Analyst

    Minted • San Francisco, CA, United States
    Full-time
    As a Security Analyst II / III at Minted, you'll play a key role in protecting the systems and data that power our global artist community and e-commerce customers. You'll monitor our environment, res...Show more
    Last updated: 16 days ago • Promoted
    Business Systems Analyst (0657U), Berkeley IT - #82566

    Business Systems Analyst (0657U), Berkeley IT - #82566

    University of California-Berkeley • Berkeley, CA, United States
    Full-time +1
    At the University of California, Berkeley, we are dedicated to fostering a community where everyone feels welcome and can thrive. Our culture of openness, freedom and belonging make it a special pla...Show more
    Last updated: 5 days ago • Promoted