Staff Security Analyst
Navan
| Company | Navan |
| Category | Uncategorised |
| Location | Palo Alto |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 29 Jul 2026 |
| Last verified | 2 Aug 2026 |
| Source | Employer career page (greenhouse) |
Description
We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won’t just maintain compliance—you’ll scale and automate it to eliminate manual friction. In this role, you’ll manage our Information Security Management System (ISMS), lead internal and external audits, and serve as the primary bridge between external regulators and our internal teams. If you excel at translating deep technical expertise into practical, automated solutions, this is your chance to shape our security ecosystem across the organization.
What You'll Do:
Compliance Program Leadership (Primary Focus)
Multi-Framework Compliance Management : Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II)
ISMS Operations : Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processes
Audit Coordination & Management : Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessments
Risk Assessment & Adjustment : Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectives
Control Automation & Optimization : Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflows
Regulatory Compliance Strategy : Monitor regulatory changes and emerging compliance requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligations
Control Framework & Testing
Control Owner Enablement : Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence requirements
Control Testing Program : Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologies
Gap Assessment & Remediation : Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategies
Evidence Management : Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditability
Governance, Policy & Documentation
Policy Development & Maintenance : Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory requirements and industry best practices
Unified Control Framework (UCF) : Develop and maintain control mapping across multiple frameworks to identify overlapping requirements and optimize control implementation
Documentation Governance : Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change tracking
Compliance Reporting : Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committees
Cross-Functional Collaboration & Stakeholder Management
Executive Communication : Articulate complex compliance requirements and risk scenarios to C-level executives, board members, and non-technical stakeholders
Cross-Func
1,970,675 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →