Security Risk and Compliance Analyst

Asana Asana · Enterprise · San Francisco, CA · Infrastructure Engineering

Security Risk and Compliance Analyst role focused on maturing and operating a compliance and certification program, including controls maturity, policy governance, and audit execution. The role involves maintaining control frameworks, running audit cycles, and contributing to automation initiatives for scalability. It requires partnering with Security Engineering, Legal, Privacy, and R&D to ensure effective controls and maintain certifications like SOC 2, ISO 27001, and FedRAMP. Specific responsibilities include supporting control framework maintenance, engaging with teams for controls maturity activities, supporting external audits, owning the FedRAMP Continuous Monitoring package, and managing evidence collection workflows within a GRC platform, with an opportunity to automate evidence-gathering tasks.

What you'd actually do

  1. Support the maintenance and continuous improvement of Asana’s control framework, tracking control effectiveness across SOC 2, ISO 27001, FedRAMP Moderate, and other applicable standards.
  2. Own the monthly FedRAMP ConMon package submission, ensuring it is accurate, complete, and delivered on time every month.
  3. Own evidence collection workflows within our GRC platform, ensuring controls are reliably mapped, evidence is current, and audit artefacts are ready year-round.
  4. Support external compliance audits end-to-end: coordinating evidence requests, liaising with auditors, and tracking findings through to closure.
  5. Proactively engage with a wide range of teams—including Engineering, IT, and People—to work through controls maturity activities, close existing gaps, and drive remediation efforts to completion with clear documentation of progress.

Skills

Required

  • Governance, Risk, and Compliance (GRC)
  • information security
  • security compliance frameworks (SOC 2, ISO 27001, NIST CSF, or FedRAMP)
  • communication
  • organization
  • deadline-driven
  • stakeholder engagement

Nice to have

  • compliance automation
  • evidence collection tooling
  • GRC platforms
  • scripting
  • API integrations
  • SaaS engineering context

What the JD emphasized

  • SOC 2
  • ISO 27001
  • FedRAMP