Senior Security GRC Analyst

| Palo Alto, CA, USA | Hybrid
Employer Provided Salary: 105,000-192,000 Annually
Salary data is provided by the employer. Please note this is not a guarantee of compensation.
Sorry, this job was removed at 12:08 p.m. (PST) on Tuesday, May 7, 2024
Find out who's hiring in San Francisco.
See all Data + Analytics jobs in San Francisco
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

The Senior Security GRC Analyst will lead information security and compliance and certification efforts across Navan. In this role you will be responsible for driving compliance with various security standards and frameworks, achieving relevant certifications and attestations, and working with business stakeholders to design and implement security controls. You will influence and partner with stakeholders across the organization to continuously improve Navan’s security control environment and provide assurance to customers. The ideal candidate is someone who thrives in a high growth environment and easily adjusts to rapid changes in people, process, and product.

What You’ll Do:

  • Work very closely with many cross-functional teams to assist with understanding control gaps and integrating control requirements (HR, Finance, Legal, etc.)
  • Engage directly with product engineering and other organizational teams on compliance, external audit engagements, and assessments
  • Perform planned periodic assessments and testing activities against all applicable security compliance controls, policies, standards, etc.
  • Assist with Red team testing efforts and other offensive security initiatives
  • Assist in driving maturity improvements for the overall cyber security program
  • Responsible for leading internal security assessment walkthroughs and evidence collection for external audit engagements 
  • Lead the execution of external audit activities over Navan’s products and internal controls in accordance with but not limited to SOC 1, SOC 2, PCI, ISO 27001, NIST CSF
  • Develop metrics and reporting to demonstrate compliance and assurance status and progress
  • Drive controls automation and supporting process improvements in the compliance portfolio
  • Work closely with the security team on assessment findings and related remediation 
  • Provide ongoing guidance and consultation to the organization to promote a progressive and sustainable security and compliance assurance program
  • Use automation to test controls and implement exception reporting
  • Work in collaboration with Security to develop and implement a centralized audit evidence repository and GRC tool
  • Integrate ongoing changes to laws, regulations, and frameworks as required into daily activities

What We’re Looking For:

  • 3+ years of security governance, risk and compliance experience in developing programs to comply with common certification and attestation requirements like PCI DSS, ISO 27001, SOC1, SOC2 etc.
  • Expert understanding of PCI DSS, GDPR, ISO 27001, SOC, regulations and framework required
  • Expert understanding of cloud controls and environments (AWS)
  • A strong foundation in information security and ability to explore new security threats, the technology controls, and the tactics required to mitigate those threat
  • Practical understanding of IT Security Compliance, risk management and information security principles including access control, network security, information security architecture, information security operations, and leading practices and associated tools in a cloud environment
  • Strong analytical, diagnostic, critical thinking, and project management skills
  • Superb ability to represent data in graphical form
  • Strong Engagement skills (Internal & External)
  • Demonstrated experience creating security policies, procedures and standards
  • Ability to cater communication to a wide range of technical, clinical, and cultural backgrounds
  • Big 4 experience will be a plus
  • CISA, CISM, CISSP, CSA CCSK, ISC(2) CCSP or other Information Security related designation will be a plus
  • Experience in offensive security disciplines will be a major plus
  • Experience with unified control frameworks development and implementation will be a major plus

The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.
For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.

Pay Range

$105,000$192,000 USD

Read Full Job Description
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
  • People Operations
    • JavaLanguages
    • JavascriptLanguages
    • KotlinLanguages
    • SqlLanguages
    • SwiftLanguages
    • TypeScriptLanguages
    • Google AnalyticsAnalytics
    • TableauAnalytics
    • FigmaDesign
    • PhotoshopDesign
    • AsanaManagement
    • Google DriveManagement
    • Google DocsManagement
    • Google SlidesManagement
    • JIRAManagement
    • Chorus.AICRM
    • DocuSignCRM
    • LinkedIn SalesNavigatorCRM
    • OutreachCRM
    • SalesforceCRM
    • MailChimpEmail
    • SlackCollaboration
    • ZoomCollaboration
    • AsanaProject Management

Location

3045 Park Blvd, Palo Alto, CA 94304

An Insider's view of Navan

What are some social events your company does?

It’s may sound cliche, but Navan’s sales culture is ‘work hard, play hard’. Navan knows how to have fun and build an awesome culture. It's beyond your usual happy hours; I’m talking about incredible trips, gourmet handrolls, and lots of dogs! It’s safe to say I’ve met my best friends at Navan.

Nathaniel

Mid-Market Account Executive

How do you collaborate with other teams in the company?

The culture here promotes direct communication and mutual trust, fostering cross-functional collaboration among talented and driven coworkers. Our clear business goals empower us to work together and constantly challenge each other to raise the bar and deliver the best platform, experience, and partnership for our customers.

Jordan

Regional Director, Mid-Market Expense Sales

How has your career grown since starting at the company?

I've had the pleasure of sitting in 8+ roles here at Navan over the last 5 years (SDR to Regional Director). Being at a business with lofty goals and a "failure isn't an option" mentality opens the door to expedite career progression, constant new opportunities and projects, and the ability to learn from a one-of-a-kind leadership team.

Anna

Regional Director, Enterprise Expense Sales

What are Navan Perks + Benefits

Navan Benefits Overview

Our Benefits

We realize benefits are important as they support keeping you at your best at all times. Our benefits are here for you if you get sick or hurt, help you save for now and later, encourage you to take time off work and travel, and provide perks specific to being a Navan employee both in and out of the office.

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Team based strategic planning
Pair programming
Open office floor plan
Employee resource groups
Employee-led culture committees
Hybrid work model
In-person all-hands meetings
President's club
Employee awards
Diversity
Diversity employee resource groups
Hiring practices that promote diversity
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Wellness programs
Mental health benefits
Financial & Retirement
401(K)
Company equity
Child Care & Parental Leave
Generous parental leave
Family medical leave
Company sponsored family events
Vacation + Time Off
Unlimited vacation policy
Generous PTO
Paid holidays
Paid sick days
Flexible time off
Floating holidays
Bereavement leave benefits
Company-wide vacation
Office Perks
Commuter benefits
Company-sponsored outings
Free daily meals
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Pet friendly
Relocation assistance
Home-office stipend for remote employees
Mother's room
Professional Development
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education available during work hours
Online course subscriptions available
Customized development tracks
Personal development training

More Jobs at Navan

Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about NavanFind similar jobs like this