Jobs › California › San Francisco Bay Area › Security Compliance Lead
Security Compliance Lead
Asana is hiring for the job of Security Compliance Lead, San Francisco (On-site). This is a Compliance job in the governance, risk, and compliance field, with a posted range of $158,000–$180,000. Review the full details below and apply directly with Asana.
Role Overview
As a Security Risk and Compliance Lead you will play a hands-on role in maturing and operating Asana s compliance and certification programme with a primary focus on FedRAMP Continuous Monitoring and authorization activities. This role sits at the intersection of traditional GRC work and compliance engineering you will own our FedRAMP programme day-to-day while also supporting our broader audit cycles and control frameworks across SOC 2 and ISO 27001.
This is an excellent opportunity for someone with early-career GRC experience who has a strong grounding in FedRAMP and is excited to grow their technical skills in a high-growth SaaS environment. You will partner closely with Security Engineering Legal Privacy and R;D to ensure our FedRAMP obligations are met with rigour our controls are effective and our certifications are maintained.
This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday Tuesday and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you re interviewing for this role your recruiter will share more about the in-office requirements.
What You’ll Achieve
FedRAMP Continuous Monitoring
Own the monthly FedRAMP ConMon package submission ensuring it is accurate complete and delivered on time every month. Track and drive completion of all timebound FedRAMP requirements by working closely with Engineering People and other responsible teams. Maintain a clear calendar of FedRAMP deliverables and proactively flag risks to timelines escalating where needed to ensure nothing slips. Serve as the internal subject matter expert for FedRAMP acting as the day-to-day point of contact for FedRAMP-related queries from internal teams and helping them understand their obligations and what good looks like. Proactively engage with a wide range of teams including Engineering IT and People to work through FedRAMP controls maturity activities close existing gaps and drive remediation efforts to completion with clear documentation of progress.
Controls Maturity Broader Certifications
Support the maintenance and continuous improvement of Asana s broader control framework across SOC 2 ISO 27001 and other applicable standards. Support external compliance audits end-to-end coordinating evidence requests liaising with auditors and tracking findings through to closure. Contribute to controls maturity scoring and reporting providing ongoing visibility into programme health for senior leadership. Build strong working relationships across the business so that control owners feel supported and accountability is shared not siloed within the compliance team.
Evidence Collection Automation
Own evidence collection workflows within our GRC platform ensuring controls are reliably mapped evidence is current and audit artefacts are ready year-round with particular attention to FedRAMP requirements. Document evidence collection procedures so that processes are transparent auditable and maintainable by the broader team. Where possible identify opportunities to automate repetitive evidence-gathering tasks curiosity and initiative here will be valued though this is not a core requirement of the role.
About You
5+ years of experience in Governance Risk and Compliance (GRC) information security or a closely related field internships and co-ops count. Hands-on experience with FedRAMP ideally including ConMon evidence collection or working within a FedRAMP Moderate or High boundary. This is the most important qualification for this role. Foundational knowledge of broader security compliance frameworks such as SOC 2 ISO 27001 or NIST CSF is a plus but depth in FedRAMP matters most. Organised and deadline-driven you can manage multiple workstreams track time-sensitive obligations (like monthly FedRAMP submissions) and keep audit artefacts tidy without being reminded. Comfortable engaging with a wide variety of teams Engineering People IT Legal to explain compliance requirements gather evidence and build the relationships needed to close control gaps. A clear communicator who can translate compliance requirements into plain language for both technical and non-technical stakeholders. Exposure to compliance automation or evidence collection tooling (GRC platforms scripting API integrations) is a plus but not essential curiosity and a willingness to grow technically matter more. Curious about how modern SaaS engineering works comfortable asking questions and learning the technical context behind a control. Demonstrates curiosity about AI tools and emerging technologies with a willingness to learn and leverage them to enhance productivity collaboration or decision-making.
At Asana we’re committed to building teams that include a variety of backgrounds perspectives and skills as this is critical to helping us achieve our mission. If you’re interested in this role and don’t meet every listed requirement we still encourage you to apply.
What We’ll Offer
Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases we’re committed to looking at market value which is why we check ourselves and conduct a yearly pay equity audit.
For this role the estimated base salary range is between $158,000–$180,000. The actual base salary will vary based on various factors including market and individual qualifications objectively assessed during the interview process. In addition to base salary your compensation package may include equity and benefits. Speak with your Talent Acquisition Partner to learn more.
We strive to provide equitable and competitive benefits packages that support our employees worldwide and include
Mental health wellness fitness benefits Career coaching support Inclusive family building benefits Long-term savings or retirement plans In-office culinary options to cater to your dietary preferences
These are just some of the benefits we offer and benefits may vary based on role country and local regulations.
em # -Hybrid
About us
1 Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals faster. Asana has been named to Fortune s Best Workplaces for 7+ years and recognized by Fast Company Forbes and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.
TypographyPresentation_31345133_root--medium RichText3-paragraph--withVSpacingNormal RichText3-paragraph HighlightSol_1625403506_highlightSol HighlightSol_1625403506_buildingBlock left We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race color religion age sex national origin disability status genetics protected veteran status sexual orientation gender identity or expression or any other characteristic protected by law.
1 strong a LinkPrimaryPresentation LinkPrimaryPresentation--sentimentSelected PrimaryLink HighlightSol HighlightSol--core HighlightSol--buildingBlock Join Asana’s Talent Network;to stay up to date on job opportunities and life at Asana.
Location and market context
This job is based in San Francisco on-site. Local candidates benefit from being close to Asana's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About compliance jobs
Compliance programs turn law, regulation, and policy into controls the business can actually run. Demand is strongest where regulatory change, enforcement risk, and new technology intersect. Jobs like this one are typically evaluated against frameworks such as relevant regulatory frameworks, control libraries, and audit and monitoring practices.
How to position yourself for this compliance job
Strong candidates emphasize building and monitoring controls, regulatory mapping, policy and training, and partnering with the business to make compliance practical. In your resume and outreach, tie your experience to how Asana would apply relevant regulatory frameworks, control libraries, and audit and monitoring practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Legal Program Manager (Regulatory Compliance) · Openai · San Francisco
- Senior Associate, Compliance Advisory · Chime · San Francisco, CA
- Asset Compliance Program Lead, Hardware · Openai · San Francisco
- Senior Compliance Risk Manager - Securities Compliance · Mercury · San Francisco, CA, New York · Remote
- Governance, Risk, and Compliance Manager - FedRAMP · Decagon · San Francisco
- Sanctions Compliance Lead · Anthropic · San Francisco, CA, NY Washington
- Program Manager, Compliance · Scaleai · San Francisco, CA
- Federal Compliance Manager · Figma · San Francisco, CA, NY •
More jobs at Asana
- Security Risk Engineer · Asana · San Francisco
- Senior Privacy Engineer · Asana · Remote
More GRC jobs in San Francisco
- Senior Risk Analyst · AlphaSense · India · Remote
- Senior Compliance Specialist · Singlestore · India
- Governance, Risk, and Compliance Expert, GTM, Pre-Sales · Vanta · . · Remote
- Senior Risk & Governance Engineer · AlphaSense · India
- Compliance Engineering Lead · Socket · United States
- Third-Party Risk Management Analyst · Samsara · Remote
Hiring for Compliance?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Security Compliance Lead in San Francisco open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.