ABOUT TRIPACTIONS
TripActions is the fastest-growing corporate travel platform disrupting a $1.5T industry and shaping the future of business travel.
TripActions is a story of inspiration born of frustration. Road warriors and co-founders Ariel Cohen and Ilan Twig believed that companies deserved a travel solution that takes the pain out of work trips –– so that their travelers can focus on being productive and meeting in-person, not wasting valuable time booking travel. So in 2015, they created TripActions. Since then, we’ve been a mission to power the face-to-face, in-person connections that move people, ideas and businesses forward.
TripActions’ platform offers a vast selection of inventory that travelers can choose from, a personalized, intuitive user interface driven by machine learning, and 24/7 proactive real human, customer support. Companies enjoy complete travel program visibility, over 30% cost savings on average and seamless integrations with their HR and expense systems.
Globally, TripActions has grown to over 600 employees across 7 offices in 4 countries. We support over 1,500 customers, with innovative brands like Lyft, Dropbox, Sara Lee Frozen Bakery, Allbirds, Robinhood and the ACLU relying on TripActions for their business travel needs. As one of Silicon Valley’s newest “unicorns”, TripActions has a valuation north of $1B and a total of $232M in funding. We’ve recently received $154M in our Series C funding round –– led by new investor Andreessen Horowitz, with participation from repeat investors Lightspeed Venture Partners, Zeev Ventures and SGVC.
TripActions was recently recognized as one of Fast Company’s Most Innovative Companies for 2019, #12 in LinkedIn’s Top Startups 2018 and #3 in the U.S. for Happiest Employees by Comparably.
We’re redefining what it means to travel for work. Come help us build the future of business travel.
Pick a job to read the details
Tap any role on the left — its description and apply link will open here.
Navan is looking for a Security Governance & Awareness Analyst to join our team and execute the day-to-day operations of our security awareness programs and policy management lifecycle. You will own the operational delivery of phishing simulations, targeted training campaigns, and policy review cycles—focusing on defending against modern threats like AI-generated social engineering while maintaining our regulatory and compliance posture.
Sitting at the intersection of Security Culture and Compliance, you will be responsible for operational execution while collaborating closely with your manager on program strategy. This is a role for someone with strong program management skills, excellent communication abilities, and an eye for detail—with increasing emphasis on leveraging AI tools to amplify impact and efficiency.
Security Awareness Operations: Lead the day-to-day execution of phishing simulations and mandatory training, focusing on modern threats like AI-generated social engineering, deepfake audio/video, and sophisticated LLM-based phishing.
Targeted Training Programs: Develop and deliver specialized training for high-risk employee groups (e.g., Helpdesk, Sales, Call Centers) to defend against account takeover, identity verification bypass, and customer data targeting.
Policy Lifecycle Management: Own the operational cycle for all security policies, standards, and procedures—ensuring documents are reviewed, updated, and published on schedule with proper version control and stakeholder feedback.
Compliance Documentation: Maintain the centralized policy repository and ensure policies align with SOC 2, ISO 27001, PCI-DSS, and evolving AI governance standards for audit readiness.
Security Communications: Design and distribute internal security alerts, manage the security and compliance newsletter, and create engaging content about emerging threats for diverse stakeholders.
Metrics & Reporting: Compile and analyze data on simulation success rates, training completion, and policy compliance for executive-level reporting and program optimization.
Cross-Functional Collaboration: Partner with Legal, HR, and Engineering to collect policy feedback and coordinate awareness initiatives across the organization.
Experience: 2–4 years in Security Awareness, Corporate Training, or GRC, with a track record of executing awareness programs and managing policy lifecycles.
Communication Excellence: Strong written and verbal skills to create clear policies, design engaging training content, and effectively communicate with stakeholders at all levels.
Modern Threat Knowledge: Strong understanding of contemporary social engineering tactics, including deepfakes, AI-driven phishing, vishing, and identity verification attacks.
Platform Experience: Hands-on experience with Security Awareness platforms (e.g., Adaptive, KnowBe4, Proofpoint) and Policy Management software for training delivery and document control.
Program Management: Proven ability to manage multiple concurrent initiatives in a fast-paced environment, from phishing campaigns to policy review cycles, with high attention to detail.
AI Tool Awareness: Growing familiarity with AI tools (Claude, Gemini, etc.) to assist with content creation, communications drafting, and operational efficiency.
Regulatory Frameworks: Working knowledge of SOC 2, ISO 27001, PCI-DSS, and NIST CSF requirements as they relate to security awareness and policy documentation.
Preferred: Relevant industry certifications (e.g., CompTIA Security+, SANS SSAP) demonstrating commitment to the security awareness field.
Ready to apply?
Apply to Navan
Navan is looking for a Security Governance & Risk Engineer to join our team as we evolve from manual processes to automated, scalable security systems. You will own the operational execution of our governance automation infrastructure, compliance monitoring, and security program platforms—using AI and automation as your primary force multipliers.
Sitting at the intersection of Security Engineering, Compliance, and Security Culture, you will execute day-to-day operations while collaborating closely with your manager on technical strategy. This is a unique hybrid role for someone who possesses both technical engineering capabilities and strong program management skills, with a heavy emphasis on leveraging AI tools (like Claude, Gemini, and GitHub Copilot) to amplify impact.
Ready to apply?
Apply to Navan
The Senior Product Security Engineer will be responsible for securing Navan products, by identifying risks early in the SDLC and developing application security tooling & processes to promote a ‘shift left’ security culture. You will be responsible for developing and scaling the product security function by integrating security in the application development process, conducting security-related research and assessments, developing custom automated security and anti-fraud solutions, and providing security analysis/design/training to the organization.
Reporting to the senior Director of Product Security and Trust, you will contribute significantly to building and scaling an application security program. This position requires both advanced technical skills, strong communication skills, and the ability to influence people. You will be responsible for ensuring the continuous security of Navan customer-facing products and internal tools. You will focus on proactively discovering security vulnerabilities, driving and advising risk remediation based on research, and developing strong partnerships with engineering and product teams to accelerate the release of the software with security by design.
What You’ll Do:
What We’re Looking For:
Good to have:
Ready to apply?
Apply to Navan
The Senior Product Security Engineer will be responsible for securing Navan products, by identifying risks early in the SDLC and developing application security tooling & processes to promote a ‘shift left’ security culture. You will be responsible for developing and scaling the product security function by integrating security in the application development process, conducting security-related research and assessments, developing custom automated security and anti-fraud solutions, and providing security analysis/design/training to the organization.
Reporting to the senior Director of Product Security and Trust, you will contribute significantly to building and scaling an application security program. This position requires both advanced technical skills, strong communication skills, and the ability to influence people. You will be responsible for ensuring the continuous security of Navan customer-facing products and internal tools. You will focus on proactively discovering security vulnerabilities, driving and advising risk remediation based on research, and developing strong partnerships with engineering and product teams to accelerate the release of the software with security by design.
What You’ll Do:
What We’re Looking For:
Good to have:
Ready to apply?
Apply to Navan
Share this job
The Senior Product Security Engineer will be responsible for securing Navan products, by identifying risks early in the SDLC and developing application security tooling & processes to promote a ‘shift left’ security culture. You will be responsible for developing and scaling the product security function by integrating security in the application development process, conducting security-related research and assessments, developing custom automated security and anti-fraud solutions, and providing security analysis/design/training to the organization.
Reporting to the senior Director of Product Security and Trust, you will contribute significantly to building and scaling an application security program. This position requires both advanced technical skills, strong communication skills, and the ability to influence people. You will be responsible for ensuring the continuous security of Navan customer-facing products and internal tools. You will focus on proactively discovering security vulnerabilities, driving and advising risk remediation based on research, and developing strong partnerships with engineering and product teams to accelerate the release of the software with security by design.
What You’ll Do:
What We’re Looking For:
Good to have:
The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.
For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.
Ready to apply?
Apply to Navan
At Navan, you will build and evolve Detection & Response (D&R) capabilities across our infrastructure, products, and research environments. This role focuses on high-signal detection and reliable operational response to ensure the security of our global travel and expense platform.
What You’ll Do:
What We’re Looking For:
Ready to apply?
Apply to Navan
Cookies & analytics
This site uses cookies from third-party services to deliver its features and to analyze traffic.