Jobs Companies Navan Staff Security Analyst

Sobre este puesto de Staff Security Analyst en Navan

Navan · Presencial · Palo Alto, CA

We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won’t just maintain compliance—you’ll scale and automate it to eliminate manual friction. In this role, you’ll manage our Information Security Management System (ISMS), lead internal and external audits, and serve as the primary bridge between external regulators and our internal teams. If you excel at translating deep technical expertise into practical, automated solutions, this is your chance to shape our security ecosystem across the organization.

What You'll Do:

Compliance Program Leadership (Primary Focus)

  • Multi-Framework Compliance Management: Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II)
  • ISMS Operations: Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processes
  • Audit Coordination & Management: Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessments
  • Risk Assessment & Adjustment: Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectives
  • Control Automation & Optimization: Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflows
  • Regulatory Compliance Strategy: Monitor regulatory changes and emerging compliance requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligations

Control Framework & Testing

  • Control Owner Enablement: Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence requirements
  • Control Testing Program: Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologies
  • Gap Assessment & Remediation: Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategies
  • Evidence Management: Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditability

Governance, Policy & Documentation

  • Policy Development & Maintenance: Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory requirements and industry best practices
  • Unified Control Framework (UCF): Develop and maintain control mapping across multiple frameworks to identify overlapping requirements and optimize control implementation
  • Documentation Governance: Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change tracking
  • Compliance Reporting: Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committees

Cross-Functional Collaboration & Stakeholder Management

  • Executive Communication: Articulate complex compliance requirements and risk scenarios to C-level executives, board members, and non-technical stakeholders
  • Cross-Functional Partnership: Collaborate closely with Engineering, IT, Finance, Legal, People Ops, and Business Units to bridge control gaps and implement compliance solutions
  • Training & Awareness: Develop and deliver security compliance training programs for employees, contractors, and control owners; build compliance awareness throughout the organization

What We’re Looking For:

Experience & Background

  • 6-8+ years of progressive experience in security governance, risk and compliance (GRC), information security auditing, or compliance program management
  • Demonstrated experience working directly with Big Four or external auditors through full audit cycles
  • Control automation experience: Proven success implementing automated evidence collection, continuous control monitoring, and compliance workflow automation
  • ISMS management: Hands-on experience running an Information Security Management System (ISO 27001 ISMS or equivalent)

Framework & Regulatory Knowledge

  • Deep expertise in PCI DSS (all 12 requirements, SAQ types, ROC processes, compensating controls)
  • Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls, change management, backup/recovery, segregation of duties)
  • Proficiency with ISO 27001:2022 and ISO 42001:2023 (AI Management System) frameworks
  • Hands-on experience with SOC 1 (SSAE 18/ISAE 3402) and SOC 2 (Trust Services Criteria) audit requirements
  • Working knowledge of security frameworks including NIST CSF, NIST SP 800-53, CIS Controls, or COBIT

Technical & Cloud Security

  • Cloud security controls: Deep understanding of cloud security architecture, identity and access management (IAM), network security, data protection, and logging/monitoring within AWS (Azure or GCP experience is a strong plus)
  • Control implementation: Practical knowledge of technical control implementation including encryption, secure configuration management, vulnerability management, and incident response
  • Security architecture: Ability to review and assess security architectures, data flows, and system designs from a compliance perspective

Tools & Technology

  • GRC platforms: Hands-on experience with compliance automation platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, or similar)
  • Evidence collection automation: Experience implementing automated evidence collection using APIs, scripts, or integration platforms
  • Audit & assessment tools: Proficiency with vulnerability scanners, SIEM platforms, configuration management tools, and compliance scanning solutions

Education & Certifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field
  • Certifications (one or more):
    • CISA (Certified Information Systems Auditor)
    • CISM (Certified Information Security Manager)
    • CISSP (Certified Information Systems Security Professional)
    • ISO 27001 Lead Auditor or ISO 27001 Lead Implementer
    • CCSP (Certified Cloud Security Professional) or CCSK (Certificate of Cloud Security Knowledge)
    • PCI ISA (Internal Security Assessor) or PCI QSA (Qualified Security Assessor)

Specialized Experience

  • Regulated markets: Prior experience with FedRAMP (Low/Moderate/High), GovRAMP, CMMC (Level 1-3), StateRAMP, or TX-RAMP authorization processes
  • Government & defense: Experience with NIST SP 800-171, DFARS compliance, or DoD authorization frameworks
  • Unified Control Framework (UCF): Demonstrated success building and maintaining unified or common control frameworks that map requirements across multiple standards
  • Consulting background: Previous experience with Big Four consulting firms (Deloitte, PwC, EY, KPMG) or specialized security/compliance consulting practices

The posted pay range represents the anticipated low and high end of the compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity.

For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive compensation. Target incentive compensation for some roles may include a ramping draw period. Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter.

Pay Range
$131,025$291,300 USD
¿Listo para postularte en Navan?
Postúlate en Navan

Cómo se compara este salario de Cybersecurity

Este puesto paga $211,163/yrpor encima de el rango típico para los puestos de Cybersecurity.

$86,760 la mediana de $136,500 $219,432

Rango típico $114,500–$170,000/yr, a partir de 121 ofertas comparables de Cybersecurity en JobsRadar (salario anualizado en USD). Ver datos salariales de Cybersecurity →

Sobre Navan

ABOUT TRIPACTIONS

TripActions is the fastest-growing corporate travel platform disrupting a $1.5T industry and shaping the future of business travel.

TripActions is a story of inspiration born of frustration. Road warriors and co-founders Ariel Cohen and Ilan Twig believed that companies deserved a travel solution that takes the pain out of work trips –– so that their travelers can focus on being productive and meeting in-person, not wasting valuable time booking travel. So in 2015, they created TripActions. Since then, we’ve been a mission to power the face-to-face, in-person connections that move people, ideas and businesses forward.

TripActions’ platform offers a vast selection of inventory that travelers can choose from, a personalized, intuitive user interface driven by machine learning, and 24/7 proactive real human, customer support. Companies enjoy complete travel program visibility, over 30% cost savings on average and seamless integrations with their HR and expense systems.

Globally, TripActions has grown to over 600 employees across 7 offices in 4 countries. We support over 1,500 customers, with innovative brands like Lyft, Dropbox, Sara Lee Frozen Bakery, Allbirds, Robinhood and the ACLU relying on TripActions for their business travel needs. As one of Silicon Valley’s newest “unicorns”, TripActions has a valuation north of $1B and a total of $232M in funding. We’ve recently received $154M in our Series C funding round –– led by new investor Andreessen Horowitz, with participation from repeat investors Lightspeed Venture Partners, Zeev Ventures and SGVC.

TripActions was recently recognized as one of Fast Company’s Most Innovative Companies for 2019, #12 in LinkedIn’s Top Startups 2018 and #3 in the U.S. for Happiest Employees by Comparably.

We’re redefining what it means to travel for work. Come help us build the future of business travel.

Ver todos los empleos en Navan →

Empleos similares

Assurity Trusted Solutions
Cybersecurity Engineer (Solutioning and Architecture) - Multiple Headcounts
Assurity Trusted Solutions
⚡ Postúlate pronto Singapore, Singapore, Singapor... Presencial
● Nuevo 👁 Visto ✓ Postulado hace 53m
EE
Senior Security & Compliance Analyst
Energy Exemplar
⚡ Postúlate pronto Pune, Maharashtra, India Presencial
● Nuevo 👁 Visto ✓ Postulado hace 3h
Enshored Inc. (External)
Security and Compliance Junior Analyst
Enshored Inc. (External)
⚡ Postúlate pronto Pasig, Pasig, Philippines Presencial
● Nuevo 👁 Visto ✓ Postulado hace 4h
Roblox
Senior Security GRC Analyst
Roblox
⚡ Postúlate pronto San Mateo, CA, United States Presencial $209,250–$271,710
● Nuevo 👁 Visto ✓ Postulado hace 5h
Discord
Security Analyst
Discord
⚡ Postúlate pronto San Francisco Bay Area Presencial
● Nuevo 👁 Visto ✓ Postulado hace 9h
AlertMedia
IT Security Operations Analyst
AlertMedia
⚡ Postúlate pronto Austin, TX HQ Presencial
● Nuevo 👁 Visto ✓ Postulado hace 13h
CA
Business Analyst - Dallas - Cyber Security - CyberArk/Privileged Access Management
Capco
⚡ Postúlate pronto US - Dallas Presencial
● Nuevo 👁 Visto ✓ Postulado hace 14h
Parachute Health
Lead Security & Compliance Analyst
Parachute Health
⚡ Postúlate pronto U.S. Remote · restringido por ubicación $80,000–$130,000
● Nuevo 👁 Visto ✓ Postulado hace 15h
Capgemini
FBS Information Security Analyst (RACF)
Capgemini
⚡ Postúlate pronto Brazil Remoto
● Nuevo 👁 Visto ✓ Postulado hace 15h

Regístrate para recibir sugerencias adaptadas a los empleos que abres y las búsquedas que guardas.

Más empleos en Navan

Ver todos los empleos en Navan →

Postúlate ahora
🤖

Un momento — para

JobsRadar se creó para personas reales que están pasando un mal momento en su búsqueda de empleo — no para solicitudes automatizadas. Estás haciendo clic demasiado rápido y ahora estás bloqueado temporalmente.

Vuelve más tarde. Si de verdad estás buscando empleo, cuentas con nosotros — solo compórtate como una persona.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Toma ventaja en tu búsqueda de empleo.

Únete a nuestro canal de Telegram para lo que te ayuda a conseguir el puesto — referencias salariales, el pulso semanal del mercado y avisos de nuevas funciones. Sin spam, solo señal.

Únete al canal — es gratis