Security Risk and Compliance Analyst

6 days ago


San Francisco, California, United States Asana Full time

At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance with legal and regulatory requirements, and fostering a culture of security throughout our product and operations. We are a team of security engineers and risk and compliance practitioners who build innovative safeguards and collaborate across the organization to build and maintain trust at scale.

As a Security Risk and Compliance Analyst at Asana, you'll play a critical and high-impact role in building and maintaining trust with Asana's global customers. You will be responsible for initiatives that continuously improve our vendor risk assessment and security risk management programs, ensuring we maintain a strong security posture and meet both compliance requirements and customer expectations.

This is a highly cross-functional role where you'll partner closely with Legal, Privacy, Finance, R&D, and other key stakeholders. You'll help evolve our programs with a strategic, risk-based mindset—balancing operational excellence with agility as we grow and scale.

This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.

What you'll achieve:

  • Vendor Risk Management: Own and operate Asana's vendor risk management program, including performing due diligence for new vendors, managing ongoing monitoring and reporting, and reviewing vendor contracts for security and compliance requirements.
  • Security Risk Management: Support the execution of periodic assessments across the organization to identify, evaluate, and track risks—driving mitigation and treatment efforts with business and technical owners.
  • Risk Register Maintenance: Assist in maintaining the central security risk register to promote and drive accountability across the organization.
  • FedRAMP Compliance: Support FedRAMP continuous monitoring activities to ensure ongoing compliance with FedRAMP moderate requirements.
  • Compliance Audit Support: Partner with internal teams to support external compliance audits such as FedRAMP, SOC 2, and ISO 27001, providing evidence and program documentation as needed.
  • Policy Management: Help to draft, update, and maintain security policies, standards, and procedures that align with evolving business needs and industry best practices.

About you:

  • 3+ years of experience in Governance Risk and Compliance, with a focus on risk assessments and security risk management.
  • Demonstrated understanding of security compliance frameworks and audits (e.g., SOC 2, ISO 27001, PCI DSS, NIST, HIPAA, FedRAMP, etc.).
  • Experience with enterprise SaaS applications, cloud infrastructure, modern software engineering practices and tools, databases, operating systems, secure network design, and public cloud models such as AWS
  • Experience performing third-party vendor security reviews and due diligence processes
  • Proven ability to drive operational process improvements and develop metrics for tracking success.
  • Excellent communicator and influencer, with the ability to translate complex security and compliance requirements to both technical and non-technical stakeholders.
  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.

At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.

What we'll offer

Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we're committed to looking at market value which is why we check ourselves and conduct a yearly pay equity audit.

For this role, the estimated base salary range is between $130,000-$160,000. The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. The listed range above is a guideline, and the base salary range for this role may be modified.

In addition to base salary, your compensation package may include additional components such as equity, sales incentive pay (for most sales roles), and benefits. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.

We strive to provide equitable and competitive benefits packages that support our employees worldwide and include:

  • Mental health, wellness & fitness benefits
  • Career coaching & support
  • Inclusive family building benefits
  • Long-term savings or retirement plans
  • In-office culinary options to cater to your dietary preferences

These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.

LI-Hybrid

About us

Asana helps teams orchestrate their work, from small projects to strategic initiatives. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named a Top 10 Best Workplace for 5 years in a row, is Fortune's #1 Best Workplace in the Bay Area, and one of Glassdoor's and Inc.'s Best Places to Work. After spending more than a year physically distanced, Team Asana is safely and mindfully returning to in-person collaboration, incorporating flexibility that adds hybrid elements to ouroffice-centric culture. With 11+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world.

We believe in supporting people to do their best work and thrive. Our goal is to ensure that Asana upholds an environment where all people feel that they are respected and valued, whether they are applying for an open position or working at the company. We provide equal employment opportunities to all applicants without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by law. We also comply with the San Francisco Fair Chance Ordinance and similar laws in other locations.

Join Asana's Talent Network to stay up to date on job openings.



  • San Francisco, California, United States Primary Talent Partners Full time

    Primary Talent Partners has a new contract opening for an Information Security Risk Analyst with our enterprise client inSan Francisco, CA or Los Angeles, CA OR Salt Lake City, UT. This is a 12-month contract with a potential for extension or perm conversion. Pay:$ $75.00/hr; W2 contract, no PTO, no Benefits. ACA-compliant supplemental package available...


  • San Francisco, California, United States Zip Full time $120,000 - $180,000 per year

    The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally (>30 times larger than annual consumer e-commerce spend) and rely on vendors more than ever before to run their businesses.Our cofounders started Zip in 2020 to...


  • San Francisco, California, United States City and County of San Francisco Full time $138,684 - $174,434 per year

    Company DescriptionSpecific information regarding this recruitment process is listed below:Application Opening - Wednesday, October 15, 2025.Application Deadline - Interested candidates are encouraged to apply as soon as possible, as this job announcement will close at any time, but not earlier than 11:59PM PST, Wednesday, October 29, 2025.About Department...


  • San Francisco, California, United States Stefanini Group Full time

    Job DescriptionStefanini Group is hiringStefanini is looking for anInformation Security Risk Analyst forSan Francisco, CA/Salt Lake City, UT/Los Angeles, CA (Onsite Role).**For quick Apply, please reach out to Akash Gupta: / W2 candidates onlyResponsibilitiesThe ideal candidate for this role will have the ability to blend and apply their technical,...

  • IT Security Analyst

    6 days ago


    San Diego, California, United States TALENT Software Services Full time

    IT Security Analyst 4Job Summary: Talent Software Services is in search of an IT Security Analyst for a contract position in San Diego, CA. The opportunity will be for six months with a strong chance for a long-term extension.Position Summary:Working with the Senior Manager of Security Risk and Compliance, as a Security Risk Analyst, you are a member of a...


  • San Francisco, California, United States Decagon Full time

    About DecagonDecagon is the leading conversational AI platform empowering every brand to deliver concierge customer experience. Our AI agents provide intelligent, human-like responses across chat, email, and voice, resolving millions of customer inquiries across every language and at any time.Since coming out of stealth, Decagon has experienced rapid growth....


  • San Francisco, California, United States DocuSign Full time $286,500 per year

    Company OverviewDocusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now,...


  • San Bernardino, California, United States SAC Health Full time

    Who We Are:SAC Health empowers our patients and their families to live vibrant and healthy lives through culturally responsive, exceptional care. Patient-centered, whole-person care. Our unique, full scope, team-based approach is what makes SAC Health the provider of choice for patients. Top-Tier Patient Satisfaction Scores | Largest Teaching Health Center...

  • Security Analyst

    7 days ago


    San Francisco, California, United States Minted Full time $72,391 - $95,013

    The Role:As a Security Analyst II/III at Minted, you'll play a key role in protecting the systems and data that power our global artist community and e-commerce customers.You'll monitor our environment, respond to security incidents, analyze vulnerabilities, and support ongoing improvements to our cloud and enterprise security posture. This role blends...

  • Security Analyst

    2 weeks ago


    San Francisco, California, United States Minted Full time $72,391 - $95,013 per year

    *The Role:*As a Security Analyst II/III at Minted, you'll play a key role in protecting the systems and data that power our global artist community and e-commerce customers.You'll monitor our environment, respond to security incidents, analyze vulnerabilities, and support ongoing improvements to our cloud and enterprise security posture. This role blends...