FedRAMP & GRC Security Lead

Asana

San Francisco, Northern (CA, KY)

Hybrid

USD 158,000 - 180,000

Full time

8 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Mental health, wellness & fitness
Career coaching & support
Inclusive family building benefits
Long-term savings or retirement plans
In-office culinary options

Job summary

Asana is seeking a Security Risk and Compliance Lead to mature and operate FedRAMP, SOC 2, and ISO 27001 programs. The role sits at the intersection of GRC and compliance engineering, owning FedRAMP day-to-day while supporting audit cycles and control frameworks across standards.

The position is based in San Francisco with a hybrid schedule (office Mon/Tue/Thu; optional WFH Wed; Fri depending on work). You will partner with Security, Legal, Privacy, and R&D to ensure obligations are met and

Qualifications

  • 5+ years in Governance, Risk, and Compliance (GRC).
  • Hands-on FedRAMP experience (ConMon, evidence collection, or Moderate/High boundary).
  • Knowledge of SOC 2, ISO 27001, or NIST CSF helpful, but FedRAMP depth matters most.
  • Organised and deadline-driven with multiple workstreams.
  • Able to explain compliance to technical and non-technical stakeholders.
  • Experience with compliance automation or evidence collection tooling is a plus.
  • Curiosity about modern SaaS engineering and AI tools.

Responsibilities

  • Own FedRAMP Continuous Monitoring package submissions and timeliness.
  • Drive completion of FedRAMP requirements with cross-functional teams.
  • Maintain calendars of FedRAMP deliverables and flag risks.
  • Act as internal SME for FedRAMP and guidance for teams.
  • Support evidence collection workflows and remediation activities.
  • Assist in broader controls maturity efforts across SOC 2, ISO 27001.

Skills

GRC
FedRAMP
Certification
Audits
Cross-team collaboration
Communication
Automation mindset
SaaS security

Tools

GRC platforms
Scripting
APIs

Job description

Asana is seeking a Security Risk and Compliance Lead to mature and operate FedRAMP, SOC 2, and ISO 27001 programs. The role sits at the intersection of GRC and compliance engineering, owning FedRAMP day-to-day while supporting audit cycles and control frameworks across standards.

The position is based in San Francisco with a hybrid schedule (office Mon/Tue/Thu; optional WFH Wed; Fri depending on work). You will partner with Security, Legal, Privacy, and R&D to ensure obligations are met and

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

FedRAMP Compliance Lead: Drive GRC & Certifications
FedRAMP Compliance Lead: Drive GRC & Certifications

Decisive Point • San Francisco (CA)

Hybrid
USD 158,000 - 180,000
Mental health benefits
Career coaching & support
Inclusive family building benefits
+2
FedRAMP Compliance Lead — GRC & Audit Expert
FedRAMP Compliance Lead — GRC & Audit Expert

Asana • San Francisco (CA)

On-site
USD 150,000 - 210,000
Security Compliance Lead
Security Compliance Lead

Asana • San Francisco (CA)

On-site
USD 150,000 - 210,000
Senior GRC Director: FedRAMP, ISO 27001 & SOC 2 Lead
Senior GRC Director: FedRAMP, ISO 27001 & SOC 2 Lead

Anomali • Redwood City (CA)

Hybrid
USD 180,000 - 230,000
Senior Security Risk Engineer — Data-Driven Risk
Senior Security Risk Engineer — Data-Driven Risk

Asana • San Francisco (CA), Northern (KY)

Hybrid
USD 202,000 - 230,000
Mental health
Wellness & fitness benefits
Career coaching & support
+3
Senior Security Program Lead
Senior Security Program Lead

Decisive Point • San Francisco (CA)

Hybrid
USD 194,000 - 220,000
Mental health, wellness & fitness
Career coaching & support
Inclusive family building benefits
+2
Senior FedRAMP Compliance & Security Lead
Senior FedRAMP Compliance & Security Lead

United States Digital Space LLC • United States

Remote
USD 153,000 - 245,000
Equity
Health, dental, and vision coverage
Retirement benefits
+7
Senior FedRAMP Security Compliance Lead
Senior FedRAMP Security Compliance Lead

United States Digital Space LLC • United States

On-site
USD 110,000 - 160,000
Lead Security Risk Architect (Data-Driven)
Lead Security Risk Architect (Data-Driven)

Asana • San Francisco (CA), Northern (KY)

Hybrid
USD 202,000 - 230,000
Mental health benefits
Career coaching
Family building benefits
+2
Senior Security Risk Engineer: Data-Driven Risk
Senior Security Risk Engineer: Data-Driven Risk

Decisive Point • San Francisco (CA)

Hybrid
USD 202,000 - 230,000
Mental health & fitness benefits
Career coaching & support
Inclusive family building benefits
+2