Security Compliance Analyst

Harbinger Motors

Garden Grove (CA)

On-site

USD 110,000 - 160,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Stock options
Flexible PTO
Health coverage
Vacation stipend
Paid meals and sundries

Job summary

Harbinger Motors is seeking a Security Compliance Analyst to build and own our security compliance program end to end. This hands-on, builder role requires taking a framework from gap assessment through external audit and applying it across our growing operations.

You will own the control catalog, the evidence behind it, the policies that describe it, and the tooling that holds it together, while expanding scope with new business opportunities and cross‑functional teams.

Qualifications

  • 5+ years in security compliance, GRC, or IT audit with at least one framework taken from gap assessment through external audit or certification.
  • Experience in startup or high-growth environment building a program rather than maintaining one.
  • Familiarity with NIST-based control catalogs and cross-framework mapping.
  • Hands-on ownership of SOC 2 Type II and ISO/IEC 27001 and translating controls across frameworks.

Responsibilities

  • Own and manage the security compliance program end to end, including control catalog, evidence, policies, and tooling.
  • Synchronize control requirements with engineering teams and verify implementations.
  • Maintain the corrective action plan with owners, dates, and evidence readiness for audits.
  • Support external audits and certification assessments, including readiness reviews and auditor walkthroughs.
  • Define system boundaries and scope decisions to withstand assessor questions.
  • Administer GRC tooling and ensure evidence freshness in the platform.

Skills

Startup experience
Security compliance
Audit readiness
Documentation
Written & verbal communication

Education

Bachelor's degree in Cybersecurity or related field

Tools

Jira
Confluence
Vanta

Job description

  • Harbinger is hiring a Security Compliance Analyst to build and own our security compliance program end to end. This is a hands‑on, builder role: we’re looking for someone who has already taken a compliance framework from gap assessment through an external audit and wants to do it again somewhere the program doesn’t exist yet
  • You’ll own the control set, the evidence behind it, the policies that describe it, and the tooling that holds it together. You’ll grow into our expanding compliance scope as that work emerges with new business opportunities
  • Compliance Frameworks & Controls
  • Own the control catalog: implementation status, testing, evidence requirements, and crosswalks where frameworks overlap
  • Translate control requirements into specific, actionable changes for teams to implement, then verify they landed
  • Maintain the corrective action plan; open findings with named owners, real dates, and a defined evidence bar for closure partnering with program management on execution
  • Audit & Evidence Management
  • Run evidence collection on a standing cadence, building automations so evidence becomes a byproduct of normal operations rather than a quarterly scramble
  • Prepare for and support external audits and certification assessments: readiness reviews, sample pulls, auditor walkthroughs, and remediation of findings
  • Define and document our system boundary and scope decisions: what’s in, what’s deliberately out, and reasoning that holds up under an assessor’s questions
  • Policy, Governance & Tooling
  • Write and maintain the policy and procedure set. Short enough that engineers read it, specific enough that an auditor accepts it
  • Administer our GRC platform Vanta, including control mappings, integrations, framework crosswalks, and evidence freshness
  • Support role‑based security awareness training and data handling guidance
  • Third‑Party Risk & Cross‑Functional
  • Run vendor and third‑party security reviews, including cloud services and the security requirements we flow down to suppliers
  • Document control decisions, scope rationale, and audit outcomes in Jira or Confluence so the program is maintainable by others
  • Report compliance posture and audit readiness to security leadership on a regular cadence
Benefits
  • Accelerate Your Wealth: As one of our first 100 employees, you’ll have the opportunity to rev up your financial future with early‑stage stock options
  • Unleash Your Time: Take control of your work‑life balance. Salaried teammates receive flexible PTO and the freedom to celebrate holidays and wellness days as you see fit
  • 100% Comprehensive Health Coverage: You and your loved ones are covered with top‑tier medical, dental, and vision insurance
  • Cruise into Vacations: Enjoy an exciting annual vacation stipend to help you recharge your batteries
  • Fuel Your Day: Forget brown bag lunches; we’ve got you covered with paid lunches and dinners to keep you energized
  • Experience in a startup or high‑growth environment building a program rather than maintained one
  • Security certifications (e.g. CISA, CRISC, CompTIA Security+, ISO 27001 Lead Auditor) are a plus
  • Bachelor’s degree in Information Systems, Cybersecurity, or related field (or equivalent experience)
  • 5+ years in security compliance, GRC, or IT audit, including at least one framework taken from gap assessment through an external audit report or certification
  • Scripting ability (e.g. Python or JavaScript) is a plus
  • Working in collaboration platforms like Confluence or Jira
  • GRC platform administration in Vanta configuring mappings and integrations
  • Familiarity with NIST‑based control catalogs, mapping between overlapping frameworks, and the handling and storage controls that attach to restricted or contractually protected data
  • Hands‑on ownership of SOC 2 Type II and/or ISO/IEC 27001. Able to translate controls to other frameworks and compliance needs across all business units
  • Experience with a certification audit where the outcome is pass or fail against a fixed control catalog, not an opinion accompanied by a management response
  • Experience defining a system boundary and defending the scoping decision to an external assessor
  • Evidence and audit management: you can describe an evidence chain end to end: what artifact, generated how, refreshed how often, who attests
  • Strong written and verbal communication; able to translate control requirements into concrete changes an engineer can act on
  • Comfortable working cross‑functionally in a fast‑paced, high‑growth manufacturing environment
  • Documentation discipline: if it isn’t written down, it didn’t happen
  • Comfortable influencing teams that don’t report to you, and staying with a position when the answer needs to be no
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

Fireworks AI • San Mateo (CA)

On-site
USD 110,000 - 170,000
Senior Security Assurance Engineer
Senior Security Assurance Engineer

6sense • New York (NY)

On-site
USD 150,000 - 190,000
Health & Wellness
HUB Working Model
WeWork Access
+3
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000
GRC Compliance Auditor
GRC Compliance Auditor

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 90,000 - 140,000
Staff Security Analyst
Staff Security Analyst

Navan • Palo Alto (CA)

On-site
USD 131,000 - 291,000
Security Compliance Engineer
Security Compliance Engineer

ANAUTICS INC • Oklahoma City (OK)

On-site
USD 80,000 - 100,000
Compliance Manager
Compliance Manager

Anyscale • San Francisco (CA)

On-site
USD 180,000 - 240,000
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Information Security and Compliance Manager
Information Security and Compliance Manager

Transhield, Inc. • Elkhart (IN)

On-site
USD 120,000 - 180,000
GRC Compliance Auditor
GRC Compliance Auditor

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000