Security Compliance Lead

Asana

San Francisco (CA)

On-site

USD 150,000 - 210,000

Full time

9 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Asana is seeking a Security Risk and Compliance Lead to mature and operate FedRAMP ConMon and drive certification programs. You will partner with Security Engineering, Legal, Privacy, and R&D to ensure controls are effective and certifications maintained.

The role sits in San Francisco with a hybrid, office-centric schedule; in-office days are Mon, Tue, and Thu, with optional WFH on Wednesdays. Fridays depend on work and teams involved.

Qualifications

  • 5+ years of experience in Governance, Risk, and Compliance (GRC) or related field.
  • Hands-on FedRAMP experience, including Continuous Monitoring (ConMon) and evidence collection.
  • Foundational knowledge of SOC 2, ISO 27001, or NIST CSF is a plus, with depth in FedRAMP prioritized.

Responsibilities

  • Own FedRAMP Continuous Monitoring tasks and monthly ConMon submissions.
  • Coordinate with Engineering, Legal, Privacy, and IT to meet FedRAMP obligations.
  • Support SOC 2, ISO 27001, and other certifications and audit cycles.
  • Automate or streamline evidence collection and maintain auditable artefacts.

Skills

GRC expertise
FedRAMP ConMon
Evidence collection
Audit coordination
Cross-functional communication

Job description

Role Overview

As a Security Risk and Compliance Lead you will play a hands‑on role in maturing and operating Asana's compliance and certification programme-with a primary focus on FedRAMP Continuous Monitoring and authorization activities. This role sits at the intersection of traditional GRC work and compliance engineering: you will own our FedRAMP programme day-to day, while also supporting our broader audit cycles and control frameworks across SOC 2 and ISO 27001.

This is an excellent opportunity for someone with early‑career GRC experience who has a strong grounding in FedRAMP and is excited to grow their technical skills in a high‑growth SaaS environment. You will partner closely with Security Engineering, Legal, Privacy, and R&D to ensure our FedRAMP obligations are met with rigour, our controls are effective, and our certifications are maintained.

This role is based in our San Francisco office with an office‑centric hybrid schedule. The standard in‑office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in‑office requirements.

What You'll Achieve
FedRAMP Continuous Monitoring
  • Own the monthly FedRAMP ConMon package submission, ensuring it is accurate, complete, and delivered on time every month.
  • Track and drive completion of all timebound FedRAMP requirements by working closely with Engineering, People, and other responsible teams.
  • Maintain a clear calendar of FedRAMP deliverables and proactively flag risks to timelines, escalating where needed to ensure nothing slips.
  • Serve as the internal subject matter expert for FedRAMP, acting as the day‑to day point of contact for FedRAMP‑related queries from internal teams and helping them understand their obligations and what good looks like.
  • Proactively engage with a wide range of teams-including Engineering, IT, and People-to work through FedRAMP controls maturity activities, close existing gaps, and drive remediation efforts to completion with clear documentation of progress.
Controls Maturity & Broader Certifications
  • Support the maintenance and continuous improvement of Asana's broader control framework across SOC 2, ISO 27001, and other applicable standards.
  • Support external compliance audits end-to-end: coordinating evidence requests, liaising with auditors, and tracking findings through to closure.
  • Contribute to controls maturity scoring and reporting, providing ongoing visibility into programme health for senior leadership.
  • Build strong working relationships across the business so that control owners feel supported and accountability is shared, not siloed within the compliance team.
Evidence Collection & Automation
  • Own evidence collection workflows within our GRC platform, ensuring controls are reliably mapped, evidence is current, and audit artefacts are ready year‑round‑with particular attention to FedRAMP requirements.
  • Document evidence collection procedures so that processes are transparent, auditable, and maintainable by the broader team.
  • Where possible, identify opportunities to automate repetitive evidence‑gathering tasks‑curiosity and initiative here will be valued, though this is not a core requirement of the role.
About You
  • 5+ years of experience in Governance, Risk, and Compliance (GRC), information security, or a closely related field-internships and co‑ops count.
  • Hands‑on experience with FedRAMP-ideally including ConMon, evidence collection, or working within a FedRAMP Moderate or High boundary. This is the most important qualification for this role.
  • Foundational knowledge of broader security compliance frameworks such as SOC 2, ISO 27001, or NIST CSF is a plus, but depth in FedRAMP matters most.
  • Organised and deadline‑driven: you can manage multiple workstreams, track time‑sensitive obligations (like monthly FedRAMP submissions), and keep audit artefacts tidy without being reminded.
  • Comfortable engaging with a wide variety of teams-Engineering, People, IT, Legal-to explain compliance requirements, gather evidence, and build the relationships needed to close control gaps.
  • A clear communicator who can translate compliance requirements into plain language for both technical and non‑technical stakeholders.
  • Exposure to compliance automation or evidence collection tooling (GRC platforms, scripting, API integrations) is a plus, but not essential-curiosity and a willingness to grow technically matter more.
  • Curious about how modern SaaS engineering works-comfortable asking questions and learning the technical context behind a control.
  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision‑making.

At Asana, we're committed to building teams that include a variety of backgrounds, persp

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Compliance Lead
Security Compliance Lead

Decisive Point • San Francisco (CA)

Hybrid
USD 158,000 - 180,000
Mental health benefits
Career coaching & support
Inclusive family building benefits
+2
Security Compliance Lead San Francisco
Security Compliance Lead San Francisco

Asana • San Francisco (CA), Northern (KY)

Hybrid
USD 158,000 - 180,000
Mental health, wellness & fitness
Career coaching & support
Inclusive family building benefits
+2
FedRAMP Compliance Lead: Drive GRC & Certifications
FedRAMP Compliance Lead: Drive GRC & Certifications

Decisive Point • San Francisco (CA)

Hybrid
USD 158,000 - 180,000
Mental health benefits
Career coaching & support
Inclusive family building benefits
+2
FedRAMP & GRC Security Lead
FedRAMP & GRC Security Lead

Asana • San Francisco (CA), Northern (KY)

Hybrid
USD 158,000 - 180,000
Mental health, wellness & fitness
Career coaching & support
Inclusive family building benefits
+2
Security Risk Engineer
Security Risk Engineer

Asana • San Francisco (CA), Northern (KY)

Hybrid
USD 202,000 - 230,000
Mental health benefits
Career coaching
Family building benefits
+2
FedRAMP Compliance Lead — GRC & Audit Expert
FedRAMP Compliance Lead — GRC & Audit Expert

Asana • San Francisco (CA)

On-site
USD 150,000 - 210,000
Security Risk Engineer San Francisco
Security Risk Engineer San Francisco

Asana • San Francisco (CA), Northern (KY)

Hybrid
USD 202,000 - 230,000
Mental health
Wellness & fitness benefits
Career coaching & support
+3
Security Compliance Analyst
Security Compliance Analyst

Harbinger Motors • Garden Grove (CA)

On-site
USD 110,000 - 160,000
Stock options
Flexible PTO
Health coverage
+2
Security Risk Engineer
Security Risk Engineer

Decisive Point • San Francisco (CA)

Hybrid
USD 202,000 - 230,000
Mental health & fitness benefits
Career coaching & support
Inclusive family building benefits
+2
Senior FedRamp Program Manager
Senior FedRamp Program Manager

Agiloft • United States

Remote
USD 120,000 - 190,000