Senior Security Assurance Analyst

Rippling

San Francisco (CA)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Equity
Competitive compensation
Collaborative culture

Job summary

You will own coordination of evidence collection, liaising with auditors, and maturing governance across engineering, privacy/legal, product, and security teams. A strong communicator who thrives autonomously will excel in this role.

Qualifications

  • 5+ years of experience in security/compliance roles.
  • In-depth familiarity with ISO 27001 and SOC 2.
  • Proficiency in cloud security best practices.
  • Experience developing, reviewing, and maintaining information security policies.
  • Good understanding of privacy regulations and data handling obligations.

Responsibilities

  • Support delivery of security assurance program across ISO 27001, SOC 2, ISO/IEC 42001, ISO/IEC 27018 and CSA STAR.
  • Perform security due diligence on vendors and third parties, evaluating data processing, storage, controls, and external certifications.
  • Support evolution of ISMS by enhancing security policies, maturing policy lifecycle, and governance processes.
  • Assist internal teams and external stakeholders with audit evidence, due diligence, policy guidance, and governance activities.

Skills

ISO 27001
SOC 2
Cloud security
Policy development
Privacy regs

Job description

About the Role

Join Rippling’s Security Assurance team and help demonstrate the trust our customers place in us every day. You’ll play a key role in delivering internationally recognized security certifications and attestations, supporting regulatory obligations, and partnering across the business to strengthen our security assurance program.

At Ripping, we are on an exciting growth journey, and our Security team is at the forefront of this transformation. We are committed to our mission of protecting our company’s assets and data, and we need individuals who share this passion.

About the Team

The Security Assurance team is responsible for delivering Rippling’s security assurance programmes and supporting compliance with technology and security regulatory requirements. Through internationally recognised certifications, attestations, and effective governance, the team helps maintain a strong security posture, meet regulatory obligations, and build customer trust.

Ideal candidate:

A self-motivated, experienced professional who thrives with autonomy, takes ownership of their work, and executes with minimal oversight. A collaborative team player and strong communicator, capable of building relationships and driving outcomes across technical and business teams.

What You’ll Do:
  • Support the delivery of Rippling’s security assurance program across ISO 27001, SOC 2, ISO/IEC 42001, ISO/IEC 27018 and CSA STAR. The successful candidate will have experience supporting these certifications and attestation, coordinating evidence collection across the business, liaising with internal stakeholders and auditors, and helping ensure all annual certification and attestation activities are completed efficiently and on schedule.
  • Vendor Management (Security Assurance): Perform security due diligence on new and existing vendors, evaluating the data they process, where it is stored, how it is used, their security and privacy controls, independent certifications (e.g. SOC and ISO), and external security ratings (BitSight) to support informed third-party risk and onboarding decisions.
  • Support the evolution of the ISMS by enhancing security policies and standards, maturing the policy lifecycle, and improving governance and review processes across the organization.
  • Support internal teams and external stakeholders with ad hoc security assurance requests, including audit evidence, customer due diligence, policy guidance, and broader security governance activities.
What You Bring:
  • 5+ years of experience in security compliance roles, with exceptional communication skills, enabling you to effectively engage with internal teams (e.g., engineering, privacy/legal, and product, etc.) and external stakeholders.
  • In-depth familiarity with information security standards such as ISO 27001 and SOC 2.
  • Proficiency in cloud security best practices, ensuring our cloud infrastructure remains secure and compliant.
  • Experience developing, reviewing, and maintaining information security policies
  • Good understanding of privacy regulations and data handling obligations, with the ability to work effectively alongside legal and privacy teams.
Nice to have:
  • Information security awareness training materials
  • Experience creating meaningful Security Metrics
  • Working knowledge or experience of User access management
  • Experience automating security controls
Additional Information

Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics, Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accomodations@rippling.com

Rippling highly values having employees working in-office to foster a collaborative work environment and company culture. For office-based employees (employees who live within a defined radius of a Rippling office), Rippling considers working in the office, at least three days a week under current policy, to be an essential function of the employee’s role.

This role will receive a competitive salary + benefits + equity. The salary for US-based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.

A variety of factors are considered when determining someone’s compensation–including a candidate’s professional background, experience, and location. Final offer amounts may vary from the amounts listed below.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Rippling • New York (NY)

On-site
USD 140,000 - 210,000
Equity
Staff Product Security Engineer
Staff Product Security Engineer

Rippling • San Francisco (CA)

On-site
USD 190,000 - 270,000
Equity
Benefits
Onsite three days a week
Staff Product Security Engineer
Staff Product Security Engineer

Rippling • Seattle (WA)

On-site
USD 189,000 - 315,000
Senior Product Security Engineer: Build Guardrails & Tools
Senior Product Security Engineer: Build Guardrails & Tools

Rippling • San Francisco (CA)

On-site
USD 168,000 - 280,000
Senior Security Engineer
Senior Security Engineer

Rippling • San Francisco (CA)

On-site
USD 168,000 - 280,000
Senior Product Security Engineer — Build Secure, Scalable Apps
Senior Product Security Engineer — Build Secure, Scalable Apps

Rippling • Seattle (WA)

On-site
USD 168,000 - 280,000
Senior Security Engineer
Senior Security Engineer

Rippling • Seattle (WA)

On-site
USD 168,000 - 280,000
Staff Product Security Engineer
Staff Product Security Engineer

Rippling • New York (NY)

On-site
USD 180,000 - 260,000
Equity
Senior Security Engineer
Senior Security Engineer

Rippling • New York (NY)

Hybrid
USD 168,000 - 280,000
Technical Support Specialist, IT-Apps
Technical Support Specialist, IT-Apps

Rippling • Washington

On-site
USD 30,000 - 33,000