- Location
<h4><strong>Role Overview</strong></h4> <p>As a Security Risk and Compliance Lead you will play a hands-on role in maturing and operating Asana's compliance and certification programme—with a primary focus on FedRAMP Continuous Monitoring and authorization activities. This role sits at the intersection of traditional GRC work and compliance engineering: you will own our FedRAMP programme day-to-day, while also supporting our broader audit cycles and control frameworks across SOC 2 and ISO 27001.</p> <p>This is an excellent opportunity for someone with early-career GRC experience who has a strong grounding in FedRAMP and is excited to grow their technical skills in a high-growth SaaS environment. You will partner closely with Security Engineering, Legal, Privacy, and R&D to ensure our FedRAMP obligations are met with rigour, our controls are effective, and our certifications are maintained.</p> <p>This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.</p> <h4><strong>What You’ll Achieve</strong></h4> <p><strong>FedRAMP Continuous Monitoring</strong></p> <ul> <li>Own the monthly FedRAMP ConMon package submission, ensuring it is accurate, complete, and delivered on time every month.</li> <li>Track and drive completion of all timebound FedRAMP requirements by working closely with Engineering, People, and other responsible teams.</li> <li>Maintain a clear calendar of FedRAMP deliverables and proactively flag risks to timelines, escalating where needed to ensure nothing slips.</li> <li>Serve as the internal subject matter expert for FedRAMP, acting as the day-to-day point of contact for FedRAMP-related queries from internal teams and helping them understand their obligations and what good looks like.</li> <li>Proactively engage with a wide range of teams—including Engineering, IT, and People—to work through FedRAMP controls maturity activities, close existing gaps, and drive remediation efforts to completion with clear documentation of progress.</li> </ul> <p><strong>Controls Maturity & Broader Certifications</strong></p> <ul> <li>Support the maintenance and continuous improvement of Asana's broader control framework across SOC 2, ISO 27001, and other applicable standards.</li> <li>Support external compliance audits end-to-end: coordinating evidence requests, liaising with auditors, and tracking findings through to closure.</li> <li>Co
asana
Posted via Greenhouse_public
Apply Now takes you to Rozgoo, where auto-apply can submit your application for this role. Updated today.
Apply Now