InterviewHack.ai
Start free
Jobs / Asana

Security Compliance Lead

Asana·San Franciscosenior

In short

  • →Liderazgo en cumplimiento de FedRAMP con enfoque en monitoreo continuo y certificaciones.
  • →Trabajo diario con ingeniería, legal y otras áreas para mantener controles y cumplir auditorías.
  • →Destaca ser el experto interno en FedRAMP y liderar procesos de evidencia y remediasión.

Fluent written and verbal English

Apply on company site ↗Share on WhatsApp

In ~1 minute you get: who interviews you, the likely questions answered from your CV, and your CV tailored to this job. Free, no card.

🎧Land the interview? Bring the copilot. Our free extension listens to the live interview and flashes 3-4-word anchors from your resume and prep — glance, connect, talk. Get the extension →

What they ask for

  • ✓5+ años en GRC o seguridad de la información
  • ✓Experiencia hands-on con FedRAMP (ConMon, evidencia, certificación Moderate/High)
  • ✓Capacidad para gestionar plazos y coordinar múltiples equipos
  • ✓Conocimiento de SOC 2 e ISO 27001
  • ✓Habilidades de comunicación para actuar como punto de contacto interno
  • ✓Capacidad para documentar procesos y gestionar riesgos

Don't tick every box? That's normal — your free dossier shows your gaps and how to cover them in the interview.

GRC platformFedRAMP Continuous MonitoringSOC 2ISO 27001Audit coordinationEvidence collectionControl frameworksRisk trackingCompliance documentationCross-functional collaboration

Who should you write to at Asana?

Your free dossier identifies the people who'd interview you — their background, what they value, and how to reach out so you stand out before applying.

Role Overview As a Security Risk and Compliance Lead you will play a hands-on role in maturing and operating Asana's compliance and certification programme—with a primary focus on FedRAMP Continuous Monitoring and authorization activities. This role sits at the intersection of traditional GRC work and compliance engineering: you will own our FedRAMP programme day-to-day, while also supporting our broader audit cycles and control frameworks across SOC 2 and ISO 27001. This is an excellent opportunity for someone with early-career GRC experience who has a strong grounding in FedRAMP and is excited to grow their technical skills in a high-growth SaaS environment. You will partner closely with Security Engineering, Legal, Privacy, and R&D to ensure our FedRAMP obligations are met with rigour, our controls are effective, and our certifications are maintained. This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements. What You’ll Achieve FedRAMP Continuous Monitoring • Own the monthly FedRAMP ConMon package submission, ensuring it is accurate, complete, and delivered on time every month. • Track and drive completion of all timebound FedRAMP requirements by working closely with Engineering, People, and other responsible teams. • Maintain a clear calendar of FedRAMP deliverables and proactively flag risks to timelines, escalating where needed to ensure nothing slips. • Serve as the internal subject matter expert for FedRAMP, acting as the day-to-day point of contact for FedRAMP-related queries from internal teams and helping them understand their obligations and what good looks like. • Proactively engage with a wide range of teams—including Engineering, IT, and People—to work through FedRAMP controls maturity activities, close existing gaps, and drive remediation efforts to completion with clear documentation of progress. Controls Maturity & Broader Certifications • Support the maintenance and continuous improvement of Asana's broader control framework across SOC 2, ISO 27001, and other applicable standards. • Support external compliance audits end-to-end: coordinating evidence requests, liaising with auditors, and tracking findings through to closure. • Contribute to controls maturity scoring and reporting, providing ongoing visibility into programme health for senior leadership. • Build strong working relationships across the business so that control owners feel supported and accountability is shared, not siloed within the compliance team. Evidence Collection & Automation • Own evidence collection workflows within our GRC platform, ensuring controls are reliably mapped, evidence is current, and audit artefacts are ready year-round—with particular attention to FedRAMP requirements. • Document evidence collection procedures so that processes are transparent, auditable, and maintainable by the broader team. • Where possible, identify opportunities to automate repetitive evidence-gathering tasks—curiosity and initiative here will be valued, though this is not a core requirement of the role. About You • 5+ years of experience in Governance, Risk, and Compliance (GRC), information security, or a closely related field—internships and co-ops count. • Hands-on experience with FedRAMP—ideally including ConMon, evidence collection, or working within a FedRAMP Moderate or High bou

Looking for something similar?

Leave your email and we'll alert you when matching jobs appear.

Don't apply unprepared

We research who's interviewing you, tailor your CV and rehearse you live — first one free.

InterviewHack.ai

Prepare for the exact interview: who's interviewing you, a tailored CV, and a real coach.

Product

JobsFree ATS checkerInterview-English checkSalary checkLATAM salary reportFree coursesBlogTailored CVSpoken practiceIt's free

Remote jobs

ReactPythonFull-StackLATAMArgentinaMexicoSee all →

Prepare

Spoken practiceFrontendBackendAI EngineerBy companySell with your CV

Company

For employersAboutContactPrivacyTerms

© 2026 InterviewHack.ai · Your CV is yours. Never used to train anything. · A product of IA-PTY

Similar open roles

Lead Product Manager, Enterprise Services Management

Asana · Vancouver, BC

→

Engineering Manager

Asana · San Francisco

→

Administrative Business Partner

Asana · Vancouver, BC

→

Lead Product Manager, Enterprise Services Management

Asana · San Francisco

→