InternFlow

Greenhouse ·

full-time

Security Compliance Lead

Asana · San Francisco

Asana provides a cloud‑based work‑management platform that helps teams plan, track, and coordinate projects. In the Security Compliance Lead role you will own the day‑to‑day operation of Asana’s FedRAMP programme, preparing and submitting the monthly Continuous Monitoring package, tracking time‑bound requirements, and acting as the internal subject‑matter expert for FedRAMP‑related questions. You will also support SOC 2 and ISO 27001 audit cycles, coordinate evidence requests, liaise with auditors, and help maintain and improve the broader control framework. Working with Security Engineering, Legal, Privacy, and R&D, you will identify control gaps, drive remediation, and look for opportunities to automate evidence‑gathering within the GRC platform. The position suits candidates with at least five years of GRC or information‑security experience, hands‑on exposure to FedRAMP (including ConMon or evidence collection), and a solid grasp of SOC 2, ISO 27001, or NIST CSF. Strong organisational skills, deadline orientation, and the ability to collaborate across technical and non‑technical teams are essential.

security compliancefedrampcontinuous monitoringsoc 2iso 27001grcevidence collectionaudit supportasanasaas

Education

  • Level: Bachelor's degree
Security ComplianceHybrid

Key Skills

FedRAMPGRCSOC 2ISO 27001NIST CSFEvidence CollectionCompliance Engineering

Notes

Hybrid schedule with mandatory in‑office days Monday, Tuesday, Thursday

About the Role As a Security Risk and Compliance Lead you will play a hands‑on role in maturing and operating Asana's compliance and certification programme, focusing on FedRAMP Continuous Monitoring and authorization activities. Responsibilities Own the monthly FedRAMP ConMon package submission and track timebound FedRAMP requirements. Serve as internal subject matter expert for FedRAMP and support broader certifications (SOC 2, ISO 27001). Maintain evidence collection workflows in the GRC platform and identify automation opportunities. Support external compliance audits, coordinate evidence requests, and track findings. Requirements 5+ years of experience in Governance, Risk, and Compliance (GRC) or information security; internships and co‑ops count. Hands‑on experience with FedRAMP, including ConMon and evidence collection. Foundational knowledge of SOC 2, ISO 27001, or NIST CSF is a plus. Organised and deadline‑driven with ability to manage multiple workstreams.

Skills for this role

FedRAMPGRCSOC 2ISO 27001NIST CSFEvidence CollectionCompliance Engineering

Required skills

FedRAMPGRCSOC 2ISO 27001NIST CSFEvidence CollectionCompliance Engineering

Also mentioned in the listing

security compliancecontinuous monitoringaudit supportasanasaas
RoleSecurity Compliance Lead, Fedramp
CompanyAsana
LocationSan Francisco
CompensationNot disclosed
Posted2026-09-30
DeadlineRolling

Typical process for this type of role

A general guide — the exact steps for this specific listing may vary; check the original posting for details.

  1. 1ApplicationSubmit your resume through the apply link.
  2. 2ScreeningRecruiter reviews your background against the role.
  3. 3AssessmentA technical test, assignment, or coding round, depending on the role.
  4. 4Interview(s)One or more rounds with the hiring team.
  5. 5OfferOffer letter with compensation and start date.

Before you apply

0/4

About Asana

Asana is an operating system designed for human-agent teams to manage critical workflows. Founded in 2008, the platform utilizes the Asana Work Graph, a system that connects tasks, projects, goals, and dependencies to provide a shared context for both human users and AI agents. The software enables teams to collaborate within a shared space, utilizing shared memory to improve workflows over time while maintaining enterprise-grade governance, including audit trails and scoped permissions. Asana serves a wide range of organizations, including 85% of Fortune 100 companies, by providing tools for project management, compliance, portfolio monitoring, and cross-functional alignment. The platform is designed to help teams coordinate work, reduce time spent on status updates, and integrate AI agents directly into existing business processes.

All jobs and hiring details at Asanaasana.com

More at Asana

Other jobs at Asana

See all 30 openings at Asana

Explore Related Placements


// similar opportunities

You might also like

Lead Security Compliance Engineer

Klaviyo

Klaviyo logo
Denver, COfull-time
Any GraduateGreenhouseSecurity Compliance# Security Automation# Risk Analysis# Control Design# Audit Management+7 more

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. ...

Apply now →

Lead Security Compliance Engineer

Klaviyo

Klaviyo logo
Boston, MAfull-time
Greenhouse

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. ...

Apply now →

Security Risk & Compliance, Agent Security

Anthropic

San Francisco, CA | New York City, NYfull-time
Greenhouse

About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for s...

Apply now →

US Public Sector Compliance, Security GRC

Anthropic

San Francisco, CA | New York City, NYfull-time
Greenhouse

About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for s...

Apply now →

Public Sector Lead, Defence & Security

Scaleai

London, UKfull-time
Greenhouse

About Scale Scale builds AI systems for decisions that matter. We started out providing the data and evaluation behind many of the world's leading models, and w...

Apply now →

Sr. Technical Program Manager - Security Compliance

Cloudflare

Hybridfull-time
Greenhouse

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of ...

Apply now →