About the Role
The Security Compliance Analyst will ensure continued compliance with global security regulations and industry frameworks, acting as a bridge between technical teams, end users, external assessors, and international business units to safeguard platforms and maintain customer trust.
Responsibilities
- Coordinate and support internal and external security audits, technical assessments, and penetration tests.
- Partner closely with US-based compliance auditors and external audit firms, with a flexible schedule to work late a few days per month.
- Manage audit findings and remediation tracking to ensure timely resolution of compliance issues.
- Perform regular testing of security compliance controls to identify deficiencies, track KPIs, and report on compliance health.
- Partner with engineering teams to implement automated evidence collection workflows using JIRA and AI platforms.
- Translate complex technical security requirements into clear business language for effective collaboration.
Requirements
- Minimum of 3 years of hands-on experience in information security compliance.
- Ideally paired with a technical background (e.g., developer, software engineer, systems administrator).
- Strong working understanding of Sarbanes-Oxley 404 IT General Controls (ITGCs) and PCI DSS.
- Familiarity with frameworks like ISO 27001, Cyber Essentials Plus, NIST CSF, or SOC 1 and SOC 2.
- Practical experience using GRC software (e.g., Optro/AuditBoard, SafeBase).
- Practical experience using standard ticketing platforms like JIRA.
- Excellent attention to detail.
- Proactive approach to problem-solving.
- Flexibility to adapt working hours monthly to accommodate collaboration with US-based auditing bodies.
- Degree-level education in Cybersecurity, Computer Science, or a related field (or equivalent practical experience).
- Industry certifications like CompTIA Security+, ISO 27001 Lead Auditor, or ISC2 CGRC are highly advantageous.
- Proficiency in French, Spanish, Italian, or German is highly beneficial.
Skills
- Information security compliance
- Sarbanes-Oxley 404 ITGCs
- PCI DSS
- ISO 27001
- Cyber Essentials Plus
- NIST CSF
- SOC 1
- SOC 2
- GRC software
- JIRA
- Attention to detail
- Problem-solving
- Adaptability
- Communication
Experience Level
- Minimum of 3 years
Education Level
- Degree-level education in Cybersecurity, Computer Science, or a related field (or equivalent practical experience)
About the Company
- Navan provides a secure, world-class global travel and expense platform.
