About the Role
The Security Compliance Analyst will be a critical, hands-on member of the Navan Governance, Risk, Compliance, and Trust (GRCT) Team, specifically embedded in London to drive the compliance integration between Navan and Reed & Mackay. This role focuses on execution, untangling legacy systems, mapping control deficiencies, and running daily operational workflows to ensure the security of global travel and expense platforms.
Responsibilities
- Own Vulnerability Remediation Loops: Actively track and oversee quarterly PCI ASV scans and penetration testing cycles, collaborating directly with IT and engineering teams to ensure patches are executed within strict SLA windows.
- Lead the Integration Pipeline: Conduct continuous gap analyses and map security controls as we merge legacy travel infrastructure into Navan's modern cloud frameworks.
- Drive SOX 404 Controls: Take ownership of testing and validating IT General Controls (ITGCs) under Sarbanes-Oxley Section 404, with a heavy emphasis on access control management (Joiners/Movers/Leavers) and secure code deployment.
- Embed with Engineering: Partner with development teams to automate manual evidence gathering, translating rigid compliance jargon into clear, actionable JIRA tickets.
- Collaborate Globally: Partner closely with US-based audit firms and compliance bodies, including flexible scheduling for monthly evening shifts.
- Track Open Deficiencies: Manage the risk register and remediation tracking lifecycle from initial identification to final verification and closure.
Requirements
- Minimum of 3+ years of hands-on, corporate operational experience in information security compliance.
- Active experience sitting on a corporate security or IT team.
- Proved, practical exposure executing compliance frameworks for transactional environments.
- Understanding of Section 404 ITGCs and the technical mechanics of PCI DSS (including cardholder data protection environments and SAQs).
- Comfortable navigating tracking platforms such as JIRA, ServiceNow GRC, or AuditBoard.
- Baseline technical background (e.g., computer science, systems administration, or IT support).
- Willingness to work under a hybrid model out of our London office (4 days a week).
- Routine flexibility needed to support monthly evening shifts for US team synchronization.
- Full proficiency in English.
Skills
- Information security compliance
- PCI DSS
- SOX 404
- IT General Controls (ITGCs)
- Access control management
- Secure code deployment
- JIRA
- ServiceNow GRC
- AuditBoard
- Computer science
- Systems administration
- IT support
Location
- London
Work Type
- Hybrid
- Full-time
Experience Level
- 3+ years
Education Level
- CompTIA Security+ (Bonus)
- ISO 27001 Internal Auditor (Bonus)
