Senior Security Assurance Analyst at Lyft | NY, US | Rezi

Senior Security Assurance Analyst at Lyft

Senior Security Assurance Analyst

Lyft · NY, US

2 weeks ago

Senior Security Assurance Analyst

Lyft · NY, US

19 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Lyft's Customer Trust team ensures that appropriate security controls and data protections are applied to meet compliance requirements and customer contractual commitments. This role will own a portfolio of concurrent, multi-program compliance efforts and help ensure Lyft meets its enterprise promises and contractual commitments to customers on security and privacy across global markets.

Responsibilities

  • Own and lead the ISO 27001 compliance program end-to-end.
  • Drive execution across a multi-program compliance portfolio spanning SOC 2, PCI DSS, HIPAA, and NIST CSF, alongside global and international frameworks.
  • Serve as the primary liaison to external auditors, QSAs, and certification bodies.
  • Own the Security Risk Management Framework.
  • Lead the development, review, and maintenance of internal information security and data protection policies, standards, and procedures.
  • Build and maintain strong cross-functional relationships with Engineering, Legal, Privacy, and Sales.
  • Support review of security provisions in customer contracts, MSAs, and security exhibits.
  • Drive evidence collection and continuous control testing using workflow tools.
  • Partner with Engineering to design, implement, and monitor automated evidence collection, continuous control testing, and remediation tracking.
  • Leverage AI tools and LLM-based workflows to automate and improve compliance and assurance processes.
  • Own responses to customer security questionnaires and management of our external trust center.

Requirements

  • 5+ years of experience in security governance, risk, and compliance (GRC), IT audit, or a related security assurance role.
  • 5+ years of hands-on experience with ISO 27001 and PCI DSS.
  • In-depth knowledge of other regulatory compliance and related assessments/certifications, including SOC 2, HIPAA, and NIST CSF.
  • Experience managing a multi-program compliance portfolio spanning global and international requirements.
  • Experience managing, reviewing, and drafting InfoSec policies and procedures.
  • Strong technical background with the ability to communicate and negotiate effectively with engineering teams.
  • Excellent cross-functional communication and leadership skills.
  • Ability to manage a large workload and competing priorities amid resourcing constraints and tight deadlines.
  • Strong written and verbal communication skills.

Skills

  • ISO 27001
  • PCI DSS
  • SOC 2
  • HIPAA
  • NIST CSF
  • UK Cyber Essentials
  • Spain ENS
  • Cyber Resilience Act (CRA)
  • Radio Equipment Directive (RED)
  • NIS2
  • Jira
  • Confluence
  • AI tools
  • LLM-based workflows
  • CAIQ
  • SIG
  • SafeBase
  • GRC platforms
  • AuditBoard CrossComply
  • Vanta
  • Drata
  • AWS/GCP/Azure

Location

  • New York City area

Work Type

  • Hybrid
  • In-office 3 days per week
  • Work from anywhere for up to 4 weeks per year

Experience Level

  • Senior

Education Level

  • CISA
  • CISSP
  • CISM
  • CRISC
  • ISO 27001 Lead Auditor/Implementer

Salary/Compensations

  • $148,000 - $185,000

Benefits

  • Great medical, dental, and vision insurance options with additional programs available when enrolled
  • Mental health benefits
  • Family building benefits
  • Child care and pet benefits
  • 401(k) plan with company match
  • Discretionary paid time off (salaried)
  • 15 days paid time off (hourly)
  • 18 weeks of paid parental leave
  • Subsidized commuter benefits
  • Monthly Lyft credits and complimentary Lyft Pink membership

About the Company

  • Lyft connects people to transportation to change the way we live and get around our communities.
  • Lyft's Customer Trust team ensures that appropriate security controls and data protections are applied to meet our compliance requirements and customer contractual commitments.
  • Lyft highly values having employees working in-office to foster a collaborative work environment and company culture.

Equal Opportunity

  • Lyft is an equal opportunity employer committed to an inclusive workplace that fosters belonging. All qualified applicants will receive consideration for employment without regards to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, age, genetic information, or any other basis prohibited by law. We also consider qualified applicants with criminal histories consistent with applicable federal, state and local law.