Security Compliance Lead
Core
Lead Asana's FedRAMP Continuous Monitoring and authorization activities while supporting broader SOC 2 and ISO 27001 compliance frameworks.
Role type
Senior GRC Security Compliance Lead
Builds
FedRAMP compliance programme, audit evidence packages, and control maturity frameworks
Domain
Cloud Security / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
FedRAMP expertise (ConMon, evidence collection), GRC framework knowledge (SOC 2, ISO 27001), audit coordination, stakeholder management, deadline-driven execution, technical curiosity
Preferred skills
Experience with GRC platforms, automation/scripting, NIST CSF knowledge, AI tool adoption
Technologies
GRC platforms, scripting, API integrations
Responsibilities
Own monthly FedRAMP ConMon submissions, track timebound FedRAMP requirements, serve as internal FedRAMP SME, support external audits, manage evidence collection workflows, drive controls maturity and remediation
Seniority
Senior, hands-on IC