CareerPlanSign in

Senior Security Assurance Analyst

New York Office💼 Full-time🗓 2026-08-10 → 2026-09-26

Core

Lead end-to-end security compliance and assurance programs (ISO 27001, SOC 2, PCI DSS, HIPAA) and manage external audit lifecycles for Lyft's global markets.

Role type

Senior Security Assurance Analyst (GRC)

Builds

Compliance certifications, audit evidence, security policies, and automated control testing workflows

Domain

Information Security / Regulatory Compliance / GRC

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

ISO 27001, PCI DSS, SOC 2, HIPAA, NIST CSF, risk management, policy development, external auditor liaison, contract security review, automation design, cross-functional leadership

Preferred skills

EU/UK regulatory frameworks (GDPR, NIS2, CRA), vulnerability management, GRC platforms (AuditBoard, Vanta, Drata), AI/LLM for compliance automation, Big 4 consulting experience, CISA/CISSP/CISM certifications

Technologies

Jira, Confluence, SafeBase, AuditBoard, Vanta, Drata

Responsibilities

Own ISO 27001 compliance program end-to-end; Drive execution across multi-program compliance portfolio (SOC 2, PCI DSS, HIPAA, NIST CSF); Serve as primary liaison to external auditors; Own Security Risk Management Framework; Lead development of security policies and procedures; Support review of security provisions in customer contracts; Drive evidence collection and continuous control testing using workflow tools; Partner with Engineering to design automated evidence collection and remediation tracking; Own responses to customer security questionnaires and manage external trust center

Seniority

Senior, hands-on IC

Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.