Full Job Description
As a Security and Compliance Analyst at Lasso, you own the weekly security and compliance work behind a health research data platform running on AWS and Google Cloud. You review cloud and identity logs, triage vulnerabilities, keep our audit evidence current in Vanta, and help take the company through SOC 2 Type 2. You also run Lasso's AI governance execution work. This position sits under the Manager of Security, Compliance and DevOps, with oversight from the CTO, COO and CEO as appropriate.
We are a HIPAA Business Associate running to a NIST 800-53 Moderate control baseline, and a federal sponsor checks our work continuously. The security team is one person today. You would be the second, and getting us certified is a real piece of the job, not a side project. As the role matures, this person may be designated Information System Security Officer (ISSO) for our NIST 800-53 authorization boundary, working under the Security Officer
What You'll Do
• Run the weekly security review: audit logs across our cloud and identity systems, then vulnerability scan results, written up and published, with tickets opened for anything that needs action.
• Keep Vanta healthy: failing tests, evidence collection, document gaps, policy acceptances and vendor security assessments.
• Maintain our remediation tracker. Chase owners and flag items before they go late.
• Run quarterly access reviews and third-party risk work, including customer security questionnaires.
• Support incidents: gather facts, build the timeline, keep the tracker and draft the notification. Escalation calls stay with the Security Officer.
• Help get us certified. Gap assessment through observation window through audit, roughly a third of the role.
• Run AI governance execution: build and quarterly-refresh the AI systems and agent inventory, and produce the shadow-AI discovery report from our identity, endpoint and monitoring data. Roughly 3 hours a week in year one, less after that. This work sits under Ian, with oversight from the CTO, COO and CEO as appropriate.
Qualifications
Required
• Three or more years in security, compliance, audit, information technology or systems administration, where you produced evidence that someone else then inspected.
• A current CompTIA Security+, SSCP, GSEC, CySA+ or CISA. Mid-study with a confirmed test date works too, tell us.
• You can read logs and tell a real problem from noise. Not detection engineering: looking at a week of sign-in activity and deciding what deserves a ticket.
• Writing that holds up: clear, plain, dated and specific. We test this with a short take-home exercise.
We will teach you Vanta, the frameworks (HIPAA, NIST 800-53, SOC 2, ISO 27001), read-only evidence work in AWS and Google Cloud, Microsoft Entra ID and Intune, Jira and Confluence, and Splunk as we stand it up this year. Almost nobody arrives knowing all of it.
Preferred
• Time on the inside of a SOC 2 Type 2 or ISO/IEC 27001 certification, on the company's side of the audit rather than the auditor's.
• HIPAA as a Business Associate, or NIST 800-53 or FedRAMP evidence work.
• Vulnerability management and patch deadline tracking.
• Experience with endpoint or awareness tooling such as CrowdStrike Falcon or KnowBe4.
• Exposure to AI governance or AI risk work: tool or vendor risk assessment, model inventories, or supporting an AI use policy.
You do not need a degree, a security clearance, coding experience, an on-call rotation, production access, or a prior job title with the word "compliance" in it. Hands-on experience substitutes for a degree in full. Some of our strongest candidates will be systems administrators moving into security, security operations analysts who have never done compliance, or the person at a hospital, credit union or lab who ended up answering the auditor without ever being given the title.
Want to Be a Wrangler? Here's What We Look For
• You hold yourself to a high standard and bring real rigor to your work.
• You make the people around you better.
• You stay curious and keep learning.
• You see a problem and start solving it, without waiting to be asked.
• You keep the whole picture in view and notice how a change in one place ripples through the evidence, the tracker and the audit.
• You write clearly and document your findings with precision.
• You take data privacy and responsible stewardship seriously, every time.
What We Offer
• A flexible, remote-friendly position with hours overlapping North American Eastern time.
• Group benefits plan (Lasso pays 100%).
• Group retirement savings plan with a 2% employer match.
• A professional development budget.
• Written procedures for every recurring duty, and a manager who does this work today and will run the first cycles alongside you.
• Work that matters: protecting the data behind a health research platform that scientists depend on.
• The range and pace of a start-up: broad scope, fast decisions and impact you can see.