Security Compliance Analyst

Harbinger Motors Inc.

$130K — $160K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Systems, Cybersecurity, or related field (or equivalent experience).
  • 5+ years in security compliance, GRC, or IT audit with experience from gap assessment through external audit report or certification.
  • Experience in a startup or high-growth environment building compliance programs.
  • Hands-on ownership of SOC 2 Type II and/or ISO/IEC 27001, translating controls across frameworks.
  • Familiarity with NIST-based control catalogs and handling restricted data controls.

Responsibilities

  • Own and maintain the control catalog for implementation status and evidence requirement verification.
  • Translate control requirements into actionable changes for teams and verify implementation success.
  • Maintain the corrective action plan with defined ownership and evidence for closure.
  • Run evidence collection automatically to streamline compliance processes.
  • Prepare for and support external audits, ensuring readiness and effective remediation of findings.
  • Document system boundaries and scope rationale for clear audit defensibility and understanding.
  • Administer the GRC platform Vanta for control mappings and evidence management.

Benefits

  • Comprehensive Health, Dental & Vision coverage - 100% employee covered
  • Early-stage Stock Options available
  • Robust Retirement Savings (401k, HSA, FSA) offered
  • Generous Paid Time Off (PTO) & Parental Leave provided
  • Annual Vacation Bonus included
  • Wellness & Fertility Benefits available
  • Cell Phone Stipend provided
  • Complimentary Meals & Stocked Kitchens at the workplace.
Full Job Description
Role Summary

Harbinger is hiring a Security Compliance Analyst to build and own our security compliance program end to end. This is a hands-on, builder role: we're looking for someone who has already taken a compliance framework from gap assessment through an external audit and wants to do it again somewhere the program doesn't exist yet. You'll own the control set, the evidence behind it, the policies that describe it, and the tooling that holds it together. You'll grow into our expanding compliance scope as that work emerges with new business opportunities.

What You'll Do:

Compliance Frameworks & Controls
  • Own the control catalog: implementation status, testing, evidence requirements, and crosswalks where frameworks overlap.
  • Translate control requirements into specific, actionable changes for teams to implement, then verify they landed.
  • Maintain the corrective action plan; open findings with named owners, real dates, and a defined evidence bar for closure partnering with program management on execution.


Audit & Evidence Management
  • Run evidence collection on a standing cadence, building automations so evidence becomes a byproduct of normal operations rather than a quarterly scramble.
  • Prepare for and support external audits and certification assessments: readiness reviews, sample pulls, auditor walkthroughs, and remediation of findings.
  • Define and document our system boundary and scope decisions: what's in, what's deliberately out, and reasoning that holds up under an assessor's questions.


Policy, Governance & Tooling
  • Write and maintain the policy and procedure set. Short enough that engineers read it, specific enough that an auditor accepts it.
  • Administer our GRC platform Vanta, including control mappings, integrations, framework crosswalks, and evidence freshness
  • Support role-based security awareness training and data handling guidance


Third-Party Risk & Cross-Functional
  • Run vendor and third-party security reviews, including cloud services and the security requirements we flow down to suppliers.
  • Document control decisions, scope rationale, and audit outcomes in Jira or Confluence so the program is maintainable by others.
  • Report compliance posture and audit readiness to security leadership on a regular cadence.


Who You Are:

Education & Experience
  • Bachelor's degree in Information Systems, Cybersecurity, or related field (or equivalent experience).
  • 5+ years in security compliance, GRC, or IT audit, including at least one framework taken from gap assessment through an external audit report or certification.
  • Experience in a startup or high-growth environment building a program rather than maintained one.
  • Security certifications (e.g. CISA, CRISC, CompTIA Security+, ISO 27001 Lead Auditor) are a plus.

Technical Competencies
  • Hands-on ownership of SOC 2 Type II and/or ISO/IEC 27001. Able to translate controls to other frameworks and compliance needs across all business units.
  • Experience with a certification audit where the outcome is pass or fail against a fixed control catalog, not an opinion accompanied by a management response.
  • Experience defining a system boundary and defending the scoping decision to an external assessor.
  • Familiarity with NIST-based control catalogs, mapping between overlapping frameworks, and the handling and storage controls that attach to restricted or contractually protected data.
  • Evidence and audit management: you can describe an evidence chain end to end: what artifact, generated how, refreshed how often, who attests.
  • GRC platform administration in Vanta configuring mappings and integrations.
  • Working in collaboration platforms like Confluence or Jira.
  • Scripting ability (e.g. Python or JavaScript) is a plus.

Soft Skills
  • Strong written and verbal communication; able to translate control requirements into concrete changes an engineer can act on.
  • Comfortable influencing teams that don't report to you, and staying with a position when the answer needs to be no.
  • Comfortable working cross-functionally in a fast-paced, high-growth manufacturing environment.
  • Documentation discipline: if it isn't written down, it didn't happen.


Key Benefits & Perks:
  • Comprehensive Health, Dental & Vision (HDV) - 100% employee covered
  • Early-stage Stock Options
  • Robust Retirement Savings (401k, HSA, FSA)
  • Generous Paid Time Off (PTO) & Parental Leave
  • Annual Vacation Bonus
  • Wellness & Fertility Benefits
  • Cell Phone Stipend
  • Complimentary Meals & Stocked Kitchens


California Pay Range

$130,000-$160,000 USD

Similar Jobs

More Jobs at Harbinger Motors Inc.

More Information Technology Jobs

Find similar Security Compliance Analyst jobs: