HashiCorp is hiring a
Compliance Analyst II

Logo of HashiCorp

HashiCorp

πŸ’΅ ~$201k-$241k
πŸ“Remote - Canada

Summary

Join our team as a Compliance Analyst II to support compliance enablement across HashiCorp product lines. As a cloud and DevOps savvy GRC Compliance Analyst, you will embed within the day-to-day of HashiCorp product lines to enable compliance by providing real-time readiness evaluation, control scoping, and advising on remediation of gaps. The ideal candidate will have experience collaborating with cross-functional teams to embed compliance controls into agile and DevOps processes.

Requirements

  • Minimum of 2-5 years of related professional compliance and controls program experience
  • Previous experience in a cloud environment, preferably AWS and/or Azure
  • Experience with modern DevOps patterns and practices, with a strong understanding of how to embed security controls into these processes
  • Advanced level knowledge either controls and control frameworks
  • Comfortable working with both deeply technical and non-technical resources
  • Flexible in daily hours (e.g. willingness to work longer hours during end of quarter ,peak periods, and audit)
  • Highly responsive
  • Ability to prioritize and track multiple projects and tasks in parallel
  • Excellent communication and collaboration skills. Ability to work effectively with cross-functional teams and provide clear guidance on complex compliance issues

Responsibilities

  • Work closely with product development teams to integrate security and compliance requirements into the product lifecycle, ensuring that all products are built with compliance in mind from the ground up
  • Conduct real-time readiness assessments of products and features during development, identifying potential compliance risks and providing actionable recommendations to address gaps
  • Define the scope of compliance controls and requirements for new and existing products, ensuring that all relevant aspects of the product are covered
  • Provide ongoing guidance to product teams on security controls and industry best practices, helping them navigate complex compliance landscapes
  • Leverage your technical expertise and deep understanding of the product to effectively collaborate with the rest of the GRC team, ensuring alignment and accuracy of understanding during audits. Lead internal and external audits related to product compliance, ensuring that all documentation and controls are in place and up to date
  • Collaborate with cross-functional teams, including product managers and engineers, to embed security controls into development and operational processes
  • Help develop and deliver training on security and compliance requirements and control owner responsibilities
  • Identify assets utilized in the services/products that impact compliance (cloud accounts, repositories, Github teams, etc.) and ensure they are documented in the scope/boundaries of the compliance program including updates, removals and additions
  • Assisting with internal audits, control testing and external audits
  • Work with Engineering teams to identify automation opportunities of manual tasks, such as continuous monitor of controls and audit evidence collection
  • Support other GRC work as required

Preferred Qualifications

  • Experience working in a large, multi-cloud environment
  • Deep understanding of common security compliance frameworks, attestations and certifications
  • Understanding of infrastructure as code and related controls
  • Previous experience at a technology or SaaS company in a similar role
  • Existing experience with HashiCorp products
  • Experience working with OSCAL

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.

Similar Jobs

Please let HashiCorp know you found this job on JobsCollider. Thanks! πŸ™