Security Analyst - Governance, Risk, and Compliance

Remote - US

LaunchDarkly

Maximize the value of every software feature through automation and feature management.

View company page

Software powers the world, and LaunchDarkly empowers all teams to deliver and control the best software. We serve trillions of feature flags daily to help teams ship better software faster and eliminate risk for companies big and small. We're based in downtown Oakland and growing quickly.

We're looking to hire a Security Analyst to join the Governance, Risk Management, and Compliance function of our security team and help us secure our company and product. This role will report to the Director of Security and participate in initiatives to reduce security risk and achieve compliance with frameworks including ISO 27001, SOC 2, and FedRAMP.

What you'll do:

  • Collaborate with stakeholders to operate security controls that comprise the LaunchDarkly GRC program
  • Use technology to automate compliance activities like gathering evidence and verifying controls
  • Operationalize the health of the program by tracking metrics based on quantitative and qualitative data
  • Drive progress towards results for GRC-related continuous improvement projects
  • Contribute to documentation for security standards, policies, and processes
  • Support audits and assessments with internal and external stakeholders
  • Work with product and infrastructure delivery teams on engineering projects related to GRC requirements

Who you are:

  • Demonstrated interest in cybersecurity and privacy

  • Excellent communication skills
  • Experience working on collaborative projects
  • Familiarity with modern cloud-based SaaS organizations - we’re almost entirely AWS and Mac OS-based
  • Basic knowledge of software development and architecture

You may also have:

  • Information security experience at an organization with significant compliance requirements
  • Familiarity with security standards (SOC 2, ISO 27001, FedRAMP) as well as privacy laws (CCPA and GDPR)
  • CCSP, PCI QSA, CISSP, or CISA certifications
  • Familiarity with LaunchDarkly’s collaboration tools like Confluence, Slack, and Github

 

About LaunchDarkly:

LaunchDarkly is a Feature Management Platform that serves hundreds of billions of feature flags daily to help software teams build better software, faster. Feature flagging is an industry standard methodology of wrapping a new or risky section of code or infrastructure change with a flag. Each flag can easily be turned off independent of code deployment (aka "dark launching"). LaunchDarkly has SDKs for all major web and mobile platforms. We are building a diverse team so that we can offer robust products and services. Our team culture is dynamic, friendly, and supportive. Our headquarters are in Oakland.

At LaunchDarkly, we believe in the power of teams. We're building a team that is humble, open, collaborative, respectful and kind. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, or disability status.

Don't let the confidence gap get in the way of applying! We'd love to hear from you.

We've partnered with KeyValues to help demonstrate the amazing culture we've built here at LaunchDarkly, find more info at https://www.keyvalues.com/launchdarkly. LaunchDarkly is also committed to giving back to our community by donating 1% of annual revenue to local charities and organizations. You can find more about the LaunchDarkly Foundation and the organizations we serve at https://launchdarkly.com/foundation/

#LI-Remote

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Audits AWS CCPA CCSP CISA CISSP Cloud Compliance FedRAMP GDPR GitHub Governance ISO 27001 PCI QSA Privacy Risk management SaaS SOC 2

Perks/benefits: Team events

Regions: Remote/Anywhere North America
Country: United States
Job stats:  17  4  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.