Security Compliance Analyst

Reposted 6 Days Ago
Easy Apply
Be an Early Applicant
London, Greater London, England, GBR
Hybrid
Mid level
Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Travel & expense made easy.
The Role
The Security Compliance Analyst ensures compliance with global security regulations and frameworks, manages security audits, and collaborates with internal and external teams to improve security posture.
Summary Generated by Built In

About the Role

The Security Compliance Analyst will work as a critical part of the Security Compliance Team, operating within the wider Navan Governance, Risk, Compliance, and Trust (GRCT) Team. In this role, you will ensure our continued compliance with global security regulations and industry frameworks—including GDPR, Sarbanes-Oxley ITGCs, ISO 27001, PCI DSS, and SOC 1/SOC 2. Acting as a key bridge between technical engineering teams, end users, external assessors, and international business units, you will play an essential part in safeguarding our platforms, maintaining customer trust, and scaling Navan’s global operations securely.


What You’ll Do

In this role, you will protect and enhance Navan's security posture, directly furthering our company goal of providing a secure, world-class global travel and expense platform. Your typical responsibilities will include:

  • Coordinating and supporting internal and external security audits, technical assessments, and penetration tests across our environments.
  • Partnering closely with US-based compliance auditors and external audit firms; this includes a flexible schedule to work late (until 9:00 PM–10:00 PM) a few days per month on specific alignment days to facilitate direct collaboration with US teams.
  • Managing audit findings and remediation tracking items to ensure compliance issues and non-conformities are resolved in a timely manner.
  • Performing regular testing of security compliance controls to identify operational deficiencies, track Key Performance Indicators (KPIs), and report on overall compliance health and continuous improvements.
  • Partnering with engineering teams to gather and implement automated evidence collection workflows, utilizing JIRA and AI platforms to drive efficiency and reduce manual overhead.
  • Translating complex technical security requirements into clear, actionable business language to collaborate effectively with internal technical teams and external stakeholders at all levels.

What We’re Looking For

  • Experience: Minimum of 3 years of hands-on experience in information security compliance, ideally paired with a technical background (such as experience as a developer, software engineer, or systems administrator).
  • Framework Expertise: Strong working understanding of Sarbanes-Oxley 404 IT General Controls (ITGCs) and the PCI DSS, alongside familiarity with frameworks like ISO 27001, Cyber Essentials Plus, NIST CSF, or SOC 1 and SOC 2.
  • Tools & Systems: Practical experience using GRC software (e.g., Optro/AuditBoard, SafeBase) alongside standard ticketing platforms like JIRA.
  • Core Skills & Flexibility: Excellent attention to detail, a proactive approach to problem-solving, and the flexibility to adapt your working hours monthly to accommodate collaboration with US-based auditing bodies.
  • Education & Certifications: A degree-level education in Cybersecurity, Computer Science, or a related field (or equivalent practical experience); industry certifications like CompTIA Security+, ISO 27001 Lead Auditor, or ISC2 CGRC are highly advantageous.
  • Bonus: As Navan works with colleagues around the globe, proficiency in French, Spanish, Italian, or German is highly beneficial.

Skills Required

  • Minimum of 3 years of experience in information security compliance
  • Technical background in development, software engineering, or systems administration
  • Strong understanding of Sarbanes-Oxley 404 IT General Controls and PCI DSS
  • Experience with GRC software and JIRA
  • Degree in Cybersecurity, Computer Science, or related field

What the Team is Saying

Brian Guimond
Adamas Victória Cavalcante Robitz
Bastian Martino
Charlotte Delafosse
Daniella Schuh
Alice Rao-Wyckoff
Mily O Loughlin
Anna
Roshni
Henry Statfeld
Jose Soares

Navan Compensation & Benefits Highlights

  • Fair & Transparent Compensation Pay aligns with mid‑ to upper‑market in core engineering and GTM roles, with competitive cash, equity, and bonus plans. Defined pay bands and commission tiers provide clarity on how earnings are structured.
  • Leave & Time Off Breadth Flexible/unlimited PTO is part of the package alongside paid parental leave durations for birthing and non‑birthing parents. Time‑off policies are positioned as broad and supportive across the company.
  • Wellbeing & Lifestyle Benefits Travel‑centric perks (IATAN access and discounted personal travel) combine with connectivity/home‑office stipends, commuter benefits, in‑office meals/snacks, and pet insurance. Access to Headspace supports mental‑health resources.

Navan Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Palo Alto, CA
3,300 Employees
Year Founded: 2015

What We Do

Navan (Nasdaq: NAVN) is the leading all-in-one business travel, payments, and expense management platform that makes travel easy for frequent travelers. From finding flights and hotels to automating expense reconciliation, with 24/7 support along the way, Navan delivers an intuitive experience travelers love and finance teams rely on. See how Navan customers benefit and learn more at navan.com.

Why Work With Us

At Navan, we’re never satisfied with the status quo, and we know breakthrough ideas come from diverse perspectives. We are committed to cultivating a workplace that reflects the diversity of the customers we serve while fostering leadership and innovation.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Navan Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

In-person connections is the foundation of Navan, the connections forged through face-to-face interactions improve company culture and what we can achieve together. We operate on a hybrid working model, which we define as four days a week in-office.

Typical time on-site: 4 days a week
HQPalo Alto, CA
Austin, TX
Bengaluru, IN
Berlin, DE
Boston, MA
Dallas, TX
Gurugram, IN
Lisbon, PT
London, GB
New Delhi, Delhi
New York, NY
Paris, FR
San Francisco, CA
Singapore
Sydney, AU
Tel Aviv-Yafo, IL
Learn more

Similar Jobs

Navan Logo Navan

Consultant

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
London, Greater London, England, GBR
3300 Employees

Navan Logo Navan

Consultant

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
London, Greater London, England, GBR
3300 Employees

Navan Logo Navan

Consultant

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
London, Greater London, England, GBR
3300 Employees

Navan Logo Navan

Account Manager

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
London, Greater London, England, GBR
3300 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account