Senior Security Assurance Analyst
Lyft · New York, NY
About this role
**Senior Security Assurance Analyst** **About the Role** Join Lyft's Customer Trust team to own a portfolio of concurrent, multi-program compliance efforts. You'll ensure Lyft meets enterprise promises and contractual commitments to customers on security and privacy across global markets, managing relationships with external auditors and internal stakeholders. **Key Responsibilities** **Program & Audit Ownership** • Own and lead ISO 27001 compliance program end-to-end • Drive execution across multi-program compliance portfolio (SOC 2, PCI DSS, HIPAA, NIST CSF, UK Cyber Essentials, Spain ENS, CRA, RED, NIS2) • Serve as primary liaison to external auditors, QSAs, and certification bodies **Risk, Policy & Stakeholder Advisory** • Own the Security Risk Management Framework • Lead development and maintenance of information security and data protection policies • Build cross-functional relationships with Engineering, Legal, Privacy, and Sales • Support review of security provisions in customer contracts and MSAs **Evidence, Automation & Tooling** • Drive evidence collection and continuous control testing using Jira and Confluence • Partner with Engineering on automated evidence collection and control testing • Leverage AI tools and LLM-based workflows to automate compliance processes **Customer-Facing Assurance** • Own responses to customer security questionnaires (CAIQ, SIG) • Manage external trust center (SafeBase) **Required Experience** • 5+ years in security governance, risk, and compliance (GRC), IT audit, or related role • 5+ years hands-on with ISO 27001 and PCI DSS • In-depth knowledge of SOC 2, HIPAA, and NIST CSF • Experience managing multi-program compliance portfolios with global/international requirements • Experience managing, reviewing, and drafting InfoSec policies • Strong technical background and ability to communicate with engineering teams • Excellent cross-functional communication and leadership skills • Strong written and verbal communication across technical, business, and executive audiences **Preferred Qualifications** • Experience with multiple frameworks (ISO 27001, SOC 2, PCI DSS, SOX ITGC) • GDPR, EU AI Act, NIS2, or international privacy/security compliance experience • Vulnerability management program experience • GRC platform experience (AuditBoard, Vanta, Drata), Jira, SafeBase • AI/LLM experience for compliance automation • Certifications: CISA, CISSP, CISM, CRISC, or ISO 27001 Lead Auditor • Big 4/3 consulting experience • Scripting, automation skills, AWS/GCP/Azure experience **Benefits** • Medical, dental, vision insurance • Mental health benefits • Family building and child care benefits • 401(k) with company match • Discretionary PTO (salaried) or 15 days PTO (hourly) • 18 weeks paid parental leave • Subsidized commuter benefits • Lyft credits and complimentary Lyft Pink membership **Work Arrangement** Hybrid role - 3 days/week in-office (Mon/Wed/Thu) in New York City area **Compensation** Base pay range: $148,000 - $185,000 (plus potential equity, bonus, and benefits) Lyft is an equal opportunity employer committed to an inclusive workplace.
Listing freshness
CronJobs last confirmed this listing 2d ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.