Staff Security Analyst Navan - Business Travel Solutions & Expense Management Navan - Business Travel Solutions & Expense Management Platform Travel Business Travel Management See how to manage all corporate travel in one place. Program Management Advanced Analytics Navan Rewards Sustainability Travel Services Support Personal Travel Expense Payments Navan Events Business Travel Management See how to manage all corporate travel in one place. Program Management Travel Services Advanced Analytics Navan Rewards Sustainability Support Personal Travel Expense Management Control, manage, and track expenses. Payments Use Navan cards or bring your own corporate card. Navan Events Source venues and manage events end-to-end. Intelligence Integrations Security & Trust Solutions By Role Accounting Teams Executive Assistants Finance Teams Travel Managers Travelers By Company Size Enterprises Small Businesses By Industry Energy and Utilities Financial Services Food and Beverage Health and Wellness Industrial and Manufacturing Media and Entertainment Professional Services Real Estate & Construction Retail and E-Commerce Technology and Software Study finds Navan saves customers 16% on business travel Read now Pricing Resources Resource Center Webinars Guides and Reports Blogs Per Diem Calculator Mileage Calculator Glossary See why 77% of managers prioritize all-in-one T&E Read now Customers Case Studies Customer Reviews Admin resources End-User Resources Help Center Your browser does not support the video tag. “Navan just feels so much easier. It’s super seamless.” Watch full video Company
About Us Partners Careers Contact Us Join our team View job openings Region France Germany Netherlands Spain United Kingdom United States Your browser does not support the video tag. Introducing Navan Edge Early access The new standard for frequent travelers: tailored, rewarding, effortless. Get started Request a demo Log In France Germany Netherlands Spain United Kingdom United States Log In Log In Log In Staff Security Analyst Location: Palo Alto, CA Department: Security, Risk & Fraud We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won’t just maintain compliance—you’ll scale and automate it to eliminate manual friction. In this role, you’ll manage our Information Security Management System (ISMS), lead internal and external audits, and serve as the primary bridge between external regulators and our internal teams. If you excel at translating deep technical expertise into practical, automated solutions, this is your chance to shape our security ecosystem across the organization.
What You'll Do: Compliance Program Leadership (Primary Focus) Multi-Framework Compliance Management : Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II) ISMS Operations : Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processes Audit Coordination & Management : Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessments Risk Assessment & Adjustment : Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectives Control Automation & Optimization : Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflows Regulatory Compliance Strategy : Monitor regulatory changes and emerging compliance
requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligations Control Framework & Testing Control Owner Enablement : Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence
requirements Control Testing Program : Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologies Gap Assessment & Remediation : Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategies Evidence Management : Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditability Governance, Policy & Documentation Policy Development & Maintenance : Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory
requirements and industry best practices Unified Control Framework (UCF) : Develop and maintain control mapping across multiple frameworks to identify overlapping
requirements and optimize control implementation Documentation Governance : Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change tracking Compliance Reporting : Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committees Cross-Functional Collaboration & Stakeholder Management Executive Communication : Articulate complex compliance
requirements and risk scenarios to C-level executives, board members, and non-technical stakeholders Cross-Functional Partnership : Collaborate closely with Engineering, IT, Finance, Legal, People Ops, and Business Units to bridge control gaps and implement compliance solutions Training & Awareness : Develop and deliver security compliance training programs for employees, contractors, and control owners; build compliance awareness throughout the organization What We’re Looking For: Experience & Background 6-8+ years of progressive experience in security governance, risk and compliance (GRC), information security auditing, or compliance program management Demonstrated experience working directly with Big Four or external auditors through full audit cycles Control automation experience : Proven success implementing automated evidence collection, continuous control monitoring, and compliance workflow automation ISMS management : Hands-on experience running an Information Security Management System (ISO 27001 ISMS or equivalent) Framework & Regulatory Knowledge Deep expertise in PCI DSS (all 12
requirements, SAQ types, ROC processes, compensating controls) Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls, change management, backup/recovery, segregation of duties) Proficiency with ISO 27001:2022 and ISO 42001:2023 (AI Management System) frameworks Hands-on experience with SOC 1 (SSAE 18/ISAE 3402) and SOC 2 (Trust Services Criteria) audit
requirements Working knowledge of security frameworks including NIST CSF, NIST SP 800-53, CIS Controls, or COBIT Technical & Cloud Security Cloud security controls : Deep understanding of cloud security architecture, identity and access management (IAM), network security, data protection, and logging/monitoring within AWS (Azure or GCP experience is a strong plus) Control implementation : Practical knowledge of technical control implementation including encryption, secure configuration management, vulnerability management, and incident response Security architecture : Ability to review and assess security architectures, data flows, and system designs from a compliance perspective Tools & Technology GRC platforms : Hands-on experience with compliance automation platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, or similar) Evidence collection automation : Experience implementing automated evidence collection using APIs, scripts, or integration platforms Audit & assessment tools : Proficiency with vulnerability scanners, SIEM platforms, configuration management tools, and compliance scanning solutions Education & Certifications Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field Certifications (one or more): CISA (Certified Information Systems Auditor) CISM (Certified Information Security Manager) CISSP (Certified Information Systems Security Professional) ISO 27001 Lead Auditor or ISO 27001 Lead Implementer CCSP (Certified Cloud Security Professional) or CCSK (Certificate of Cloud Security Knowledge) PCI ISA (Internal Security Assessor) or PCI QSA (Qualified Security Assessor) Specialized Experience Regulated markets : Prior experience with FedRAMP (Low/Moderate/High), GovRAMP, CMMC (Level 1-3), StateRAMP, or TX-RAMP authorization processes Government & defense : Experience with NIST SP 800-171, DFARS compliance, or DoD authorization frameworks Unified Control Framework (UCF) : Demonstrated success building and maintaining unified or common control frameworks that map
requirements across multiple standards Consulting background : Previous experience with Big Four consulting firms (Deloitte, PwC, EY, KPMG) or specialized security/compliance consulting practices The posted pay range represents the anticipated low and high end of the
compensation for this position and is subject to change based on business need. To determine a successful candidate’s starting pay, we carefully consider a variety of factors, including primary work location, an evaluation of the candidate’s skills and experience, market demands, and internal parity. For roles with on-target-earnings (OTE), the pay range includes both base salary and target incentive
compensation. Target incentive
compensation for some roles may include a ramping draw period.
Compensation is higher for those who exceed targets. Candidates may receive more information from the recruiter. Pay Range $131,025 — $291,300 USD About Navan Navan (Nasdaq: NAVN) is the global AI-powered business travel and expense platform that makes travel easy for frequent travelers. From finding flights and hotels, to automating expense reconciliation, with 24/7 support along the way, Navan delivers an intuitive experience travelers love and finance teams rely on. See how Navan customers benefit and learn more at navan.com . Culture of Excellence Our team is our competitive edge — a high-performance group of smart, driven people committed to winning together. This dedication to excellence is why we’ve been recognized as a Best Place to Work by Built In (2023–2026), a G2 Best Global Software Company (2025–2026), Forbes Cloud 100 (2022–2025), and CNBC Disruptor 50 (2022–2025). At Navan, we provide an environment where top talent excels, offering the autonomy and fast-paced trajectory needed to build a defining career and do the best work of your life. Our
Benefits Navan offers a comprehensive
benefits program designed to support your well-being, financial security, and life outside of work. Our
benefits, thoughtfully tailored by country to meet local needs, include healthcare coverage, insurance offerings, and wellness resources for you and your family. We support long-term financial growth through retirement savings programs and opportunities to participate in our equity plans, so you can share in Navan’s success. To promote balance, we offer flexible time off, country-specific holidays, and paid parental leave for all new parents. Additional
benefits include connectivity and commuting support*, mental health resources, and exclusive travel-related
perks. Wherever you’re based, our
benefits evolve with you. Workplace Policy Navan believes in the value of in-person connections, whether that’s sitting down to have lunch with one another, taking a walking 1:1, or collaborating in a room together. The connections forged through face-to-face interactions improve company culture and drive business results. Navan invests in global office spaces — in the U.S., Europe, and Asia, among others — that feel welcoming. In-office
perks such as company-provided lunches and happy hours create a strong team environment to help you do your best work. Our employees work from the office four days a week. Please expect this policy for all roles that are tied to an office. Equal Opportunity Navan is an equal opportunity employer. We make all employment decisions based solely on merit. We provide equal employment opportunity to all applicants and employees without discrimination on the bases of race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We prohibit any such discrimination or harassment. This policy applies to all terms and conditions of employment, including hiring. Accommodations Navan complies with the Americans with Disabilities Act (ADA), as amended by the ADA Amendments Act, and all applicable state or local law. Navan will reasonably accommodate qualified individuals with a disability in connection with applications for employment as required by law. If you need any assistance or accommodations due to a disability, you are welcome to email us at [email protected] . Candidate Privacy Notice and Use of AI As part of the recruitment process, certain personal data may be processed using automated tools, including tools that use AI. For details on how Navan collects and uses your personal data, please review Navan's Candidate Privacy Notice here . Job Search Best Practices We have been made aware of recruitment scams involving fraudulent attempts to lure job seekers into sending money or personal information in return for fake job offers or coerce them into purchasing equipment by electronic funds transfer (Zelle, Venmo, etc.) Legitimate Navan recruiters will never ask for money in any recruitment or onboarding activities. All available job openings at Navan will be posted on Navan’s website and all Navan recruiters will be reachable through an email address ending in “@navan.com” or “@navan.tech” or "@talent.navan.com". *Applies to select locations. Product Business Travel Expense Management Advanced Analytics Navan Rewards Navan Events Sustainability Solutions Enterprises Small Business Accounting Teams Executive assistants Finance Teams Travel Managers Travelers By Industry Energy and Utilities Financial Services Food and Beverages Health and Wellness Industrial and Manufacturing Media and Entertainment Professional Services Real Estate and Construction Retail and Ecommerce Technology and Software Resources Guides Compare Us Blog Travel and Expense Glossary Per Diem Calculator Mileage Calculator Customers Case Studies Help Center Customer Resources End-User Resources Customer Reviews Company
About Us Partners Careers Contact Us 4.7 out of 5 | 9K+ reviews return ( ); Region France Germany Netherlands Spain United Kingdom United States Website Terms of Use Privacy Security Accessibility Statement Modern Slavery Statement Status Your Privacy Choices © 2026 Navan The Navan card is issued by Celtic Bank (Member FDIC), Stripe Technology Europe Limited, Stripe Payments UK Limited, Adyen N.V. (EU), Adyen N.V. San Francisco Branch (US), and Adyen N.V. London Branch (UK) About Navan Navan is the global AI-powered business travel and expense management platform that makes travel easy for frequent travelers. powering travel programs at more than 10,000 companies, including Canva , HelloFresh , DoorDash, Duolingo , and Steelcase. The platform simplifies travel, payments, and expense management with intuitive tools for booking, automated payments with built-in virtual cards, and seamless expense reporting. Navan delivers exceptional customer satisfaction , with a 96% CSAT and 43 NPS. Founded in 2015 by Ariel Cohen and Ilan Twig as TripActions, Navan reported $613M in LTM revenue and $7.6B in LTM gross booking volume, each for the twelve months ended July 31, 2025. The company aims to empower organizations worldwide to make corporate travel smarter and more efficient. Learn more at navan.com . Product Business Travel Expense Management Advanced Analytics Navan Rewards Navan Events Sustainability Solutions Enterprises Small Business Accounting Teams Executive assistants Finance Teams Travel Managers Travelers By Industry Energy and Utilities Financial Services Food and Beverages Health and Wellness Industrial and Manufacturing Media and Entertainment Professional Services Real Estate and Construction Retail and Ecommerce Technology and Software Resources Guides Compare Us Blog Travel and Expense Glossary Per Diem Calculator Mileage Calculator Customers Case Studies Help Center Customer Resources End-User Resources Customer Reviews Company
About Us Partners Careers Contact Us 4.7 out of 5 | 9K+ reviews return ( ); Region France Germany Netherlands Spain United Kingdom United States Website Terms of Use Privacy Security Accessibility Statement Modern Slavery Statement Status Your Privacy Choices © 2026 Navan The Navan card is issued by Celtic Bank (Member FDIC), Stripe Technology Europe Limited, Stripe Payments UK Limited, Adyen N.V. (EU), Adyen N.V. San Francisco Branch (US), and Adyen N.V. London Branch (UK) About Navan Navan is the global AI-powered business travel and expense management platform that makes travel easy for frequent travelers. powering travel programs at more than 10,000 companies, including Canva , HelloFresh , DoorDash, Duolingo , and Steelcase. The platform simplifies travel, payments, and expense management with intuitive tools for booking, automated payments with built-in virtual cards, and seamless expense reporting. Navan delivers exceptional customer satisfaction , with a 96% CSAT and 43 NPS. Founded in 2015 by Ariel Cohen and Ilan Twig as TripActions, Navan reported $613M in LTM revenue and $7.6B in LTM gross booking volume, each for the twelve months ended July 31, 2025. The company aims to empower organizations worldwide to make corporate travel smarter and more efficient. Learn more at navan.com .
Salary
$131,025 - $291,300
Location
Palo Alto, CA
Experience
8+ years
Total raised
$1.6B
Last stage
Public
Investors
Ilan Twig
Co-Founder & CTO
No applications, no recruiter spam. Just the intro.
A few questions to make sure this role is the right shape for you. Two minutes.
I write the intro, send it to the founder, and handle the back-and-forth.
If they’re a yes, I book the chat. You show up — that’s the whole job-hunt.