Security Compliance Analyst

San Francisco, CA
Engineering
Full-time

About the Role:
PlanGrid is used on thousands of construction projects (including hospitals, government buildings, universities, utility plants, etc.), and we must do everything in our power to keep our 40M+ blueprints secure for our customers. The Security Compliance Analyst will be a key member of a growing Information Security team responsible for coordination of security certification audits, control definitions, policy creation and security and awareness training. Success in this role requires a good understanding of information security best practices, ability to understand and communicate risk and controls, organization, planning, good communication and writing skills.

Responsibilities:
- Lead coordinator of all information technology and security related audits for compliance standards
- Monitor the measurement and review of internal processes, especially those that affect the quality of the organization's services
- Manage 3rd Party Vendor Risk Assessments
- Performs and/or oversees the performance of periodic risk assessments that identify current and future internal and external information security risks, provides necessary information to derive decisions about risk acceptance and risk mitigation, and identifies strategies to reduce information security risks
- Provides guidance and subject matter expertise on processes, controls and objectives around audit and information security activities, best practices and process improvement, and manages assessment reporting and remediation activities
- Maintains Information Security Policy and Standards documentation
- Supports daily operational security activities such as responses to client inquiries regarding the information security program as required.

Required Skills:
- Strong knowledge of applicable compliance/risk concepts and methodologies
- Strong collaborative and influencing skills
- Strong program management, project management, and execution and delivery oversight
- Attention to detail around controls, metrics, accountability and operational excellence
- Strong understanding of information security audit standards and best practices

Qualifications:
- Minimum of 3-4 years of experience in regulatory compliance, risk management and/or audit roles or technology governance
- Excellent communication, organizational and writing skills
- Ability to develop and manage multiple activities
- Ability to explain technical or complex analysis to non-technical individuals
- A self-starter with the desire to drive change and engage in building a program
- Experience with compliance requirements/standards such as ISO, SOC, FedRAMP, GDPR and Safe Harbor / Privacy Shield.




About PlanGrid:
PlanGrid solves a major problem for a 7,000 year old industry. Construction data is shackled in legacy, paper blueprints that are clunky, heavy to carry, and result in enormous rework costs totaling $9 billion per year for the industry due to working from outdated plans. 

PlanGrid was built by builders, for builders. We’re spearheading the industry’s transformation to the cloud and digitization by arming construction workers with the best productivity tools. Contractors, owners, designers, and architects worldwide maximize PlanGrid to finish their projects on time and under budget. PlanGrid currently stores over 50 million blueprints, making us the largest digital blueprint repository in the world. We emerged from Y Combinator in 2012, and have secured over $62 million in funding from world-renowned organizations and individuals including Sequoia, Founders Fund, GV, 500 Startups, Box, Northgate, Spectrum 28, and Tenaya Capital.

Perks:
- Located in San Francisco’s Mission District just one block from BART, among local shops, bars, and restaurants
- Flexible vacation
- Dog-friendly office
- Clipper Cards (for public transportation) funded by PlanGrid
- Construction site tours of the biggest projects in San Francisco using PlanGrid
- Volunteer time off: We encourage employees to give back to our local communities. We organize volunteer days and have worked with organizations such as Glide, SF/Marin Food Bank, Muttville, Family Dog Rescue, and Bryant Elementary School (as part of PlanGrid’s commitment with Circle the Schools). 
- Catered lunches
- Premium medical, dental, and vision coverage for full-time employees and their dependents
- 401k
- Equity
- Office is wheelchair accessible