Senior Security Assurance Analyst

Lyft

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
New York, NY
Salary
$148,000–$185,000 / yr
Posted
36 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $167k
This role $166k
$120k most similar roles pay here $209k

This role pays more than 52% of similar roles. Most pay $137,187–$197,775 — the shaded band above. At the midpoint, this role pays about $166k versus about $167k for comparable roles.

Based on 240 similar postings.

Employer

About Lyft

Lyft is a transportation network company offering ride-hailing services across the US and Canada.

Lyft currently has 22 open roles on FindRole.

Listed pay typically runs $140,800–$176,000 across 16 roles with salary data.

Most-posted roles

View all roles at Lyft

At a glance

TL;DR · Senior Security Assurance Analyst

As a Senior Security Assurance Analyst on the Customer Trust team, you will manage a complex portfolio of multi-program compliance efforts to ensure data protection across global markets. You will own the ISO 27001 program end-to-end while driving execution for SOC 2, PCI DSS, HIPAA, and NIST CSF. Your daily responsibilities include managing relationships with external auditors, developing information security policies, and conducting risk management activities. You will collaborate with Engineering, Legal, and Sales teams to translate technical risks into actionable guidance and review security provisions in customer contracts. To scale operations, you will utilize Jira, Confluence, SafeBase, and GRC platforms like AuditBoard CrossComply or Vanta. Additionally, you will leverage AI tools and LLM-based workflows to automate evidence collection and control testing while addressing complex regulatory requirements such as NIS2 and the Cyber Resilience Act.

What you'll do

  • Lead the end-to-end ISO 27001 compliance program including certification planning, internal audits, and surveillance cycles.
  • Manage a multi-program compliance portfolio including SOC 2, PCI DSS, HIPAA, NIST CSF, and various international regulations.
  • Serve as the primary liaison to external auditors and certification bodies throughout the full audit lifecycle.
  • Manage the Security Risk Management Framework to ensure risk identification, treatment, and reporting across the business.
  • Develop, review, and maintain internal information security and data protection policies and procedures.
  • Partner with Engineering to design and implement automated evidence collection and continuous control testing.
  • Utilize AI tools and LLM-based workflows to automate compliance processes, policy drafting, and questionnaire responses.
  • Manage customer security questionnaires and oversee the company's external trust center platform.

What we're looking for

  • 5+ years of experience in security governance, risk, and compliance (GRC), IT audit, or a related security assurance role.
  • 5+ years of hands-on experience with ISO 27001 and PCI DSS.
  • In-depth knowledge of SOC 2, HIPAA, NIST CSF, and international frameworks like UK Cyber Essentials and NIS2.
  • Experience managing, reviewing, and drafting information security policies and procedures.
  • Strong technical background with the ability to communicate and negotiate effectively with engineering teams.
  • Experience with GRC platforms (e.g., AuditBoard CrossComply, Vanta, or Drata), Jira, and SafeBase (preferred).
  • Relevant certifications such as CISA, CISSP, CISM, CRISC, or ISO 27001 Lead Auditor/Implementer (preferred).
  • Big 4 or Big 3 consulting experience (preferred).

More like this

Similar roles

GRC Engineer

Apex

Austin, TX +6 19 days ago
SOC 2 NIST CSF ISO 27001 PCI DSS GLBA SQL Python API Anecdotes Vanta Drata Secureframe OneTrust ServiceNow GRC AWS Azure GCP IAM SIEM
2+ yrs exp Hybrid

Senior Security Analyst

Microsoft

26 days ago $119,800$234,700
Kusto SQL Azure M365 Sentinel Defender XDR MITRE ATT&CK SIEM GitHub Actions Entra ID Threat Hunting Root Cause Analysis Forensics Reverse Engineering AI Copilot
4+ yrs exp Hybrid

Senior Security Assurance Engineer

GitLab

Remote 12 days ago $139,200$196,000
SOX ITGC SOC 2 ISO 27001 NIST CSF PCI-DSS ISO 42001 SSO SCIM RBAC GitLab SaaS AI Governance GRC
5+ yrs exp Remote

Senior SAP Security Analyst

Abbott

Madison, WI 13 days ago $78,000$156,000
SAP SAP GRC Fiori OData SaaS Microsoft Office SOD Risk Analysis and Remediation Compliant User Provisioning Superuser Privilege Management Emergency Access Management SAC Datasphere IBP IAS/IPS
5+ yrs exp

Senior Cybersecurity Analyst

Leidos

Fort George G. Meade, MD 4 days ago $131,300$237,350
Azure AWS Google Cloud VMware Oracle Cisco IaaS PaaS ITIL 4 SAFe Agile Scrum CISSP CISM PMP Data Centers Network Architecture
10+ yrs exp