Senior Security & Compliance Analyst
HeadspaceAbout the role
<p><strong>About the </strong><strong>Senior Security & Compliance Analyst</strong><strong> at Headspace:</strong></p> <p><strong>What you will do:</strong></p> <ul> <li>Interact closely with other cyber security architects, privacy officer, general counsel, engineering, and product management teams to ensure adequate security capabilities and controls are in place within the technology stack to mitigate security risks and meet the highest security and compliance requirements. </li> <li>Work closely with prospects and the proposal managers to provide detailed responses to security assessment questionnaires. </li> <li>Continuously research, design, advocate and recommend new security technologies, architectures, and products that will ensure meeting all compliance requirements. </li> <li>Function as the go-to individual with in-depth understanding of all security and compliance related nuances within the Headspace Health stack. </li> <li>Develop the ability to effectively navigate a highly complex environment to independently retrieve technical evidence for gaining assurance over the effectiveness of controls. </li> <li>Serve as the subject matter expert who will actively guide the broader risk and compliance team on all security-related technical components within the environment. </li> <li>Conduct ad-hoc security architecture/application reviews to assess new risks, keep abreast of latest cyber security technical risks, and foster a culture of continuous service improvement and service excellence. Pre-audit analysis, strategic product analysis, diligence for components/technologies under review. </li> <li>Support for product testing in the course of audit and provide the post-audit analysis and assessment. </li> <li>Telecommuting permitted pursuant to company policy.</li> </ul> <p><strong>What you will bring</strong>:</p> <p><strong>Required Skills:</strong></p> <ul> <li>Education Requirements: Bachelor’s degree or foreign equivalent in Computer Engineering, Management Information Systems, Cybersecurity or related field.</li> <li>Experience Requirements: Two (2) years of experience in the position offered, as a Security Analyst or related occupation.</li> <li>Must have experience with the following: industry security compliance frameworks and regulations (ISO 27001/2, PCI-DSS, HIPAA, GDPR, FedRAMP, HITRUST, SOC 1, SOC 2, and international privacy requirements; cloud security concepts (DevSecOps, Infrastructure as Code (IaC), Continuous Integration/Continuous Deployment (CI/CD), Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST)); agile se
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s