SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Lucid Software is seeking a Security Analyst to protect corporate assets, web applications, and employees through governance, risk, and compliance (GRC) operations. This hybrid role is based in Salt Lake City and focuses on day-to-day security execution, third-party risk management, and customer trust.
Key responsibilities include conducting third-party vendor risk assessments and internal risk evaluations to identify vulnerabilities and control gaps. You will respond to vendor security questionnaires, support internal teams (Sales, Customer Success) with security inquiries from prospects, and track evidence for SOC 2 and ISO 27001 compliance audits. The role requires proactively identifying emerging threats, collaborating with senior team members on security solutions, and coordinating security awareness training programs.
You will assure compliance with external regulations, collect security and compliance metrics for dashboards, and partner cross-functionally with Legal, Engineering, IT, Finance, and HR to ensure security policies are understood and followed. The position also involves identifying operational inefficiencies in existing security controls and designing improved workflows.
Required qualifications include a Bachelor's degree in information security assurance, business management, or related field, plus 3+ years of experience in third-party risk management, GRC, or customer due diligence. You must understand common security frameworks (NIST 800-53, ISO 27001, SOC 2) and demonstrate strong organizational, verbal, and written communication skills. Excellent interpersonal abilities are essential for collaborating across technical and non-technical teams.
Preferred qualifications include experience in modern SaaS or cloud-first technology companies, knowledge of risk management principles, relevant certifications (CRISC, CISSP, CISA, SSCP, CC, Security+, CySA+), understanding of cloud environments (AWS, GCP, Azure), and experience with process improvement and GRC automation using AI tools.