SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 130,000 - 160,000 / annual
Harbinger Motors is an American commercial electric vehicle (EV) company building medium-duty EVs and hybrids. The Security Compliance Analyst will build and own the company's security compliance program end-to-end, taking it from gap assessment through external audit and certification.
Key Responsibilities:
Compliance Frameworks & Controls: Own the control catalog including implementation status, testing, and evidence requirements. Translate control requirements into actionable changes for teams to implement and verify completion. Maintain the corrective action plan with named owners, real dates, and defined evidence closure criteria.
Audit & Evidence Management: Run evidence collection on a standing cadence, building automations so evidence becomes a byproduct of normal operations. Prepare for and support external audits and certification assessments including readiness reviews, sample pulls, auditor walkthroughs, and remediation. Define and document system boundary and scope decisions with reasoning that holds up under assessor scrutiny.
Policy, Governance & Tooling: Write and maintain the policy and procedure set—short enough for engineers to read, specific enough for auditors to accept. Administer the GRC platform Vanta, including control mappings, integrations, framework crosswalks, and evidence freshness. Support role-based security awareness training and data handling guidance.
Third-Party Risk & Cross-Functional: Run vendor and third-party security reviews, including cloud services and security requirements for suppliers. Document control decisions, scope rationale, and audit outcomes in Jira or Confluence for program maintainability. Report compliance posture and audit readiness to security leadership on a regular cadence.
This is a hands-on, builder role for someone who has already taken a compliance framework from gap assessment through external audit and wants to do it again in an environment where the program doesn't exist yet. You'll grow into expanding compliance scope as new business opportunities emerge.
REQUIREMENTS:
- Bachelor's degree in Information Systems, Cybersecurity, or related field (or equivalent experience)
- 5+ years in security compliance, GRC, or IT audit, including at least one framework taken from gap assessment through an external audit report or certification
- Experience in a startup or high-growth environment building a program rather than maintaining one
- Hands-on ownership of SOC 2 Type II and/or ISO/IEC 27001; able to translate controls to other frameworks
- Experience with a certification audit where the outcome is pass or fail against a fixed control catalog
- Experience defining a system boundary and defending scoping decisions to external assessors
- Familiarity with NIST-based control catalogs, framework mapping, and handling/storage controls for restricted or contractually protected data
- Evidence and audit management expertise: can describe an evidence chain end-to-end (artifact, generation, refresh cadence, attestation)
- GRC platform administration in Vanta (configuring mappings and integrations)
- Working proficiency in collaboration platforms like Confluence or Jira
- Strong written and verbal communication; able to translate control requirements into concrete engineering actions
- Comfortable influencing teams that don't report to you and maintaining positions when the answer is no
- Comfortable working cross-functionally in a fast-paced, high-growth manufacturing environment
- Documentation discipline
- Security certifications (e.g., CISA, CRISC, CompTIA Security+, ISO 27001 Lead Auditor) are a plus
- Scripting ability (e.g., Python or JavaScript) is a plus