Security and Compliance Analyst II

 Posted an hour ago
  
 Canada
  
 78000 - 114K per year
  
⭐ 2-5 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

The Security and Compliance Analyst will manage weekly security reviews, vulnerability scanning, and audit evidence collection for a health research data platform. They will also lead AI governance execution and support the company's efforts to achieve SOC 2 Type 2 and NIST 800-53 certifications.

About Lasso Informatics

Research data is wild. It pours in from brain scans, genome sequencing, EEG and eye-tracking, biospecimens and wearables that track sleep and movement, across dozens of sites and years of study. Lasso Informatics ropes it in: our platform pulls it all into one place so researchers around the world can stop fighting with their data and get to discoveries faster.

That is where our name comes from. A lasso brings something wild under control, and that is the job. The people who do it are Wranglers, and we are quite choosy about who earns the title. Wranglers expect a lot of themselves, make everyone around them better, and never stop learning. We move fast, we have fun, and we keep the bar high.

About the Role

As a Security and Compliance Analyst at Lasso, you own the weekly security and compliance work behind a health research data platform running on AWS and Google Cloud. You review cloud and identity logs, triage vulnerabilities, keep our audit evidence current in Vanta, and help take the company through SOC 2 Type 2. You also run Lasso's AI governance execution work. This position sits under the Manager of Security, Compliance and DevOps, with oversight from the CTO, COO and CEO as appropriate.

We are a HIPAA Business Associate running to a NIST 800-53 Moderate control baseline, and a federal sponsor checks our work continuously. The security team is one person today. You would be the second, and getting us certified is a real piece of the job, not a side project. As the role matures, this person may be designated Information System Security Officer (ISSO) for our NIST 800-53 authorization boundary, working under the Security Officer

What You'll Do

  • Run the weekly security review: audit logs across our cloud and identity systems, then vulnerability scan results, written up and published, with tickets opened for anything that needs action.

  • Keep Vanta healthy: failing tests, evidence collection, document gaps, policy acceptances and vendor security assessments.

  • Maintain our remediation tracker. Chase owners and flag items before they go late.

  • Run quarterly access reviews and third-party risk work, including customer security questionnaires.

  • Support incidents: gather facts, build the timeline, keep the tracker and draft the notification. Escalation calls stay with the Security Officer.

  • Help get us certified. Gap assessment through observation window through audit, roughly a third of the role.

  • Run AI governance execution: build and quarterly-refresh the AI systems and agent inventory, and produce the shadow-AI discovery report from our identity, endpoint and monitoring data. Roughly 3 hours a week in year one, less after that. This work sits under Ian, with oversight from the CTO, COO and CEO as appropriate.

Qualifications

Required

  • Three or more years in security, compliance, audit, information technology or systems administration, where you produced evidence that someone else then inspected.

  • A current CompTIA Security+, SSCP, GSEC, CySA+ or CISA. Mid-study with a confirmed test date works too, tell us.

  • You can read logs and tell a real problem from noise. Not detection engineering: looking at a week of sign-in activity and deciding what deserves a ticket.

  • Writing that holds up: clear, plain, dated and specific. We test this with a short take-home exercise.


We will teach you Vanta, the frameworks (HIPAA, NIST 800-53, SOC 2, ISO 27001), read-only evidence work in AWS and Google Cloud, Microsoft Entra ID and Intune, Jira and Confluence, and Splunk as we stand it up this year. Almost nobody arrives knowing all of it.

Preferred

  • Time on the inside of a SOC 2 Type 2 or ISO/IEC 27001 certification, on the company's side of the audit rather than the auditor's.

  • HIPAA as a Business Associate, or NIST 800-53 or FedRAMP evidence work.

  • Vulnerability management and patch deadline tracking.

  • Experience with endpoint or awareness tooling such as CrowdStrike Falcon or KnowBe4.

  • Exposure to AI governance or AI risk work: tool or vendor risk assessment, model inventories, or supporting an AI use policy.

You do not need a degree, a security clearance, coding experience, an on-call rotation, production access, or a prior job title with the word "compliance" in it. Hands-on experience substitutes for a degree in full. Some of our strongest candidates will be systems administrators moving into security, security operations analysts who have never done compliance, or the person at a hospital, credit union or lab who ended up answering the auditor without ever being given the title.

Want to Be a Wrangler? Here's What We Look For

  • You hold yourself to a high standard and bring real rigor to your work.

  • You make the people around you better.

  • You stay curious and keep learning.

  • You see a problem and start solving it, without waiting to be asked.

  • You keep the whole picture in view and notice how a change in one place ripples through the evidence, the tracker and the audit.

  • You write clearly and document your findings with precision.

  • You take data privacy and responsible stewardship seriously, every time.

What We Offer

  • A flexible, remote-friendly position with hours overlapping North American Eastern time.

  • Group benefits plan (Lasso pays 100%).

  • Group retirement savings plan with a 2% employer match.

  • A professional development budget.

  • Written procedures for every recurring duty, and a manager who does this work today and will run the first cycles alongside you.

  • Work that matters: protecting the data behind a health research platform that scientists depend on.

  • The range and pace of a start-up: broad scope, fast decisions and impact you can see.

Similar Jobs

See all Remote Legal jobs β†’

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Compliance Analyst

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified