
Security Compliance Analyst
About Harbinger
Harbinger is an American commercial electric vehicle (EV) company on a mission to transform an industry starving for innovation. Harbinger’s best-in-class team of EV, battery, and drivetrain experts have pooled their deep experience to bring a first-of-its-kind EV platform to support the growing demand for medium-duty EVs and Hybrids. Harbinger: Familiar Form, Revolutionary Foundation.
Role Summary
Harbinger is hiring a Security Compliance Analyst to build and own our security compliance program end to end. This is a hands-on, builder role: we're looking for someone who has already taken a compliance framework from gap assessment through an external audit and wants to do it again somewhere the program doesn't exist yet. You'll own the control set, the evidence behind it, the policies that describe it, and the tooling that holds it together. You'll grow into our expanding compliance scope as that work emerges with new business opportunities.
What You'll Do:
Compliance Frameworks & Controls
- Own the control catalog: implementation status, testing, evidence requirements, and crosswalks where frameworks overlap.
- Translate control requirements into specific, actionable changes for teams to implement, then verify they landed.
- Maintain the corrective action plan; open findings with named owners, real dates, and a defined evidence bar for closure partnering with program management on execution.
Audit & Evidence Management
- Run evidence collection on a standing cadence, building automations so evidence becomes a byproduct of normal operations rather than a quarterly scramble.
- Prepare for and support external audits and certification assessments: readiness reviews, sample pulls, auditor walkthroughs, and remediation of findings.
- Define and document our system boundary and scope decisions: what's in, what's deliberately out, and reasoning that holds up under an assessor's questions.
Policy, Governance & Tooling
- Write and maintain the policy and procedure set. Short enough that engineers read it, specific enough that an auditor accepts it.
- Administer our GRC platform Vanta, including control mappings, integrations, framework crosswalks, and evidence freshness
- Support role-based security awareness training and data handling guidance
Third-Party Risk & Cross-Functional
- Run vendor and third-party security reviews, including cloud services and the security requirements we flow down to suppliers.
- Document control decisions, scope rationale, and audit outcomes in Jira or Confluence so the program is maintainable by others.
- Report compliance posture and audit readiness to security leadership on a regular cadence.
Who You Are:
Education & Experience
- Bachelor's degree in Information Systems, Cybersecurity, or related field (or equivalent experience).
- 5+ years in security compliance, GRC, or IT audit, including at least one framework taken from gap assessment through an external audit report or certification.
- Experience in a startup or high-growth environment building a program rather than maintained one.
- Security certifications (e.g. CISA, CRISC, CompTIA Security+, ISO 27001 Lead Auditor) are a plus.
Technical Competencies
- Hands-on ownership of SOC 2 Type II and/or ISO/IEC 27001. Able to translate controls to other frameworks and compliance needs across all business units.
- Experience with a certification audit where the outcome is pass or fail against a fixed control catalog, not an opinion accompanied by a management response.
- Experience defining a system boundary and defending the scoping decision to an external assessor.
- Familiarity with NIST-based control catalogs, mapping between overlapping frameworks, and the handling and storage controls that attach to restricted or contractually protected data.
- Evidence and audit management: you can describe an evidence chain end to end: what artifact, generated how, refreshed how often, who attests.
- GRC platform administration in Vanta configuring mappings and integrations.
- Working in collaboration platforms like Confluence or Jira.
- Scripting ability (e.g. Python or JavaScript) is a plus.
Soft Skills
- Strong written and verbal communication; able to translate control requirements into concrete changes an engineer can act on.
- Comfortable influencing teams that don't report to you, and staying with a position when the answer needs to be no.
- Comfortable working cross-functionally in a fast-paced, high-growth manufacturing environment.
- Documentation discipline: if it isn't written down, it didn't happen.
- Comprehensive Health, Dental & Vision (HDV) – 100% employee covered
- Early-stage Stock Options
- Robust Retirement Savings (401k, HSA, FSA)
- Generous Paid Time Off (PTO) & Parental Leave
- Annual Vacation Bonus
- Wellness & Fertility Benefits
- Cell Phone Stipend
- Complimentary Meals & Stocked Kitchens
California Pay Range
$130,000 - $160,000 USD
Apply for this job
*
indicates a required field