Back to jobs

Sr. Security Assurance Analyst

Salt Lake City, UT

Lucid Software is the leader in visual collaboration, helping teams see and build the future from idea to reality. We hold true to our core values: innovation in everything we do, passion & excellence in every area, individual empowerment, initiative and ownership, and teamwork over ego. At Lucid, we value diversity and are dedicated to creating an environment and culture that is respectful and inclusive for everyone. Lucid is a hybrid workplace. We promote a healthy work-life balance by allowing employees to work remotely, from one of our offices, or a combination of the two depending on the needs of the role and team.

Since the company’s founding, Lucid Software has received numerous global and regional recognitions for its products, business, and workplace culture. These include being named a Fortune Best Workplace in Technology and a 2022 Glassdoor Best Place to Work, inclusion on the Forbes Cloud 100, and ranking in the top 100 on G2’s 2023 Best Global Software Companies. Top businesses use our products all around the world, including customers such as Google, GE, and NBC Universal. Our partners include industry leaders such as Google, Atlassian, and Microsoft. 

As a Senior Security Assurance Analyst at Lucid, you will leverage your cybersecurity knowledge and expertise to protect corporate information assets, demonstrate compliance with industry frameworks, and promote confidence in Lucid’s security program both internally and externally. Your role will include managing vulnerabilities and handling risks to effectively safeguard customer data and corporate assets. Through your proactive approach in risk identification and risk management, you'll contribute significantly to Lucid's mission of secure and responsible innovation, ensuring the trust our customers have in us is both well-placed and consistently maintained.

Responsibilities:

  • Maintain state, federal, and international compliance documentation and control compliance (e.g. FedRAMP, StateRAMP, IRAP, etc).
  • Perform risk assessments, document results, and provide detailed updates to stakeholders through risk related security metrics.
  • Proactively identify threats and associated risks to existing processes and assets and help develop solutions.
  • Implement and enhance compliance programs and routines.
  • Assures compliance to outside regulations affecting the Company.
  • Execute end to end compliance initiatives Work with other teams such as Legal, Engineering, IT, Finance, and HR to maintain evidence playbooks for audits.
  • Identify opportunities for efficiencies, as well as for improvements in security controls while leading the design and implementation of related improvements.
  • Identify and report on possible security risks identified from third party assessments, vulnerability scans, and internal risk discussions.
  • Mentoring junior team members and contributing to the development of the security team’s skills and capabilities.
  • Manage specific Plans of Action and Milestones (POA&Ms).

Requirements:

  • 3+ years working in governance, risk, and compliance; including risk and vulnerability management
  • Understanding of common security frameworks and principles (e.g. NIST 800-53, ISO 27001, SOC 2, etc).
  • Understanding of common risk analysis methodologies (e.g. OCTAVE, FAIR, NIST 800-30).
  • Practical audit management experience (auditor-facing and customer-facing).
  • Ability to independently and proactively manage tasks to meet deadlines.
  • Excellent verbal and written skills with great attention to details.
  • Able to work effectively across several different internal teams.
  • Ability to communicate technical concepts in simple and concise language.

Preferred Qualifications:

  • Knowledge of FedRAMP security controls and compliance processes
  • Preferred Certification: CISA, CISM, and/ or CISSP
  • Bachelor’s degree in information security assurance, business management, or a related field
  • Experience in risk management, threat modeling, and vulnerability management.
  • Can thrive working in a fast-paced, start-up-like environment
  • Demonstrated ability in strategic planning for security initiatives.
  • Experience working with a Third-party Assessment Organization (3PAO) and the FedRAMP PMO, to achieve agency authorization. Including the interpretation and implementation of a Security Assessment Plan (SAP)
  • Familiarity with Project Management tools, such as Smartsheet & Jira.
  • Experience working with Qualys.
  • Experience conducting Security Impact Analyses

#LI_MK1

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Lucid Software’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.