Jobs · Legal · California

Security Compliance Analyst

Harbinger · Garden Grove, CA · Today
Legal$130k–$160k/yrContract

About Harbinger

Harbinger is an American commercial electric vehicle (EV) company on a mission to transform an industry starving for innovation. Harbinger’s best-in-class team of EV, battery, and drivetrain experts have pooled their deep experience to bring a first-of-its-kind EV platform to support the growing demand for medium-duty EVs and Hybrids.

Role Summary

Harbinger is hiring a Security Compliance Analyst to build and own our security compliance program end to end. This is a hands-on, builder role: we're looking for someone who has already taken a compliance framework from gap assessment through an external audit and wants to do it again somewhere the program doesn't exist yet. You'll own the control set, the evidence behind it, the policies that describe it, and the tooling that holds it together. You'll grow into our expanding compliance scope as that work emerges with new business opportunities.

Who You Are

  • Educational & Experience: Bachelor's degree in Information Systems, Cybersecurity, or related field (or equivalent experience). 5+ years in security compliance, GRC, or IT audit, including at least one framework taken from gap assessment through an external audit report or certification.
  • Experience: Experience in a startup or high-growth environment building a program rather than maintained one.
  • Security Certifications: Security certifications (e.g. CISA, CRISC, CompTIA Security+, ISO 27001 Lead Auditor) are a plus.

Technical Competencies

  • Hands-on ownership of SOC 2 Type II and/or ISO/IEC 27001.
  • Able to translate controls to other frameworks and compliance needs across all business units.
  • Experience with a certification audit where the outcome is pass or fail against a fixed control catalog, not an opinion accompanied by a management response.
  • Familiarity with NIST-based control catalogs, mapping between overlapping frameworks, and the handling and storage controls that attach to restricted or contractually protected data.
  • Experience defining a system boundary and defending the scoping decision to an external assessor.
  • Experience with evidence and audit management: you can describe an evidence chain end to end: what artifact, generated how, refreshed how often, who attests.
  • Experience with GRC platform administration in Vanta configuring mappings and integrations.
  • Scripting ability (e.g. Python or JavaScript) is a plus.

Soft Skills

  • Strong written and verbal communication; able to translate control requirements into concrete changes an engineer can act on.
  • Comfortable influencing teams that don't report to you, and staying with a position when the answer needs to be no.
  • Comfortable working cross-functionally in a fast-paced, high-growth manufacturing environment.
  • Documentation discipline: if it isn't written down, it didn't happen.

Similar jobs