Security Compliance Analyst
Harbinger Motors • Garden Grove, CA • Full Time • $130,000–$160,000 / year
Posted on Thu, Aug 27, 2026
About Harbinger
Harbinger is an American commercial electric vehicle (EV) company on a mission to transform an industry starving for innovation. Harbinger’s best-in-class team of EV, battery, and drivetrain experts have pooled their deep experience to bring a first-of-its-kind EV platform to support the growing demand for medium-duty EVs and Hybrids. Harbinger: Familiar Form, Revolutionary Foundation.
Role Summary
Harbinger is hiring a Security Compliance Analyst to build and own our security compliance program end to end. This is a hands-on, builder role: we're looking for someone who has already taken a compliance framework from gap assessment through an external audit and wants to do it again somewhere the program doesn't exist yet. You'll own the control set, the evidence behind it, the policies that describe it, and the tooling that holds it together. You'll grow into our expanding compliance scope as that work emerges with new business opportunities.
What You'll Do:
Compliance Frameworks & Controls
- Own the control catalog: implementation status, testing, evidence requirements, and crosswalks where frameworks overlap.
- Translate control requirements into specific, actionable changes for teams to implement, then verify they landed.
- Maintain the corrective action plan; open findings with named owners, real dates, and a defined evidence bar for closure partnering with program management on execution.
Audit & Evidence Management
- Run evidence collection on a standing cadence, building automations so evidence becomes a byproduct of normal operations rather than a quarterly scramble.
- Prepare for and support external audits and certification assessments: readiness reviews, sample pulls, auditor walkthroughs, and remediation of findings.
- Define and document our system boundary and scope decisions: what's in, what's deliberately out, and reasoning that holds up under an assessor's questions.
Policy, Governance & Tooling
- Write and maintain the policy and procedure set. Short enough that engineers read it, specific enough that an auditor accepts it.
- Administer our GRC platform Vanta, including control mappings, integrations, framework crosswalks, and evidence freshness
- Support role-based security awareness training and data handling guidance
Third-Party Risk & Cross-Functional
- Run vendor and third-party security reviews, including cloud services and the security requirements we flow down to suppliers.
- Document control decisions, scope rationale, and audit outcomes in Jira or Confluence so the program is maintainable by others.
- Report compliance posture and audit readiness to security leadership on a regular cadence.
Who You Are:
Education & Experience
- Bachelor's degree in Information Systems, Cybersecurity, or related field (or equivalent experience).
- 5+ years in security compliance, GRC, or IT audit, including at least one framework taken from gap assessment through an external audit report or certification.
- Experience in a startup or high-growth environment building a program rather than maintained one.
- Security certifications (e.g. CISA, CRISC, CompTIA Security+, ISO 27001 Lead Auditor) are a plus.
Technical Competencies
- Hands-on ownership of SOC 2 Type II and/or ISO/IEC 27001. Able to translate controls to other frameworks and compliance needs across all business units.
- Experience with a certification audit where the outcome is pass or fail against a fixed control catalog, not an opinion accompanied by a management response.
- Experience defining a system boundary and defending the scoping decision to an external assessor.
- Familiarity with NIST-based control catalogs, mapping between overlapping frameworks, and the handling and storage controls that attach to restricted or contractually protected data.
- Evidence and audit management: you can describe an evidence chain end to end: what artifact, generated how, refreshed how often, who attests.
- GRC platform administration in Vanta configuring mappings and integrations.
- Working in collaboration platforms like Confluence or Jira.
- Scripting ability (e.g. Python or JavaScript) is a plus.
Soft Skills
- Strong written and verbal communication; able to translate control requirements into concrete changes an engineer can act on.
- Comfortable influencing teams that don't report to you, and staying with a position when the answer needs to be no.
- Comfortable working cross-functionally in a fast-paced, high-growth manufacturing environment.
- Documentation discipline: if it isn't written down, it didn't happen.
- Comprehensive Health, Dental & Vision (HDV) – 100% employee covered
- Early-stage Stock Options
- Robust Retirement Savings (401k, HSA, FSA)
- Generous Paid Time Off (PTO) & Parental Leave
- Annual Vacation Bonus
- Wellness & Fertility Benefits
- Cell Phone Stipend
- Complimentary Meals & Stocked Kitchens
More live compliance_analyst roles
- Compliance Analyst at Modulr — Amsterdam, United States
- Compliance Analyst - Local to NY/NJ at Nexiva — Jersey City, New Jersey, United States
- Senior or Lead Compliance Analyst at Deriva Energy (Remote)
- Cybersecurity Compliance Analyst at Saxon Global — Connecticut, United States
- Compliance Analyst Summer Internship Program Whippany at Barclays — Whippany, New Jersey, United States
- Compliance Analyst Summer Internship Program New York at Barclays — New York, United States
- Compliance Analyst or Manager at Finvari — Seattle, Washington, United States
- Sr. Compliance Analyst at Aspida Financial Services — Durham, North Carolina, United States
- Experienced or Senior Supply Chain Compliance Analyst - Self Governance & Compliance at Boeing — Dallas, Texas, United States
- Procurement Compliance Analyst/Specialist at CACI (Remote)
- Principal Regulatory Compliance Analyst at Northrop Grumman — Linthicum, Maryland, United States
- Risk and Compliance Analyst at 9th Way Insignia (Remote)
- Security & Compliance Analyst at KSN Technologies. — Lansing, Michigan, United States
- Data Quality & Compliance Analyst at City and County of Denver — United States
- Senior Compliance Analyst at Brighthouse Financial (Remote)
- Corporate Quality Compliance Analyst at Novolex — United States
- Compliance Analyst at Boston Partners Global Investors — Boston, Massachusetts, US
- Jr. Compliance Analyst at Hab Bank — New York, New York, US
- Junior Compliance Analyst at Hab Bank — New York, New York, United States
- Compliance Analyst - Policies & Procedures at Austal — Mobile, Alabama, US
- Trade Compliance Analyst II at Solstice Advanced Materials — Morris Plains, New Jersey, US
- Compliance Analyst at Amivero (Remote)
- SR. Payroll & HR Compliance Analyst at Nienhuis Financial Group — North Kansas City, MO, United States
- SR. Payroll & HR Compliance Analyst — North Kansas City, Missouri, United States
- Senior Payroll & HR Compliance Analyst — North Kansas City, Missouri, United States
- Lease Compliance Analyst at Foot Locker — Camp Hill, Pennsylvania, United States
- Lease Compliance Analyst (Hybrid) at Foot Locker — Camp Hill, PA, US
- Controlled Research Compliance Analyst, Office of Research Support and Compliance at The University of Texas at Austin — Austin, Texas, United States
- Controlled Research Compliance Analyst at The University of Texas at Austin — Austin, TX, US
- Healthcare Compliance Analyst - Turkish Speaking at Roche — Budapest
- 2027 Compliance Analyst Summer Internship Program Whippany at Barclays — Building 400-Whippany Campus, Jefferson Park
- Compliance Analyst - Broker Dealer at Cetera Financial Group — Dallas, TX, United States
- Erp Controls & Compliance Analyst at Teledyne Technologies — 5 Locations
- Healthcare Compliance Analyst - Polish Speaking at Roche — Budapest
- 2027 Compliance Analyst Summer Internship Program New York at Barclays — New York, 745 7th Avenue
- Senior Compliance Analyst - Life & Health Insurance Fraud Investigations - Hybrid at Transamerica — 4 Locations
- Senior Executive - Quality Compliance Analyst at EXL — Gurugram, Haryana, India
- Sr Trade Compliance Analyst at Honeywell Aerospace — Bengaluru, Karnataka, India
- Senior HRIS & Compliance Analyst at The University of Alabama in Huntsville — Alabama, United States
- Compliance Analyst (Fixed Term) at Irving Oil — Saint John, New Brunswick, Canada
- Pricing Governance & Compliance Analyst at Careers and Highline Warren — Lisle, Illinois, United States
- Supply Chain Compliance Analyst at GM (Remote)
- Credentialing Compliance Analyst at Cooper University Hospital — Camden, New Jersey, United States
- Governance Risk & Compliance Analyst at Nelson Mullins Riley & Scarborough — Columbia, South Carolina, United States
- Senior Federal Compliance Analyst at Horizon3 (Remote)