1

Saq Jobs (NOW HIRING)

Staff Security Analyst

Palo Alto, CA · On-site

$72K - $96K/yr

Deep expertise in PCI DSS (all 12 requirements, SAQ types, ROC processes, compensating controls) * Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls ...

Senior DevSecOps Engineer

Boulder, CO · On-site +1

$118K - $162K/yr

SAQ completion, quarterly ASV scans, and disaster recovery implementation * Harden containerized and cloud-native environments, including image scanning and Kubernetes configuration * Coordinate pen ...

Support the completion of the Annual SAQ Audit and partner with the Executive Team to develop and implement corrective action plans to strengthen controls and ongoing compliance. * Other duties as ...

Support the completion of the Annual SAQ Audit and partner with the Executive Team to develop and implement corrective action plans to strengthen controls and ongoing compliance. * Other duties as ...

HSE&S Advisor

Columbus, OH · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Responsible for SAQ elements, PSM Building Blocks, KPI's report. Participation on BBS Program of the site. Participation on site internal and external audits, contributing with completion of actions ...

HSE&S Advisor

Columbus, OH

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Responsible for SAQ elements, PSM Building Blocks, KPI's report. Participation on BBS Program of the site. Participation on site internal and external audits, contributing with completion of actions ...

Senior DevSecOps Engineer

Boulder, CO · On-site +1

$118K - $162K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

SAQ completion, quarterly ASV scans, and disaster recovery implementation * Harden containerized and cloud-native environments, including image scanning and Kubernetes configuration * Coordinate pen ...

Showing results 41-54

Saq information

See salary details

$18.5K

$120.9K

$170.5K

How much do saq jobs pay per year?

As of Aug 18, 2026, the average yearly pay for saq in the United States is $120,872.00, according to ZipRecruiter salary data. Most workers in this role earn between $97,500.00 and $146,000.00 per year, depending on experience, location, and employer.

What are SaaS (Software as a Service) jobs?

SaaS (Software as a Service) jobs refer to roles involved in the development, management, sales, and support of cloud-based software applications that are delivered over the internet. These positions can include software engineers, product managers, customer success specialists, sales representatives, and technical support agents. SaaS professionals work for companies that provide software solutions as a subscription service, helping clients implement, use, and optimize these products. The field is fast-growing due to increasing demand for scalable and accessible software solutions across industries.

What are some common challenges faced by Security Assessment and Authorization (SAA or SAQ) professionals, and how can they be addressed?

Security Assessment and Authorization (SAQ) professionals often encounter challenges such as staying up-to-date with rapidly evolving compliance frameworks, coordinating with multiple stakeholders across departments, and managing tight deadlines for documentation and reporting. To address these challenges, it's important to maintain continuous education on regulatory changes, develop strong communication and project management skills, and leverage automated tools for tracking and reporting. Building collaborative relationships with IT, compliance, and business teams also helps streamline assessment processes and ensure timely completion of security authorizations.

What are the key skills and qualifications needed to thrive as a SAQ (store attendant/stock assistant), and why are they important?

To thrive as a SAQ (Store Attendant/Stock Assistant), you need strong organizational skills, attention to detail, and often a high school diploma or equivalent. Familiarity with inventory management systems, handheld scanners, and basic point-of-sale (POS) equipment is typically required. Excellent communication, teamwork, and reliability are standout soft skills for this role. These abilities are crucial for maintaining efficient store operations, accurate inventory tracking, and delivering good customer service.

What is the difference between Saq vs Sales Associate?

AspectSaqSales Associate
Required CredentialsHigh school diploma or equivalent; certification may be preferredHigh school diploma or equivalent; sales training often provided
Work EnvironmentRetail stores, warehouses, or distribution centersRetail stores, showrooms, or customer service settings
Employer & Industry UsageCommon in retail and logistics sectorsWidespread in retail, hospitality, and service industries
Common Search & ComparisonOften compared for entry-level retail rolesFrequently compared with Saq for retail sales positions

The main difference between Saq and Sales Associate lies in their specific roles within retail environments. Saq typically refers to roles focused on stock management and logistics, while Sales Associates primarily engage in customer service and sales. Both roles require similar credentials and are common in retail settings, but their responsibilities differ based on the focus of the job.

More about Saq jobs

What cities are hiring for Saq jobs?

Cities with the most Saq job openings:

What states have the most Saq jobs?

States with the most job openings for Saq jobs include:

Infographic showing various Saq job openings in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 78% Physical, 11% Hybrid, and 11% Remote job distribution, with an average salary of $120,872 per year, or $58.1 per hour.

Staff Security Analyst

Navan

Palo Alto, CA • On-site

$72K - $96K/yr

Full-time

Posted 19 days ago


Job description

We are looking for a Staff Security Analyst to take full ownership of our compliance architecture. You won't just maintain compliance-you'll scale and automate it to eliminate manual friction. In this role, you'll manage our Information Security Management System (ISMS), lead internal and external audits, and serve as the primary bridge between external regulators and our internal teams. If you excel at translating deep technical expertise into practical, automated solutions, this is your chance to shape our security ecosystem across the organization.

What You'll Do:

Compliance Program Leadership (Primary Focus)

  • Multi-Framework Compliance Management: Lead and execute compliance programs for PCI DSS, SOX (IT General Controls and Application Controls), ISO 27001, ISO 42001 (AI Management System), SOC 1 (Type I & II), and SOC 2 (Type I & II)
  • ISMS Operations: Run and continuously improve the Information Security Management System (ISMS), including risk treatment planning, internal audit programs, management reviews, and corrective action processes
  • Audit Coordination & Management: Serve as the primary point of contact for external auditors, manage audit schedules, define testing scopes, coordinate evidence requests, and facilitate audit readiness assessments
  • Risk Assessment & Adjustment: Perform risk assessments across controls, policies, and technical environments; conduct risk-adjusted analysis of control deficiencies and exceptions; develop risk treatment plans aligned with business objectives
  • Control Automation & Optimization: Partner with control owners across IT, Engineering, Finance, and Operations to identify automation opportunities; implement automated evidence collection, continuous control monitoring, and self-service compliance workflows
  • Regulatory Compliance Strategy: Monitor regulatory changes and emerging compliance requirements; assess applicability and impact; develop implementation roadmaps for new regulatory obligations

Control Framework & Testing

  • Control Owner Enablement: Work directly with technical and business control owners to design, implement, and automate security controls; provide guidance on control testing methodologies and evidence requirements
  • Control Testing Program: Establish and execute risk-based control testing schedules; perform detailed control testing including design effectiveness, operating effectiveness, and sampling methodologies
  • Gap Assessment & Remediation: Identify control gaps and deficiencies through testing and continuous monitoring; develop comprehensive remediation plans with clear timelines, ownership, and risk mitigation strategies
  • Evidence Management: Design and maintain centralized evidence repositories and compliance platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, or similar GRC tools); ensure evidence quality, completeness, and auditability

Governance, Policy & Documentation

  • Policy Development & Maintenance: Create, review, and maintain information security policies, standards, procedures, and guidelines aligned with regulatory requirements and industry best practices
  • Unified Control Framework (UCF): Develop and maintain control mapping across multiple frameworks to identify overlapping requirements and optimize control implementation
  • Documentation Governance: Oversee the complete lifecycle of compliance documentation from creation through approval, publication, and retirement; maintain version control and change tracking
  • Compliance Reporting: Prepare executive-level compliance status reports, risk dashboards, and KPI metrics; communicate compliance posture to senior management, board, and audit committees

Cross-Functional Collaboration & Stakeholder Management

  • Executive Communication: Articulate complex compliance requirements and risk scenarios to C-level executives, board members, and non-technical stakeholders
  • Cross-Functional Partnership: Collaborate closely with Engineering, IT, Finance, Legal, People Ops, and Business Units to bridge control gaps and implement compliance solutions
  • Training & Awareness: Develop and deliver security compliance training programs for employees, contractors, and control owners; build compliance awareness throughout the organization

What We're Looking For:

Experience & Background

  • 6-8+ years of progressive experience in security governance, risk and compliance (GRC), information security auditing, or compliance program management
  • Demonstrated experience working directly with Big Four or external auditors through full audit cycles
  • Control automation experience: Proven success implementing automated evidence collection, continuous control monitoring, and compliance workflow automation
  • ISMS management: Hands-on experience running an Information Security Management System (ISO 27001 ISMS or equivalent)

Framework & Regulatory Knowledge

  • Deep expertise in PCI DSS (all 12 requirements, SAQ types, ROC processes, compensating controls)
  • Strong knowledge of SOX IT General Controls (ITGC) and Application Controls (e.g., access controls, change management, backup/recovery, segregation of duties)
  • Proficiency with ISO 27001:2022 and ISO 42001:2023 (AI Management System) frameworks
  • Hands-on experience with SOC 1 (SSAE 18/ISAE 3402) and SOC 2 (Trust Services Criteria) audit requirements
  • Working knowledge of security frameworks including NIST CSF, NIST SP 800-53, CIS Controls, or COBIT

Technical & Cloud Security

  • Cloud security controls: Deep understanding of cloud security architecture, identity and access management (IAM), network security, data protection, and logging/monitoring within AWS (Azure or GCP experience is a strong plus)
  • Control implementation: Practical knowledge of technical control implementation including encryption, secure configuration management, vulnerability management, and incident response
  • Security architecture: Ability to review and assess security architectures, data flows, and system designs from a compliance perspective

Tools & Technology

  • GRC platforms: Hands-on experience with compliance automation platforms (e.g., Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, or similar)
  • Evidence collection automation: Experience implementing automated evidence collection using APIs, scripts, or integration platforms
  • Audit & assessment tools: Proficiency with vulnerability scanners, SIEM platforms, configuration management tools, and compliance scanning solutions

Education & Certifications

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field
  • Certifications (one or more):
    • CISA (Certified Information Systems Auditor)
    • CISM (Certified Information Security Manager)
    • CISSP (Certified Information Systems Security Professional)
    • ISO 27001 Lead Auditor or ISO 27001 Lead Implementer
    • CCSP (Certified Cloud Security Professional) or CCSK (Certificate of Cloud Security Knowledge)
    • PCI ISA (Internal Security Assessor) or PCI QSA (Qualified Security Assessor)

Specialized Experience

  • Regulated markets: Prior experience with FedRAMP (Low/Moderate/High), GovRAMP, CMMC (Level 1-3), StateRAMP, or TX-RAMP authorization processes
  • Government & defense: Experience with NIST SP 800-171, DFARS compliance, or DoD authorization frameworks
  • Unified Control Framework (UCF): Demonstrated success building and maintaining unified or common control frameworks that map requirements across multiple standards
  • Consulting background: Previous experience with Big Four consulting firms (Deloitte, PwC, EY, KPMG) or specialized security/compliance consulting practices

Navan logo

About Navan

Sourced by ZipRecruiter

Industry

Traveler accommodation

Company size

1,001 - 5,000 Employees

Headquarters location

Palo Alto, CA, US

Year founded

2015

Social media