Forage→
Security Analyst at Forage in San Francisco, CA
Entry LevelHybridFull-timeSan Francisco, CA$90k–$100k/yr
Skills
grc experiencesecurity complianceit auditsoc 2 familiaritypci dss familiarityiso 27001 familiaritypython code readingvendor assessmentsaccess reviewsaudit supportpayments experiencepenetration testing knowledgenode reading abilityorganizational skillsdocumentation skills
Job Description
Summary: Forage is a fast-growing startup focused on building a modern payments stack that facilitates inclusive commerce. They are seeking a Security Analyst to manage their security and compliance programs, ensuring policies and audits are organized and up-to-date while collaborating closely with the Head of Security.
Responsibilities:
- Triage and manage incoming security requests from entire company
- Own and manage the full vendor security assessment lifecycle (new vendors and annual reviews)
- Own and build device management and provisioning process
- Troubleshoot and enhance in-office IT, wifi and physical security
- Partner with product/engineering teams to clarify which controls apply to new features, systems, or architectural changes
- Read python code to understand vulnerabilities and help validate fixes and make small bug fixes or configuration updates when appropriate
- Maintain organized, audit-ready repositories of policies, SOC reports, and control documentation
- Assist with security questionnaires from enterprise customers
- Coordinate evidence collection and organize materials for quarterly/annual audits
- Update and refine security policies to reflect current controls and organizational practices
- Track remediation of security findings from vulnerability scans, pentests, and audits
Required Qualifications:
- 1-4 years of experience in GRC, security compliance, IT audit or security operations
- Familiarity with SOC 2, PCI DSS, ISO 27001, or similar security frameworks
- Ability to read and understand python code to validate security fixes
- Strong organizational and documentation skills
- Ability to own and prioritize multiple tasks open at once
- Experience with vendor assessments, access reviews, evidence collection, or audit support
- Comfort working with technical teams, asking clarifying questions, and escalating when need
Preferred Qualifications:
- Payments experience
- Knowledge of penetration testing workflows
- Ability to read node
Required Skills: GRC experience, Security compliance, IT audit
Important Skills: SOC 2 familiarity, PCI DSS familiarity, ISO 27001 familiarity, Python code reading
Nice-to-Have Skills: Vendor assessments, Access reviews, Audit support, Payments experience, Penetration testing knowledge, Node reading ability, organizational skills, Documentation skills
Benefits: 100% of Medical, Dental and Vision premium coverage for yourself and dependents., Enjoy regular team lunches at our San Francisco office, fostering collaboration and connection over great food., A fun and caring environment that prioritizes transparency, growth, and ownership.
Benefits
100% of Medical, Dental and Vision premium coverage for yourself and dependents.
Enjoy regular team lunches at our San Francisco office, fostering collaboration and connection over great food.
A fun and caring environment that prioritizes transparency, growth, and ownership.