Habeo is the IT asset management and CMDB platform built for higher education, giving universities a single system of record for hardware, software, and lab instruments across campuses. As part of our push to meet the security and compliance bar universities require, we're hiring a Security & Compliance Analyst to own our SOC 2 Type II program and our HECVAT responses, and to help our team answer the detailed security questionnaires that come from university CISOs during procurement.
What you'll do
- Own and drive Habeo's SOC 2 Type II audit process end to end, including control design, evidence collection, and coordination with our external auditor
- Maintain and update our HECVAT 2024 responses (both the Lite narrative and the full HECVAT 4.1.5 workbook) as our product and controls evolve
- Respond to inbound security questionnaires and due-diligence requests from prospective university customers, working closely with sales and engineering
- Build and maintain our internal security policy library, control documentation, and audit evidence repository
- Monitor our compliance posture across SSO/identity (SAML, InCommon), data handling (FERPA-aware practices), and audit logging, flagging gaps to engineering leadership
- Track and report on compliance program status to leadership and to prospective customers' security teams
What we're looking for
- 2+ years of experience in security compliance, GRC, or a related security analyst role
- Direct experience supporting or managing a SOC 2 (Type I or Type II) audit
- Familiarity with vendor security assessment frameworks such as HECVAT, VSA, or SIG
- Working knowledge of common security and compliance concepts: access control, encryption, audit logging, incident response, and vendor risk management
- Strong written communication skills — this role involves writing clear, accurate answers to detailed customer security questionnaires
- Comfortable working cross-functionally with engineering, sales, and leadership in a small, fast-moving team
Nice to have
- Prior experience in higher education, edtech, or selling into universities
- Familiarity with FERPA, GASB, or other public-sector/education compliance frameworks
- Experience with SSO/identity standards such as SAML, Shibboleth, or SCIM
- Experience building a compliance program from an early stage, rather than maintaining an existing one