Navan

PCI & SOX Compliance Specialist

Navan · London, UK
London, UK Posted 2026-07-18
Type
Full-time

The Security Compliance Analyst will be a critical, hands-on member of the Navan Governance, Risk, Compliance, and Trust (GRCT) Team, specifically embedded in London to drive the compliance integration between Navan and Reed & Mackay.

This is not a high-level policy writing or checking boxes role. We are looking for an active, execution-focused compliance professional to untangle legacy systems, map control deficiencies, and run daily operational workflows. Acting as a decisive bridge between engineering sprint teams, IT infrastructure, and US-based external auditors, you will own the day-to-day transaction compliance and technical evidence pipeline that keeps our global travel and expense platforms bulletproof.

What You’ll Do

  • Own Vulnerability Remediation Loops: Actively track and oversee quarterly PCI ASV scans and penetration testing cycles, collaborating directly with IT and engineering teams to ensure patches are executed within strict SLA windows.
  • Lead the Integration Pipeline: Conduct continuous gap analyses and map security controls as we merge legacy travel infrastructure into Navan's modern cloud frameworks.
  • Drive SOX 404 Controls: Take ownership of testing and validating IT General Controls (ITGCs) under Sarbanes-Oxley Section 404, with a heavy emphasis on access control management (Joiners/Movers/Leavers) and secure code deployment.
  • Embed with Engineering: Partner with development teams to automate manual evidence gathering, translating rigid compliance jargon into clear, actionable JIRA tickets.
  • Collaborate Globally: Partner closely with US-based audit firms and compliance bodies. This includes a flexible schedule to work late hours (until 9:00 PM–10:00 PM) a few days per month on specific US alignment days.
  • Track Open Deficiencies: Manage the risk register and remediation tracking lifecycle from initial identification to final verification and closure.

What We’re Looking For

  • Experience: Minimum of 3+ years of hands-on, corporate operational experience in information security compliance. You must have active experience sitting on a corporate security or IT team—purely academic, training, or governmental advisory backgrounds will not fit the speed of this role.
  • PCI & SOX Technical Depth: Proved, practical exposure executing compliance frameworks for transactional environments. You must understand Section 404 ITGCs and the technical mechanics of PCI DSS (including cardholder data protection environments and SAQs).
  • Tools & Systems Mastery: Comfortable navigating tracking platforms such as JIRA, ServiceNow GRC, or AuditBoard to monitor, assign, and resolve open compliance findings.
  • A Technical Edge: A baseline technical background (e.g., computer science, systems administration, or IT support) that allows you to confidently push back on or guide engineers during patch cycles.
  • Location & Hours Flexibility: Willingness to work under a hybrid model out of our London office (4 days a week) and the routine flexibility needed to support monthly evening shifts for US team synchronization.
  • Language requirements: Full proficiency in English.
  • Bonus Points: Certifications such as CompTIA Security+ or ISO 27001 Internal Auditor.
Navan

Navan

Corporate Travel · Public · Palo Alto, USA

Stage & Valuation
Public · $5.0B
Open roles on NewJob
Most hiring in
Engineering (25) · Sales (10) · BizOps (9)
Navan is a corporate travel and expense management platform that provides a unified solution for booking business travel and managing employee expenses. The company offers AI-powered tools like Navan Travel and Navan Expense to streamline corporate spending and reimbursements.
Corporate Travel Expense Management Fintech SaaS
B
Director, Corporate Development
New York, NY
BizOps
$167K–$372K
S
Head of Private Equity Partnerships
Boston, MA
Sales
$167K–$372K
B
Senior Manager, Corporate Development
New York, NY
BizOps
$167K–$372K
See all 75+ roles at Navan →
A
Manager, Governance, Risk & Compliance
Accela Remote Based - US Remote
Engineering
$150K–$170K
A
Manager, QA & Compliance
Alertus Technologies Baltimore, MD
Engineering
$85K–$133K
C
Head of Security & Compliance
Cascading AI San Francisco, CA
Engineering
$200K–$255K
C
Senior Engineer, Security & Compliance
Code and Theory Austin, TX
Engineering
$110K–$150K
See all Engineering roles →

Interested in this role?

Apply directly on the company site — no recruiter middleman, no account required.

Apply now →
Apply on company site