Remote job
Senior Technical Compliance Analyst
Job details
About this role
Role overview A hands-on senior analyst role focused on operationalizing a Trust & Security program for a data-centric AI company. The position acts as the bridge between compliance requirements and engineering execution, maintaining SOC 2 Type II posture, advancing a second entity from Type I to Type II, and laying technical groundwork toward federal-readiness frameworks. The emphasis is on enabling revenue and engineering velocity rather than gatekeeping.
Responsibilities - Drive end-to-end SOC 2 Type I and Type II audit cycles across multiple business entities, coordinating external auditors and remediation of findings - Maintain an audit-ready evidence repository of security configurations, policy documents, and pre-vetted technical artifacts used to answer enterprise customer questionnaires (CAIQ, SIG, custom assessments) - Partner with IT, Security, Product, Engineering, and Delivery teams early in the development lifecycle to embed compliance into architectural decisions and feature launches - Translate SOC 2 and NIST controls into developer-friendly tasks, including IAM hardening, log retention, and Zero Trust implementation, and operationalize them through automated policy enforcement in CI/CD pipelines - Operate and optimize a modern GRC stack (Vanta, Drata) for continuous control monitoring, evidence collection, and dashboard reporting on KPIs/KRIs - Manage third-party vendor risk reviews, run quarterly User Access Reviews, security awareness training, phishing simulations, and the Risk Acceptance/Exception process - Support alignment of current controls with federal frameworks (NIST SP 800-53, NIST SP 800-171, FedRAMP, CMMC 2.0), including drafting early System Security Plans and POA&Ms
Requirements - 2–5 years of experience in technical compliance, IT audit, or GRC within a SaaS or fast-paced startup environment - Demonstrated end-to-end support of external SOC 2 Type I and Type II audits, including IT General Controls (Change Management, Logical Access, System Operations) - Strong understanding of modern cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD pipelines, encryption standards, and vulnerability management; ability to read Terraform plans or AWS Config rules and assess compliance impact - Hands-on experience with automated compliance platforms (Vanta, Drata), Jira-based workflow management, and security awareness tools (e.g., KnowBe4) - A business-enabler mindset that favors negotiating secure alternatives over blocking releases, with exceptional written and verbal communication for both customer-facing and engineering audiences
Nice to have - Exposure to evolving a commercial SaaS environment toward federal-readiness standards (FedRAMP, CMMC) and supply-chain risk management practices - Experience supporting incident response with audit-relevant evidence collection and post-incident reporting
Benefits and work setup - Hybrid role requiring three days per week on-site in a major metro office - Compensation range of $150,000–$220,000 USD, determined by skills, qualifications, experience, and location - Emphasis on builder culture with modern automated GRC tooling rather than manual spreadsheet tracking - Reasonable accommodations available for candidates with disabilities throughout the hiring process and employment