Назад
21 час назад

Technical Compliance Analyst (AI)

120 000 - 185 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Technical Compliance Analyst (AI): Maintaining SOC 2 Type I and Type II readiness while building compliance operations that connect security requirements with engineering and delivery execution, with an accent on GRC automation, technical evidence, and cloud control validation. Focus on translating NIST, FedRAMP, and CMMC requirements into developer workflows, automating policy enforcement in CI/CD, and coordinating audits, remediation, and supply-chain risk reviews.

Location: Hybrid in New York City, NY or San Francisco, CA

Salary: $120,000–$185,000 USD per year

Company

AI company helping enterprises transform expert knowledge and data into specialized, production-ready AI systems.

What you will do

  • Support accurate technical responses to RFPs, security questionnaires, risk assessments, and customer security portals.
  • Own an audit-ready repository of security evidence, technical configurations, and policy documentation.
  • Partner with IT, Security, Product, Engineering, and Delivery to embed compliance into architecture, infrastructure changes, and vendor integrations.
  • Translate SOC 2 and NIST controls into practical engineering tasks and automate policy enforcement in CI/CD pipelines.
  • Coordinate SOC 2 Type I and Type II audit cycles, auditor requests, remediation, evidence collection, and compliance reporting.
  • Manage access reviews, security awareness activities, risk exceptions, policy attestations, vendor reviews, and incident-related audit evidence.

Requirements

  • 2–5 years of experience in technical compliance, IT audit, or GRC in a SaaS or fast-paced startup environment.
  • End-to-end experience supporting external SOC 2 Type I and Type II audits, including IT General Controls for change management, logical access, and system operations.
  • Strong understanding of cloud infrastructure, IAM, CI/CD pipelines, encryption standards, and vulnerability management across AWS, GCP, or Azure.
  • Ability to interpret Terraform plans and AWS Config rules in relation to compliance impact.
  • Experience with Vanta or Drata, Jira, and KnowBe4.
  • Strong written and verbal communication skills, including explaining technical controls to customers and business risks to engineers.

Nice to have

  • Experience aligning controls with NIST SP 800-53, NIST SP 800-171 Rev. 3, FedRAMP, or CMMC 2.0.
  • Experience drafting System Security Plans and Plans of Action & Milestones.
  • Experience with third-party vendor reviews, supply chain risk management, or incident readiness.

Culture & Benefits

  • Builder-oriented approach focused on enabling secure delivery rather than blocking releases.
  • Modern, continuously monitored GRC tooling instead of manual spreadsheet tracking.
  • Direct connection between compliance work, enterprise revenue enablement, and customer trust.
  • Opportunity to help evolve a rapidly scaling SaaS business toward federal readiness.
  • Support for career growth, learning, cross-functional work, and leadership development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →