Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Technical Compliance Analyst (AI): Maintaining SOC 2 Type I and Type II readiness while building compliance operations that connect security requirements with engineering and delivery execution, with an accent on GRC automation, technical evidence, and cloud control validation. Focus on translating NIST, FedRAMP, and CMMC requirements into developer workflows, automating policy enforcement in CI/CD, and coordinating audits, remediation, and supply-chain risk reviews.
Location: Hybrid in New York City, NY or San Francisco, CA
Salary: $120,000–$185,000 USD per year
Company
AI company helping enterprises transform expert knowledge and data into specialized, production-ready AI systems.
What you will do
- Support accurate technical responses to RFPs, security questionnaires, risk assessments, and customer security portals.
- Own an audit-ready repository of security evidence, technical configurations, and policy documentation.
- Partner with IT, Security, Product, Engineering, and Delivery to embed compliance into architecture, infrastructure changes, and vendor integrations.
- Translate SOC 2 and NIST controls into practical engineering tasks and automate policy enforcement in CI/CD pipelines.
- Coordinate SOC 2 Type I and Type II audit cycles, auditor requests, remediation, evidence collection, and compliance reporting.
- Manage access reviews, security awareness activities, risk exceptions, policy attestations, vendor reviews, and incident-related audit evidence.
Requirements
- 2–5 years of experience in technical compliance, IT audit, or GRC in a SaaS or fast-paced startup environment.
- End-to-end experience supporting external SOC 2 Type I and Type II audits, including IT General Controls for change management, logical access, and system operations.
- Strong understanding of cloud infrastructure, IAM, CI/CD pipelines, encryption standards, and vulnerability management across AWS, GCP, or Azure.
- Ability to interpret Terraform plans and AWS Config rules in relation to compliance impact.
- Experience with Vanta or Drata, Jira, and KnowBe4.
- Strong written and verbal communication skills, including explaining technical controls to customers and business risks to engineers.
Nice to have
- Experience aligning controls with NIST SP 800-53, NIST SP 800-171 Rev. 3, FedRAMP, or CMMC 2.0.
- Experience drafting System Security Plans and Plans of Action & Milestones.
- Experience with third-party vendor reviews, supply chain risk management, or incident readiness.
Culture & Benefits
- Builder-oriented approach focused on enabling secure delivery rather than blocking releases.
- Modern, continuously monitored GRC tooling instead of manual spreadsheet tracking.
- Direct connection between compliance work, enterprise revenue enablement, and customer trust.
- Opportunity to help evolve a rapidly scaling SaaS business toward federal readiness.
- Support for career growth, learning, cross-functional work, and leadership development.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
3 дня назад
Staff Software Engineer - App & Cloud Security
200 000 - 275 000$
18 часов назад
GRC Analyst (AI)
160 000 - 170 000$
16 часов назад
Security Engineer (AI/LLM)
120 000 - 150 000$
3 дня назад
Compliance Manager (GovTech)
130 000 - 175 000$
3 дня назад
Cloud Security Architect (AI)
149 000 - 181 000$
3 дня назад
Senior Compliance Engineer, AI Governance (AI)
145 000 - 225 000$