Technical Compliance Analyst
Core
Operational engine for Trust & Security program, maintaining SOC 2 posture, driving audits, and enabling enterprise sales through technical compliance evidence.
Role type
Technical Compliance Analyst (GRC)
Builds
Automated compliance programs, 'Library of Truth' evidence repository, and audit-ready technical configurations.
Domain
SaaS / Cloud Security / GRC
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOC 2 Type I/II audit management, IT General Controls (ITGC) auditing, cloud infrastructure knowledge (AWS/GCP/Azure), CI/CD pipeline integration, GRC platform operation (Vanta/Drata), Jira ticketing, policy translation for developers, supply chain risk assessment.
Preferred skills
CMMC 2.0 / FedRAMP / NIST SP 800-53 knowledge, Terraform/AWS Config interpretation, security incident documentation, automated evidence collection.
Technologies
Vanta, Drata, Jira, KnowBe4, AWS, GCP, Azure, Terraform, AWS Config, CI/CD pipelines
Responsibilities
Manage end-to-end SOC 2 audit cycles and coordinate with external auditors; draft technical responses to RFPs and security questionnaires; maintain and update the security evidence repository; partner with engineering to bake compliance into architecture; automate policy enforcement in CI/CD pipelines; manage compliance dashboards and KPIs; oversee vendor risk assessments for federal readiness.
Seniority
Mid-level, hands-on IC