Skip to content
← Back to job listings

Senior Compliance Analyst

Horizon3 · United States

External listingfull-time7 days ago

About The Role

Join our growing Security team as a Senior Compliance Analyst. In this role, you will be a subject matter expert in compliance and data privacy, managing customer security requests, leading audit preparation activities, and driving continuous improvements in our compliance program. You will oversee the organization's privacy program, manage third-party risk, and serve as the primary point of contact for customer security inquiries. This position offers growth opportunities, an innovation-driven culture, an inclusive and diverse team, and a flexible work environment.

  • Serve as the internal lead for SOC 2 Type II compliance efforts, including control mapping, evidence collection, and audit coordination.
  • Oversee the organization’s privacy program to ensure compliance with GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. state data privacy laws.
  • Own and manage the third-party risk management lifecycle, including onboarding reviews, periodic reassessments, and contract/privacy reviews.
  • Certifications such as CIPP/US, CIPT, CISA, CRISC, or ISO Lead Implementer are a strong plus
  • Experience responding to security questionnaires, RFPs, and customer audits
  • Excellent communication skills and the ability to translate complex compliance concepts for both technical and non-technical stakeholders
  • Familiarity with common SaaS infrastructure (e.g., AWS, Okta, MDM, SIEM, DLP, etc.)
  • 4–6+ years of experience in security compliance, risk, or privacy—preferably in a B2B SaaS or cybersecurity company
  • Expertise in GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. data privacy laws
  • Deep understanding of compliance frameworks (e.g., SOC2, ISO:27001, NIST AI RMF, NIST 800-53, etc.) and experience leading annual audits
  • Strong working knowledge of third-party risk management practices and vendor due diligence processes
  • You’ve led multiple SOC 2 Type II audits from start to finish and know how to navigate both the auditor's requirements and the business's operational realities
  • You have a deep working knowledge of global and U.S. privacy laws, including GDPR, CCPA/CPRA, and stay ahead of the evolving regulatory landscape
  • You're a trusted partner across Sales, Legal, Security, and Engineering—balancing compliance rigor with practical business execution
  • You’ve built or managed a vendor risk management program and know how to evaluate technical controls, assess privacy risk, and communicate findings clearly
  • When faced with a massive security questionnaire or RFP, you know how to cut through complexity, collaborate with SMEs, and deliver confident, timely responses
  • You hold industry-recognized certifications like CIPP/US, CISA, or ISO 27001 Lead Implementer, demonstrating your commitment to professionalism and subject matter expertise.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing