
Senior Technical Compliance Analyst
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Massachusetts.
• Take ownership of specific technical compliance areas encompassing SOC 2, ISO 27001, PCI DSS, SOX ITGC, NIST, and other pertinent requirements.
• Oversee audit and certification processes from initial planning to final completion.
• Manage timelines, deliverables, evidence gathering, control validation, and responses in collaboration with technical teams.
• Collaborate with Engineering, Security, Legal, Privacy, Internal Audit, and external auditors.
• Evaluate control design and implementation, address audit inquiries, and rectify identified deficiencies.
• Convert regulatory, contractual, and certification requirements into actionable technical controls, scalable workflows, and guidance for stakeholders.
• Develop evidence strategies to enhance the quality, completeness, reusability, and efficiency of audits and assessments.
• Recognize compliance risks and control deficiencies, assign ownership for remediation, monitor progress, and drive resolutions.
• Create program health metrics, audit status reports, and compliance insights suitable for leadership review.
• Enhance governance, risk, and compliance functions through tools, automation, standardized evidence collection, and improvements following audits.
• Share knowledge and promote consistent execution throughout the team.
• A Bachelor’s Degree in Computer Science, Information Technology, or a related discipline.
• A minimum of 5 years of experience in technical compliance, information technology audit, security compliance, privacy compliance, risk management, or governance in a technology-centric or regulated setting.
• Familiarity with compliance and security frameworks like SOC 2, ISO 27001, PCI DSS, SOX ITGC, NIST, or comparable standards.
• Proven experience in leading or assisting with audit readiness, evidence gathering, control validation, remediation tracking, and external audit or certification processes.
• Technical proficiency in areas such as access management, change management, vulnerability management, logging and monitoring, incident response, data protection, cloud infrastructure, and secure development practices.
• Experience in assessing control design and implementation, and translating compliance demands into clear technical and operational expectations.
• Skills in writing scripts, including Python, and utilizing artificial intelligence tools to automate evidence collection, control testing, or compliance workflows is advantageous.
• Strong stakeholder management and communication abilities, capable of influencing teams and articulating compliance requirements, risks, and remediation necessities to both technical and non-technical audiences.
• A mindset focused on continuous improvement and a keen attention to detail.
• Experience in enhancing compliance processes, documentation, audit playbooks, evidence workflows, or control monitoring practices.
• Relevant certifications such as CISA, CISSP, CRISC, CISM, or similar qualifications are beneficial.
• May need to obtain a gaming license issued by the appropriate state agency as a condition of employment.
• Bonus
• Equity
• Benefits as applicable
Brightidea
Eli Lilly and Company
Cisco
GitLab
Get handpicked remote jobs straight to your inbox weekly.