
Technology Compliance Associate
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in New York.
• Create and implement policies and governance frameworks for AI usage.
• Establish AI security protocols and controls utilizing AI Gateway and comparable tools.
• Perform security assessments and risk evaluations on AI tools and services.
• Analyze AI tool usage and provide metrics via observability platforms.
• Uphold data privacy and protection standards during AI tool integration.
• Oversee vendor assessments and monitoring for AI service providers.
• Stay updated on emerging AI regulations, including NIST AI RMF and developments related to the EU AI Act.
• Manage the SOC 2 compliance program, encompassing control frameworks, evidence collection, audit coordination, and maintaining certification.
• Execute security risk assessments, conduct phishing simulations, manage vulnerabilities, and coordinate penetration testing efforts.
• Lead BCP/DR planning, testing, and documentation processes.
• Supervise security incident response and conduct post-incident reviews.
• Track and report on security metrics, compliance status, and risk remediation efforts.
• Oversee CrowdStrike Falcon Complete activities, including alert triage, monitoring, configuration coordination, and escalations.
• Assist with identity and access management, employee access reviews, and privileged access controls.
• Monitor vulnerability scan outcomes and coordinate remediation with engineering teams.
• Manage third-party penetration testing engagements and ensure findings are tracked through remediation.
• Take ownership of the entire DDQ process, ensuring response accuracy, version control, and automation initiatives are in place.
• Act as the primary point of contact for client and prospect security questionnaires.
• Conduct vendor security assessments and handle third-party risk management.
• Collaborate with legal and compliance teams regarding vendor contracts and technical due diligence.
• Report directly to the Technology Compliance Manager while engaging with clients, auditors, and regulators.
• 4+ years of experience in information security or GRC/Compliance, showcasing hands-on technical expertise and demonstrated leadership.
• Familiarity with cloud security (AWS is required, GCP is a plus), security tools (CrowdStrike or similar EDR/XDR platforms), and infrastructure security controls.
• Understanding of AI/LLM security risks, data privacy issues, and emerging AI governance frameworks (NIST AI RMF, EU AI Act).
• Practical experience managing SOC 2 programs in production environments, achieving successful audit results.
• Proficient knowledge of SOC 2, ISO 27001, NIST frameworks and their application in practice.
• Proven ability to effectively communicate security concepts to institutional clients and represent technical capabilities in a professional manner.
• Experience with security compliance in the financial services sector or other regulated industries.
• Exceptional written and verbal communication skills across both technical and non-technical audiences.
• CISSP, CISM, Security+, or equivalent certifications are preferred.
• Bachelor’s degree in Computer Science, Information Security, or a related field.
• AWS expertise is required; familiarity with GCP is valuable.
• Experience with CrowdStrike Falcon Complete or similar EDR/XDR platforms.
• Knowledge of SSO, MFA, and access control systems.
• Highly competitive compensation package.
• Comprehensive medical, dental, and vision coverage fully paid by the employer.
• Flexibility to work remotely.
• A team-oriented and collaborative company culture.
Avantpage Translations
Coalfire
RTX
ACA Group
Get handpicked remote jobs straight to your inbox weekly.