Horizon3 AI logo
Horizon3 AIPosted 1 month ago

Senior Compliance Analyst

$109,000–$135,000 year

RemoteUnited States

Full TimeSenior LevelSmall

Job Summary

Manage inbound customer security requests, lead audit preparation activities, and drive continuous improvements in the compliance program. Serve as the internal lead for SOC 2 Type II compliance efforts, including control mapping, evidence collection, and audit coordination. Oversee the organization's privacy program to ensure compliance with GDPR, CCPA/CPRA, and the EU AI Act, while maintaining records of processing activities and managing data subject access requests. Own the third-party risk management lifecycle, conducting due diligence on new vendors and maintaining an inventory of subprocessors. Respond to customer security questionnaires, RFPs, and due diligence requests to enable trust with clients and accelerate deal closure.

Required Qualifications

  • 4–6+ years of experience in security compliance, risk, or privacy—preferably in a B2B SaaS or cybersecurity company
  • Deep understanding of compliance frameworks (e.g., SOC2, ISO:27001, NIST AI RMF, NIST 800-53, etc.) and experience leading annual audits
  • Expertise in GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. data privacy laws
  • Strong working knowledge of third-party risk management practices and vendor due diligence processes
  • Experience responding to security questionnaires, RFPs, and customer audits
  • Familiarity with common SaaS infrastructure (e.g., AWS, Okta, MDM, SIEM, DLP, etc.)
  • Excellent communication skills and the ability to translate complex compliance concepts for both technical and non-technical stakeholders

Desired Qualifications

  • Certifications such as CIPP/US, CIPT, CISA, CRISC, or ISO Lead Implementer
  • You've led multiple SOC 2 Type II audits from start to finish and know how to navigate both the auditor's requirements and the business's operational realities
  • You have a deep working knowledge of global and U.S. privacy laws, including GDPR, CCPA/CPRA, and stay ahead of the evolving regulatory landscape
  • You're a trusted partner across Sales, Legal, Security, and Engineering—balancing compliance rigor with practical business execution
  • You've built or managed a vendor risk management program and know how to evaluate technical controls, assess privacy risk, and communicate findings clearly
  • When faced with a massive security questionnaire or RFP, you know how to cut through complexity, collaborate with SMEs, and deliver confident, timely responses
  • You hold industry-recognized certifications like CIPP/US, CISA, or ISO 27001 Lead Implementer, demonstrating your commitment to professionalism and subject matter expertise

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce