● 1–5 years of experience in compliance, GRC, security assurance, IT audit, information security, or a related field, ideally in a B2B SaaS or technology environment.
● Working knowledge of security and privacy frameworks and regulations such as SOC 2, ISO 27001, ISO 27701, ISO 42001, GDPR, or equivalent, with the ability to interpret and apply these requirements to practical compliance activities.
● Hands-on experience with, or exposure to, audit and compliance activities such as audit planning, evidence collection, control testing, control implementation, documentation, remediation, or auditor coordination.
● Ability to translate framework and regulatory requirements into practical, workable controls and collaborate with teams across Engineering, Product, IT, Legal, and other functions to implement them.
● Ability to read and interpret security documentation, audit reports, architecture diagrams, cloud configurations, and other technical information well enough to assess whether evidence adequately supports a compliance requirement.
● Experience responding to or supporting customer security questionnaires, RFIs, and security assurance requests, with the ability to communicate technical and compliance information clearly to non-technical audiences.
● Strong written and verbal communication skills, with the ability to translate technical,
security, privacy, and legal concepts into clear, customer-ready and auditor-ready language.
● Strong ownership and problem-solving mindset, with the ability to identify gaps,
investigate root causes, and drive issues through to resolution rather than simply
completing assigned tasks.
● Ability to manage multiple compliance activities, maintain accurate documentation, and track audit, framework, and remediation action items through closure.
● Comfortable working with collaborative tools such as Jira and Confluence for documentation, workflow management, and compliance tracking.
● Exposure to or experience with GRC and continuous compliance platforms, Trust Center or security questionnaire tooling, or contract review tooling is a plus.
● Exposure to vendor and customer contract reviews from a security, privacy, or compliance perspective is a plus.
● Experience working directly with auditors, control owners, Engineering, Product, or Customer-facing teams to resolve compliance requirements is a plus.
● Professional certifications such as CISA, CISM, CRISC, ISO 27001 Lead Auditor/Lead Implementer, or CIPP/E are a plus.