Security Compliance Analyst
Summary
Manage security compliance programs including SOC 2 audits, customer security questionnaires, control testing, and vendor assessments, directly investigating AWS, Windows, and other technical systems to gather audit evidence.
As the Security Compliance Analyst, you will manage security, compliance, and customer assurance programs. You will work directly with the VP of Information Security & Compliance on customer security questionnaires, SOC 2 and other audits, control testing, evidence collection, vendor assessments, and compliance initiatives including CMMC and NIST 800-171. This is a hands-on, technically self-sufficient role, not a policy-only or checklist-driven GRC position.
Responsibilities
- Complete customer security questionnaires, DDQs, RFP security sections, and related security reviews.
- Research technical questions and produce accurate, defensible answers based on the company's actual environment and controls.
- Maintain a reusable library of approved questionnaire responses and supporting evidence.
- Recognize when an existing answer applies, when something has changed, and when a subject-matter expert genuinely needs to be involved.
- Participate in customer security calls when deeper technical or compliance discussions are required.
- Help make the customer assurance process faster without sacrificing accuracy.
- Track findings, exceptions, remediation activities, and control-owner commitments through completion.
- Manage deadlines, maintain and report status, and escalate as needed.
Requirements
- 3+ years of relevant experience across IT, security, GRC, compliance, cloud operations, systems administration, or a similar field.
- Solid understanding of common security concepts.
- Hands-on experience with security compliance work, audit evidence, security questionnaires, or control testing.
- Excellent spoken English, with the ability to participate confidently in meetings with U.S.-based customers, auditors, and internal teams.
- Strong organizational skills and attention to detail, with the ability to manage multiple questionnaires, audit requests, and deadlines simultaneously.
- Hands-on experience administering Windows and cloud-based architectures, including IT Tier 2 or systems administration work.
- Comfortable investigating technical systems directly (for example, AWS, identity platforms, endpoint-management tools, GitHub, ticketing systems) to retrieve evidence rather than relying on Engineering or IT for every request.
- Working knowledge of scripting or automation (for example, PowerShell) to operate efficiently at scale.
- Ability to write clear, accurate technical documentation.
Benefits
- Compensation: $2000 to $3000
- Schedule: U.S. business hours
- PTO: Choice of following the U.S. holiday calendar or your home country's calendar.
- Health & Equipment: Healthcare reimbursement eligibility after 90 days; a device stipend of up to $1,500, or reimbursement if you use your own equipment.
As published by workable
First name, Last name, Email, Phone, Address, Photo, Education, Experience, Summary, Resume, Cover letter, What is your desired salary for this job (USD)?, Please record a 2 sentence audio telling us why you are a good fit for the role. You can use the following link and paste it below: https://www.speakpipe.com/voice-recorder
- Do you currently reside in LATAM or the Caribbean? yes / no
- Is your application submitted in English (including your CV)? yes / no
- How many years of experience do you have working in IT, security, GRC, compliance, cloud operations, or systems administration roles?
- How many years of hands-on experience do you have working directly within AWS environments?
- How many years of hands-on experience do you have completing security questionnaires, gathering audit evidence, or performing control testing? written answer