Technical Compliance Analyst

Snorkel AISan Francisco, CA
$120,000 - $185,000

About The Position

We are seeking a hands-on, builder-minded Technical Compliance Analyst to serve as the operational engine behind our Trust & Security program. You will maintain our SOC 2 Type II posture, drive our second entity from Type I to Type II, and act as the bridge between compliance requirements and engineering & delivery execution. You will also lay the technical groundwork to evolve us toward CMMC 2.0, ensuring we are ready for federal contracts without slowing down our product velocity. This is not a "compliance cop" role. We practice "Yes, if..." security—you will influence architecture, automate policy enforcement, and unblock enterprise sales by ensuring the Security team has pristine, verifiable evidence at their fingertips.

Requirements

  • 2–5 years of experience in technical compliance, IT audit, or GRC within a SaaS or fast-paced startup environment.
  • Proven end-to-end experience supporting external SOC 2 Type I and Type II audits—with specific expertise auditing IT General Controls (ITGC) (Change Management, Logical Access, System Operations).
  • Strong understanding of modern cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD pipelines, encryption standards, and vulnerability management.
  • Experience operating automated compliance platforms (Vanta, Drata), tracking work in Jira, and security awareness platform (KnowBe4).
  • You are a business enabler. You practice "Yes, if..." security—you negotiate secure alternatives rather than blocking releases or ignoring risks.
  • You thrive in a partnership role, ensuring IT, Security, Engineering, and Delivery teams have everything they need to succeed.
  • Exceptional written and verbal communication skills with the ability to explain technical controls to customers and business risks to engineers.

Nice To Haves

  • You know how to manage auditors and translate their requests into actionable developer tasks.
  • You can read a Terraform plan or an AWS Config rule and interpret its compliance impact.

Responsibilities

  • Help drafting accurate, technically precise responses to RFPs, security questionnaires (CAIQ, SIG, custom risk assessments), and customer portals.
  • Own and continuously update the "Library of Truth"—a pristine repository of pre-vetted security evidence, technical configurations, and policy documents.
  • Retrieve granular evidence and draft written narratives regarding topics like AWS KMS encryption, logging pipelines, or IAM privilege escalation paths.
  • Partner with IT, Security, Product, Engineering, and Delivery early in the development lifecycle to influence architectural decisions that bake in compliance by design.
  • Write, update, and operationalize security policies that accelerate delivery, translating abstract SOC 2 and NIST controls into clear, developer-friendly tasks.
  • Automate policy enforcement in CI/CD pipelines where possible (Compliance-as-Code).
  • Conduct lightweight compliance enablement sessions with engineering teams.
  • Drive and coordinate the end-to-end SOC 2 Type I and Type II audit cycles across our business entities.
  • Manage audit schedules, coordinate with external auditors, and drive remediation of findings.
  • Be the power-user of our modern GRC stack (Vanta, Drata) to automate evidence collection, continuously monitor technical controls, and eliminate manual spreadsheet tracking.
  • Manage the compliance ticketing queue in Jira.
  • Execute routine mandates including quarterly User Access Reviews (UAR), security awareness training, phishing simulations, and managing the Risk Acceptance/Exception process.
  • Build and maintain compliance dashboards (KPIs/KRIs) for the Security Lead and executive team.
  • Manage the annual policy review and attestation cycle.
  • Assist the Security Team in aligning current controls with federal standards—specifically NIST SP 800-53, NIST SP 800-171 Rev 3, FedRAMP, and CMMC 2.0.
  • Help draft early System Security Plans (SSPs) and Plan of Action & Milestones (POA&Ms).
  • Own the third-party vendor review process, assessing critical partners (Cloud, HRIS, CRM) to meet strict federal supply chain requirements.
  • Support the Security Team during security incidents by preserving audit-relevant evidence, documenting the chronology of events, and drafting post-incident reports.

Benefits

  • Direct Revenue Impact: Your work directly correlates to revenue.
  • Be a Builder, Not a Bureaucrat: You will build automated, scalable compliance programs that enable the business to engineer quicker and sell faster.
  • Modern, Automated Tooling: We leverage continuous-monitoring GRC tech so you can focus on technical risk and architecture, not admin overhead.
  • Future-Proof Career Growth: Gain rare, hands-on exposure to evolving a commercial SaaS startup into a federal-ready entity (FedRAMP/CMMC), highly accelerating your market value in the GRC space.
  • Meaningful opportunities to shape priorities and initiatives, influence key strategic decisions, and directly impact our ongoing success.
  • Environment designed for growth, learning, and shared success.
  • Equal employment opportunities to all employees and applicants for employment.
  • Prohibits discrimination and harassment of any type on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local law.
  • All employment is decided on the basis of qualifications, performance, merit, and business need.
  • Reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service