Blitzy: Autonomous AI platform for enterprise software development.
Hands-on ownership of SOC 2 Type II or ISO 27001:2022 audits, Vanta or equivalent GRC platform experience, auditor/vendor management, FedRAMP exposure preferred, strong written and judgment skills.
KlaviyoNYSE: KVYO: Software platform for automated e-commerce marketing and customer data.
3+ YOE3+ years security compliance/GRC engineering experience with automation focus; experience with SOC 2, ISO 27001/27017, PCI or SOX ITGCs; proficiency with cloud (AWS, Kubernetes), scripting (Python, Go, SQL), REST APIs, and compliance automation platforms.
New York City or Maryland or Massachusetts or Virginia or Georgia or New York
$97k-$184k/yrOnsiteFull Time
Chainalysis: Blockchain data platform for cryptocurrency investigation and compliance.
Experience implementing and operating security and compliance controls in cloud/SaaS environments; built evidence collection, control testing, or remediation workflows; supported SOC 2/ISO 27001 or similar; strong written/verbal communication; US citizenship required.
Emburse: Provides AI-powered travel and expense management software for businesses.
5+ YOE5+ years in information security compliance or vendor risk; working knowledge of SOC 2, ISO 27001, NIST, GDPR, CCPA; experience with high-volume DDQ workflows; strong written communication and organization; proficiency with RFPIO.
15+ YOE15+ years in technology audit/compliance/risk, knowledge of access controls, change management, disaster recovery, patching and domestic/global regulations; strong communication and team collaboration skills.
Active Directory, Workiva, AuditBoard, Vanta, Drata, Protect
United States or Canada or Washington or New York City or San Francisco or Seattle or Denver or Boston or Los Angeles
$150k-$250k/yrRemoteFull Time
Crux: Platform for financing clean energy and infrastructure projects.
4+ YOE4+ years IT ownership at high-growth startups, SOC2 audit experience, SaaS vendor negotiation, Mac/Windows management, automation mindset, regular use of AI tools.
10+ YOE10+ years in IT risk/audit/GRC, experience with RCSAs/KRIs, vendor risk/SOC reviews, strong writing and communication, knowledge of NIST/COSO/COBIT and US/global regulations; professional certs a plus.