InfoSec Analyst II Trust
You will operate and improve the security compliance program through evidence collection, control testing, customer assurance, and security assessments. You will contribute to AI governance, maintain compliance records, automate evidence workflows, explain technical requirements in customer responses, and report security metrics to stakeholders.
Responsibilities
- Contribute to AI governance activities, including AI use-case reviews, vendor assessments, data-handling evaluations, and documentation of applicable security controls.
- Manage SOC 2, ISO 27001, and customer security reviews through evidence collection and control testing.
- Coordinate end-to-end security assessments, tracking dependencies, findings, and remediation.
- Maintain accurate compliance records and automate recurring evidence-gathering workflows.
- Translate technical compliance information into clear responses for customer questionnaires and RFPs.
- Evaluate AI governance risks such as data leakage, prompt injection, and third-party exposure.
- Provide security metrics and status updates to stakeholders while building cross-functional partnerships.
Requirements
- Experience in GRC, compliance, or IT audit within a SaaS, fintech, or technology environment.
- Practical knowledge of SOC 2, ISO 27001, or NIST frameworks.
- Ability to test controls, track remediation, and translate technical requirements into actions.
- Strong organizational and communication skills to manage multiple assessments and stakeholders.
- A systems-minded approach to improving workflows and curiosity about AI security and governance.
- Experience supporting AI risk assessments, AI vendor reviews, model governance, or enterprise AI-use policies.
- Nice to have: experience using APIs, spreadsheets, scripting, or workflow automation.
- Nice to have: experience in blockchain, cryptocurrency, financial services, cybersecurity, or another high-trust environment.
Benefits
- Equity
- Bonus