
Senior Compliance Analyst
Job description
Senior Compliance Analyst at Horizon3.ai.
About the role
Horizon3 is seeking a dedicated Senior Compliance Analyst to strengthen our Security team. This role is crucial for maintaining customer trust and regulatory adherence in our cybersecurity operations. You will be a key resource for compliance and data privacy matters, helping us scale our programs effectively. The position requires ownership of complex compliance initiatives that bridge technical security controls and regulatory obligations. You will drive the execution of critical governance activities across the customer lifecycle. Your work will directly influence the security posture and market readiness of our platform. This position demands a high level of integrity and the ability to operate independently in a fast-paced environment. You will help translate evolving regulatory landscapes into actionable internal policies.
Key facts
What you'll do
- Lead SOC 2 Type II compliance initiatives, including control mapping, evidence gathering, and audit coordination.
- Enhance our control environment to meet requirements for frameworks like ISO 27001, NIST AI RMF, DORA, and NIST 800-53.
- Oversee the organization's data privacy program, ensuring adherence to GDPR, CCPA/CPRA, EU AI Act, and other relevant laws.
- Manage the full lifecycle of third-party risk, from onboarding to ongoing assessments and contract reviews.
- Act as the primary contact for customer security questionnaires, RFPs, and due diligence requests, facilitating deal closures.
- Collaborate with Engineering, IT, Legal, and HR teams to implement and verify compliance controls.
- Maintain records of processing activities, handle data subject access requests, and conduct privacy impact assessments.
- Advise product and legal teams on privacy-by-design principles and data minimization.
- Drive the continuous monitoring and improvement of the organization's compliance posture.
- Translate complex regulatory requirements into practical implementation guidance for technical teams.
- Coordinate internal readiness for external audits and ensure timely remediation of findings.
- Develop and maintain compliance documentation, policies, and procedural standards.
- Support the evaluation of new vendors and service providers for regulatory risk.
- Monitor updates to global regulations and assess potential impacts on business operations.
Requirements
- 4-6+ years of experience in security compliance, risk, or privacy, ideally within B2B SaaS or cybersecurity.
- Proficient understanding of compliance frameworks such as SOC 2, ISO 27001, NIST AI RMF, and NIST 800-53, with experience managing annual audits.
- Expertise in global and U.S. data privacy regulations including GDPR, CCPA/CPRA, and the EU AI Act.
- Solid knowledge of third-party risk management and vendor due diligence processes.
- Experience responding to security questionnaires and customer audits.
- Familiarity with common SaaS infrastructure components like AWS, Okta, MDM, SIEM, and DLP.
- Strong communication skills to explain complex compliance topics to diverse audiences.
- Ability to maintain confidentiality and exercise sound judgment in sensitive situations.
- Willingness to adhere to company policies and support a culture of compliance and ethics.
- Capacity to manage multiple priorities and meet deadlines in a dynamic remote setting.
- Commitment to following established processes while seeking continuous improvement.
- Eligibility to work in the United States without sponsorship for this role.
- Access to a reliable internet connection and a suitable workspace for remote engagement.
Nice to have
- Certifications such as CIPP/US, CIPT, CISA, CRISC, or ISO Lead Implementer.
Practical notes
- All full-time roles are eligible for an equity package.
- Benefits include health, vision, and dental insurance, flexible vacation, and generous parental leave.
- Candidates may redact age-identifying information from submitted materials without penalty.
- This position is based in the United States and allows for remote work.
- No travel is required for this role.
- No specific visa sponsorship is mentioned for this position.
- There are no published deadlines for application submission in the provided source.
About the company
Horizon3.ai uses real-world attacks to safely show what attackers can actually do in your environment - so you can fix and prove what matters.