Horizon3.ai

Senior Compliance Analyst

Horizon3.ai$109K — $135K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4-6+ years of experience in security compliance, risk, or privacy (preferably in B2B SaaS or cybersecurity)
  • Deep understanding of compliance frameworks (e.g., SOC2, ISO:27001, NIST AI RMF)
  • Expertise in GDPR, CCPA/CPRA, EU AI Act, and U.S. data privacy laws
  • Strong knowledge of third-party risk management and vendor due diligence processes
  • Experience responding to security questionnaires, RFPs, and customer audits
  • Familiarity with SaaS infrastructure (e.g., AWS, Okta)
  • Excellent communication skills for both technical and non-technical stakeholders

Responsibilities

  • Lead efforts for SOC 2 Type II compliance including audit coordination and evidence collection
  • Improve the control environment for continuous compliance with applicable frameworks
  • Oversee and ensure compliance with data privacy regulations like GDPR and CCPA/CPRA
  • Manage the lifecycle of third-party risk management including vendor audits and privacy reviews
  • Act as the primary contact for customer security inquiries and RFPs
  • Collaborate with internal teams to support compliance efforts and improve documentation

Benefits

  • Inclusive Team: Commitment to diversity and an inclusive culture
  • Growth Opportunities: Career development in a dynamic and growing environment
  • Innovative Culture: Emphasis on creativity and out-of-the-box thinking
  • Hybrid & Remote Work: Flexibility in work models depending on role
  • Competitive Compensation: Comprehensive health, vision, and dental benefits, flexible vacation policy, and parental leave
Full Job Description
What You'll Do

We are seeking a skilled Senior Compliance Analyst with strong experience in Governance, Risk, and Compliance (GRC) to join our growing Security team. As a cybersecurity company, we take compliance, privacy, and third-party risk seriously. This role will serve as a subject matter expert for compliance and data privacy, and will play a critical role in maintaining trust with customers, regulators, and partners. You will manage inbound customer security requests, lead audit preparation activities, and drive continuous improvements in our compliance program.

This role is instrumental in helping us scale and mature our Compliance and Data Privacy capabilities while maintaining a strong security posture across the organization.

This role will be responsible for.....

  • Compliance & Audit Management
    • Serve as the internal lead for SOC 2 Type II compliance efforts, including control mapping, evidence collection, and audit coordination.
    • Maintain and improve the control environment to ensure continuous compliance with SOC 2 and other applicable frameworks such as but not limited to ISO:27001, NIST AI RMF, DORA, and NIST 800-53.
    • Collaborate with cross-functional teams (Engineering, IT, Legal, HR) to implement and validate control requirements.
  • Data Privacy Compliance
    • Oversee the organization's privacy program to ensure compliance with GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. state data privacy laws.
    • Maintain records of processing activities (RoPAs), manage data subject access requests (DSARs), and conduct privacy impact assessments (PIAs).
    • Work closely with Legal and Product teams to advise on privacy-by-design and ensure data minimization and transparency practices.
  • Vendor Risk Management
    • Own and manage the third-party risk management lifecycle, including onboarding reviews, periodic reassessments, and contract/privacy reviews.
    • Conduct security and privacy due diligence on new vendors and partners supporting the SaaS product.
    • Maintain a current inventory of vendors, subprocessors, and associated risk assessments.
  • Customer Assurance
    • Serve as the primary point of contact for responding to customer security questionnaires, RFPs, and due diligence requests.
    • Leverage existing documentation (e.g., SOC 2 report, pen test, whitepapers, DPA) and collaborate with technical teams to provide accurate and timely responses.
    • Assist Sales, Customer Success, and Legal with deal acceleration by enabling trust in our security and compliance posture.

What You'll Bring
  • 4-6+ years of experience in security compliance, risk, or privacy-preferably in a B2B SaaS or cybersecurity company.
  • Deep understanding of compliance frameworks (e.g., SOC2, ISO:27001, NIST AI RMF, NIST 800-53, etc.) and experience leading annual audits.
  • Expertise in GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. data privacy laws.
  • Strong working knowledge of third-party risk management practices and vendor due diligence processes.
  • Experience responding to security questionnaires, RFPs, and customer audits.
  • Familiarity with common SaaS infrastructure (e.g., AWS, Okta, MDM, SIEM, DLP, etc.).
  • Excellent communication skills and the ability to translate complex compliance concepts for both technical and non-technical stakeholders.
  • Certifications such as CIPP/US, CIPT, CISA, CRISC, or ISO Lead Implementer are a strong plus.


What Sets You Apart?
  • You've led multiple SOC 2 Type II audits from start to finish and know how to navigate both the auditor's requirements and the business's operational realities.
  • You have a deep working knowledge of global and U.S. privacy laws, including GDPR, CCPA/CPRA, and stay ahead of the evolving regulatory landscape.
  • You're a trusted partner across Sales, Legal, Security, and Engineering-balancing compliance rigor with practical business execution.
  • You've built or managed a vendor risk management program and know how to evaluate technical controls, assess privacy risk, and communicate findings clearly.
  • When faced with a massive security questionnaire or RFP, you know how to cut through complexity, collaborate with SMEs, and deliver confident, timely responses.
  • You hold industry-recognized certifications like CIPP/US, CISA, or ISO 27001 Lead Implementer, demonstrating your commitment to professionalism and subject matter expertise..


Compensation and Values

At Horizon3, we believe that our people are our greatest asset, and our compensation philosophy reflects this core value. We are committed to fostering an environment where all employees feel valued, respected, and rewarded for their contributions. Our compensation structure is designed to be fair, competitive, and transparent, ensuring that every team member is recognized and compensated equitably across roles, levels, and locations.

In accordance with various State's transparency regulations, we provide the following salary range information for this position:
  • Base salary range: $109,000 - $135,000 annually. The exact salary will be determined based on the selected candidate's location, qualifications, experience, and relevant skills.
  • Additional compensation: All full-time roles are eligible for an equity package in the form of stock options.


Perks of Horizon3.ai
  • Inclusive Team: We value diversity and promote an inclusive culture where everyone can thrive.
  • Growth Opportunities: Be part of a dynamic and growing team with numerous career development opportunities.
  • Innovative Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking.
  • Hybrid & Remote Work: We embrace a mix of remote and hybrid work models depending on role and location, including our Chicago office, where some roles require regular in-office presence.
  • Competitive Compensation: We offer competitive salary, equity and benefits. Our benefits include health, vision & dental insurance for you and your family, a flexible vacation policy, and generous parental leave.


Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.

Application Note

In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.

About Horizon3.ai

Horizon3.ai is a California-based software company that provides artificial intelligence (AI) solutions for businesses. The company was founded in 2018 and is headquartered in Long Beach, California. Horizon3.ai offers a range of AI-powered products, including chatbots, virtual assistants, and predictive analytics tools. The company's solutions are designed to help businesses automate their operations, improve customer engagement, and gain insights from their data. Horizon3.ai serves clients in a variety of industries, including healthcare, finance, and retail.
Learn more about Horizon3.ai
Size
50 employees
Industry
Net Income
-$100,000
Founded
2018
5 Year Trend
+50%
Revenue
$500,000

Similar Jobs

More Jobs at Horizon3.ai

More Information Technology Jobs

Find similar Senior Compliance Analyst jobs: