Senior InfoSec Risk & Compliance SpecialistThe InfoSec Compliance team supports SOC 2, SOX, and PCI audits, and its coverage is expanding quickly: new European requirements could bring approximately 33 additional products into scope, including products without existing SOC 2 reports, and emerging state-level cybersecurity requirements (including Colorado and California) are adding further obligations. Because headcount will not scale at the same pace as this expanding scope, technology and automation are central to how the team succeeds.
As a
Senior InfoSec Risk & Compliance Specialist, you will help modernize how the compliance function operates - moving the team from point-in-time, retrospective evidence collection toward continuous control monitoring and a shared foundation of evidence that supports multiple audits and regulatory obligations at once.
In This Role...- You will support SOC 2, SOX, and PCI audits, coordinating with external auditors and internal teams, and act as the first line of defense before internal or external review.
- You will move the team beyond screenshot collection and backward-looking reviews of whether a control operated over the prior period, designing continuous monitoring that surfaces control failures as they happen.
- You will identify opportunities to modernize compliance work - through API integrations, configurable GRC/compliance platforms, dashboards and visualizations, practical AI use, or well-built Excel solutions - and take ownership of implementing them.
- You will connect compliance findings to organizational risk, distinguishing significant control failures (for example, missing encryption) from lower-risk documentation gaps, and drive appropriately prioritized remediation.
- You will help build a common foundation of controls and evidence that can flex to support multiple regulatory obligations - SOC 2, SOX, PCI, and emerging EU and state requirements - without a one-to-one increase in headcount.
- You will support and provide some coaching and feedback to a Grade 600 teammate who owns aspects of the SOC 2 program; this role can appeal to someone building toward future people leadership, though no management progression is guaranteed.
- You will communicate tactical and strategic updates to business teams and leaders, and bring an autonomous, curious, and forward-thinking approach rather than repeating the same audit the same way each year.
What You Will Need to Succeed...- 5 to 7+ years of experience within IT Audit, GRC, Controls, Risk Assessment, or Internal Audit. Experience across all of SOC 2, SOX, and PCI is not required - core audit skills transfer well.
- At least one year of experience performing readiness assessments for SOC 2 (or comparable) compliance.
- One of these certifications: CISA, CISM, CISSP, CRISC, CRMA, or certification-eligible.
- Working knowledge of control and risk frameworks such as NIST, COSO, and COBIT, and how to develop and implement controls through them.
- Practical, hands-on use of AI tools in your day-to-day work - for example, using AI to digest and research complex or unfamiliar regulations. Experience building AI agents or automated compliance workflows is a strong plus, not a requirement.
- A track record of proactively identifying problems, proposing technology-based improvements (automation, integrations, dashboards, or similar), and owning them through implementation - autonomy, accountability, curiosity, and adaptability are central to this role.
- Comfort approaching unfamiliar or emerging requirements (for example, the EU AI Act or the NIST AI Risk Management Framework) by structuring the work yourself - scoping what exists, identifying gaps, and building a plan - rather than following an established playbook.
- Strong written and verbal communication, with the ability to build relationships at all levels of the organization and to coach or mentor less experienced teammates.
- The ability to handle difficult issues in a professional, assertive, and proactive manner.
- Location: We are only considering those within the New England area of Maine, New Hampshire or Massachusetts. If local, we offer a flexible, hybrid of 8 days per month on site and we will consider less if you are further away.
What You Can Expect From Us:- Base annual salary starting at $120,000, with flexibility based on experience
- Opportunity for annual cash bonus
- Health / Dental / Vision Benefits Day-One
- 5% matching 401k
- Additional benefits including but not limited to financial support, pet insurance, mental health resources, volunteer paid days off, employee stock program, foundation donation matching, and much more!