SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Compliance Analyst

Horizon3.ai - Remote - Remote - posted 2026-07-24

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Horizon3.ai is a fast-growing remote cybersecurity company that delivers autonomous penetration testing and security assessment operations at scale. The company's flagship NodeZero platform helps organizations proactively identify and fix exploitable attack vectors before criminals exploit them, serving organizations from educational institutions to Global 100 enterprises. As Senior Compliance Analyst, you will serve as the subject matter expert for compliance and data privacy within the Security team, playing a critical role in maintaining trust with customers, regulators, and partners. This role is instrumental in scaling and maturing the company's compliance and data privacy capabilities while maintaining a strong security posture. Key responsibilities include: Compliance & Audit Management: Lead SOC 2 Type II compliance efforts including control mapping, evidence collection, and audit coordination. Maintain and improve the control environment for SOC 2, ISO 27001, NIST AI RMF, DORA, and NIST 800-53 compliance. Collaborate with Engineering, IT, Legal, and HR teams to implement and validate control requirements. Data Privacy Compliance: Oversee the organization's privacy program ensuring compliance with GDPR, CCPA/CPRA, EU AI Act, and emerging U.S. state data privacy laws. Maintain records of processing activities, manage data subject access requests, and conduct privacy impact assessments. Work with Legal and Product teams on privacy-by-design principles. Vendor Risk Management: Own the third-party risk management lifecycle including onboarding reviews, periodic reassessments, and contract/privacy reviews. Conduct security and privacy due diligence on vendors and partners. Maintain current inventory of vendors, subprocessors, and risk assessments. Customer Assurance: Serve as primary point of contact for customer security questionnaires, RFPs, and due diligence requests. Leverage existing documentation and collaborate with technical teams to provide timely responses. Support Sales, Customer Success, and Legal with deal acceleration. You bring 4–6+ years of experience in security compliance, risk, or privacy, preferably in B2B SaaS or cybersecurity. You have deep understanding of compliance frameworks (SOC 2, ISO 27001, NIST AI RMF, NIST 800-53) and experience leading annual audits. Expertise in GDPR, CCPA/CPRA, EU AI Act, and emerging privacy laws is essential. Strong knowledge of third-party risk management, vendor due diligence, and SaaS infrastructure (AWS, Okta, MDM, SIEM, DLP) is required. Certifications such as CIPP/US, CIPT, CISA, CRISC, or ISO Lead Implementer are a strong plus.

Similar roles