SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Snorkel AI is seeking a Technical Compliance Analyst to serve as the operational engine behind the Trust & Security program. This is a hands-on, builder-minded role focused on maintaining SOC 2 Type II compliance, driving a second entity from Type I to Type II, and laying technical groundwork for CMMC 2.0 readiness to support federal contracting.
Key responsibilities include:
**Revenue Enablement & Customer Trust**: Draft technically precise responses to RFPs, security questionnaires (CAIQ, SIG), and risk assessments. Own and maintain the "Library of Truth"—a repository of pre-vetted security evidence, technical configurations, and policy documents that enables the Security team to respond to enterprise prospects in hours rather than days. Provide technical depth on AWS KMS encryption, logging pipelines, IAM configurations, and other infrastructure details needed to close enterprise deals.
**Compliance Integration**: Partner with IT, Security, Product, Engineering, and Delivery teams early in the development lifecycle to influence architectural decisions that bake compliance in by design. Write and operationalize security policies that translate SOC 2 and NIST controls into developer-friendly tasks. Automate policy enforcement in CI/CD pipelines where possible. Conduct lightweight compliance enablement sessions with engineering teams to foster shared responsibility.
**GRC & Audit Operations**: Drive end-to-end SOC 2 Type I and Type II audit cycles. Manage audit schedules, coordinate with external auditors, and drive remediation. Serve as power-user of modern GRC tools (Vanta, Drata) to automate evidence collection and continuously monitor technical controls. Execute routine mandates including quarterly User Access Reviews, security awareness training, phishing simulations, and risk exception management. Build compliance dashboards and KPIs for leadership visibility. Manage annual policy review and attestation cycles.
**Federal Readiness**: Assist in aligning current controls with federal standards, specifically NIST SP 800 and CMMC 2.0, to position the company for federal contracts without compromising product velocity.
This is not a "compliance cop" role—the philosophy is "Yes, if..." security, where the analyst influences architecture, automates enforcement, and unblocks sales by providing pristine, verifiable evidence.