
AlphaSense is maturing its GRC function and needs a Senior Compliance Analyst to be the operational engine of our compliance program. You will own end-to-end evidence collection and auditor engagement across our ISO 27001, SOC 2, and ISO 42001 certifications—serving as the primary operational liaison between AlphaSense and external assessors throughout Stage 1, Stage 2, and surveillance cycles. You will partner with control owners across Engineering, IT, and Legal to ensure we are continuously audit-ready, not just audit-reactive. Key Responsibilities Evidence Collection & Management: Own the full evidence collection lifecycle across all active audit and continuous compliance cycles. Coordinate with control owners to gather, validate, and organize evidence artifacts in the GRC platform (Drata or equivalent). Use AI-assisted workflows to pre-stage evidence, flag stale artifacts, and reduce the manual burden on engineering and IT teams. Auditor Engagement: Serve as the primary operational point of contact for external auditors during Stage 1, Stage 2, and surveillance audits. Manage auditor portals, respond to RFIs, track open items to closure. Control Testing & Monitoring: Perform ongoing monitoring and periodic testing of implemented controls. Document control effectiveness, identify gaps, and work with control owners to remediate deficiencies. Map findings to applicable framework requirements across SOC 2, ISO 27001, and ISO 42001. Policy & Documentation Governance: Maintain and update security policies, standards, and procedures. Ensure documentation is version-controlled, accessible, and demonstrably distributed. AI-Augmented Compliance Workflows: Identify and implement opportunities to use AI tools to streamline evidence gathering, control narrative drafting, audit preparation, and gap analysis. AI Governance & Emerging Regulation: Support compliance efforts related to AI regulations and standards including EU AI Act, ISO 42001, and NIST AI RMF. Cross-Functional Coordination & Advisory: Partner with Engineering, IT, Legal, and Product to ensure control ownership is clear and compliance requirements are embedded into operational processes. Who You Are Basic Requirements - 6+ years of experience in GRC, information security, risk management, or IT audit, preferably in a SaaS or cloud-native environment - Strong understanding of security and compliance frameworks including SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; working knowledge of ISO 42001 and NIST AI RMF - AI-native mindset: use of LLMs, agents, automation for analysis, drafting, and workflow automation - Proficiency with GRC platforms (Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent) - Familiarity with cloud environments (AWS, Azure, or GCP) - Experience supporting external audits across security or privacy domains - Working knowledge of privacy and data protection requirements (GDPR, CCPA/CPRA) - Strong written communication and analytical thinking Nice to Have - Relevant certifications: CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/Implementer - Experience with AI governance frameworks (ISO 42001, NIST AI RMF, EU AI Act) - Exposure to SOX ITGC cycles - Scripting or automation experience (Python, JavaScript, or low-code tools)
Job Details
Responsibilities
- Own end-to-end evidence collection and auditor engagement for ISO 27001, SOC 2, and ISO 42001
- Serve as the primary operational liaison for external assessors
- Perform ongoing monitoring and periodic testing of implemented controls
- Maintain and update security policies, standards, and procedures
- Implement AI-augmented workflows to streamline compliance tasks
- Support compliance efforts for AI regulations including EU AI Act and NIST AI RMF
- Partner with Engineering, IT, Legal, and Product teams to embed compliance into operational processes
Requirements
- 6+ years of experience in GRC, information security, risk management, or IT audit
- Experience in a SaaS or cloud-native environment
- Strong understanding of SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls
- Working knowledge of ISO 42001 and NIST AI RMF
- Proficiency with GRC platforms such as Drata, Vanta, AuditBoard, or ServiceNow GRC
- Familiarity with cloud environments (AWS, Azure, or GCP)
- Experience supporting external audits including evidence collection and auditor interaction
- Working knowledge of GDPR and CCPA/CPRA
- Strong written communication and analytical thinking skills
Skills & Technologies

Related Opportunities
Discover more opportunities that match your interests and skills