ForgeApply
Try it free

ForgeApply · Job listing

Technical Compliance Analyst

Snorkel AI

New York City, NY (Hybrid); San Francisco, UShybrid

See all 42 open roles at Snorkel AI

Tailor your resume for this Snorkel AI job in about a minute.

ForgeApply rewrites your resume for this exact posting, then autofills the application on Snorkel AI's site with it. You review everything before it's sent. Free trial, no card required.

About this role

About Snorkel

At Snorkel, we believe meaningful AI doesn’t start with the model, it starts with the data.

We’re on a mission to help enterprises transform expert knowledge into specialized AI at scale. The AI landscape has gone through incredible changes since 2015, when Snorkel started as a research project in the Stanford AI Lab, to the generative AI breakthroughs of today. But one thing has remained constant: the data you use to build AI is the key to achieving differentiation, high performance, and production-ready systems. We work with some of the world’s largest organizations to empower scientists, engineers, financial experts, product creators, journalists, and more to build custom AI with their data faster than ever before. Excited to help us redefine how AI is built? Apply to be the newest Snorkeler!

Job Description

We are seeking a hands-on, builder-minded Technical Compliance Analyst to serve as the operational engine behind our Trust & Security program.

You will maintain our SOC 2 Type II posture, drive our second entity from Type I to Type II, and act as the bridge between compliance requirements and engineering & delivery execution. You will also lay the technical groundwork to evolve us toward **CMMC 2.0**, ensuring we are ready for federal contracts without slowing down our product velocity.

**This is not a "compliance cop" role.** We practice **"Yes, if..."** security—you will influence architecture, automate policy enforcement, and unblock enterprise sales by ensuring the Security team has pristine, verifiable evidence at their fingertips.

What You will Do

Powering Customer Trust & Revenue Enablement

• The Engine Behind Revenue: Help drafting accurate, technically precise responses to RFPs, security questionnaires (CAIQ, SIG, custom risk assessments), and customer portals.

• Repository Stewardship: Own and continuously update the "Library of Truth"—a pristine repository of pre-vetted security evidence, technical configurations, and policy documents. By keeping this repository audit-ready, you enable the Security team to respond to enterprise prospects in hours, not days.

• Technical Depth on Demand: When a customer asks about AWS KMS encryption, logging pipelines, or IAM privilege escalation paths, you retrieve the granular evidence and draft the written narrative the Security and Legal Team needs to confidently close the deal.

Building Compliance into the DNA

• Compliance Partner: Partner with IT, Security, Product, Engineering, and Delivery early in the development lifecycle. Review new features, infrastructure changes, and vendor integrations to influence architectural decisions that bake in compliance by design—without creating friction or slowing sprints.

• Policy as Guardrails: Write, update, and operationalize security policies that accelerate delivery. Translate abstract SOC 2 and NIST controls into clear, developer-friendly tasks (e.g., IAM hardening, log retention, Zero Trust implementation).

• Compliance-as-Code: Where possible, automate policy enforcement in CI/CD pipelines so that security checks are invisible, automated, and frictionless for engineering teams.

• Enablement, Not Enforcement: Conduct lightweight compliance enablement sessions with engineering teams—showing them how to self-serve evidence collection and interpret compliance requirements—so security becomes everyone's responsibility, not just yours.

Operational GRC & Audit Excellence

• Audit Lifecycle Management: Drive and coordinate the end-to-end SOC 2 Type I and Type II audit cycles across our business entities. Manage audit schedules, coordinate with external auditors, and drive remediation of findings to keep us perpetually audit-ready.

• GRC Automation: Be the power-user of our modern GRC stack (Vanta, Drata). Automate evidence collection, continuously monitor technical controls, and eliminate manual spreadsheet tracking.

• Operational Cadences: Manage the compliance ticketing queue in Jira. Execute routine mandates including quarterly User Access Reviews (UAR), security awareness training, phishing simulations, and managing the Risk Acceptance/Exception process.

• Metrics & Reporting: Build and maintain compliance dashboards (KPIs/KRIs) for the Security Lead and executive team. Track audit readiness scores, remediation SLAs, and control health trends to provide clear visibility into our posture.

• Policy Governance: Manage the annual policy review and attestation cycle—ensuring process owners review, sign off, and update documentation on schedule, keeping our policies evergreen.

Future Federal & Supply Chain Roadmap

• Foundation for Federal Growth: Assist the Security Team in aligning current controls with federal standards—specifically NIST SP 800-53 , NIST SP 800-171 Rev 3 , FedRAMP , and CMMC 2.0 . Help draft early System Security Plans (SSPs) and Plan of Action & Milestones (POA&Ms).

• Supply Chain Risk Management (C-SCRM): Own the third-party vendor review process, assessing critical partners (Cloud, HRIS, CRM) to meet strict federal supply chain requirements and offload this operational work from the Security Lead.

• Incident Readiness: Support the Security Team during security incidents by preserving audit-relevant evidence, documenting the chronology of events, and drafting post-incident reports to satisfy regulatory and audit requirements.

Who You Are

• Experience: 2–5 years of experience in technical compliance, IT audit, or GRC within a SaaS or fast-paced startup environment.

• Audit Mastery: Proven end-to-end experience supporting external SOC 2 Type I and Type II audits—with specific expertise auditing IT General Controls (ITGC) (Change Management, Logical Access, System Operations). You know how to manage auditors and translate their requests into actionable developer tasks.

• Technical Acumen: Strong understanding of modern cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD pipelines, encryption standards, and vulnerability management. You can

Salary insight

This posting doesn't disclose pay. Across 8,673 San Francisco jobs with disclosed salaries on ForgeApply, the median is $200k.

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Snorkel AI role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)