Serve as the primary compliance authority for our engineering team, translating SOC 2, ISO 27001, HIPAA, PCI DSS, and NIST CSF requirements into detailed technical specifications for our automation platform
Interface directly with auditors evaluating our platform, answering technical questions about compliance methodology, control validation, and evidence collection processes
Design and validate automated audit workflows to ensure they meet professional auditing standards and produce audit-ready documentation
Review and approve platform features to guarantee compliance with framework requirements and auditing best practices
Develop technical documentation and training materials for auditors learning to use our platform effectively
Collaborate with engineering to build AI agents that can automatically assess control implementation, collect evidence, and flag compliance gaps
Stay current with regulatory changes and auditing standard updates, ensuring our platform evolves with industry requirements
Support sales conversations by demonstrating to prospective auditing firms how our platform enhances their audit capabilities and efficiency
You should have
4+ years of hands-on compliance auditing or implementation experience, with deep understanding of what auditors require from compliance tools and evidence
Extensive experience conducting SOC 2 Type 1 and Type 2 audits, including evidence collection, control testing, and report preparation methodologies
Deep technical knowledge of ISO 27001, HIPAA, PCI DSS, and NIST Cybersecurity Framework control requirements and testing procedures
Experience working with auditing firms or as an auditor, with understanding of professional auditing standards and quality requirements
Proven ability to translate complex compliance requirements into technical specifications that developers can implement
Advanced degree in cybersecurity, information security, cyber law, or related field
Skilled certifications such as