Skip to main content
AlphaSense

Senior Compliance Analyst

RemoteIndia only
Published
Role
Security
Experience
Senior
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to IN only. Set where you work from to check your eligibility.

No BS summary

Senior GRC/compliance analyst with 6+ years in information security, risk management, or IT audit, ideally SaaS or cloud-native. Must own ISO 27001, SOC 2, ISO 42001 audit evidence and external auditor engagement, with GRC platforms, cloud security tooling, privacy requirements, and AI-assisted workflows. Remote role hiring in India.

Core skills

SOC 2ISO 27001GRC platforms

Required skills

NIST CSF 2.0CIS ControlsISO 42001NIST AI RMFLLMsAI agentsAI automationDrata/Vanta/AuditBoard/ServiceNow GRCAWS/Azure/GCPCSPMSIEMGDPRCCPA/CPRA

Optional skills

CISACRISCCISMCISSPCCSKISO 27001 Lead AuditorISO 27001 Lead ImplementerEU AI Act

What you'll do

  • Own the full evidence collection lifecycle across all active audit and continuous compliance cycles.
  • Coordinate with control owners to gather, validate, and organize evidence artifacts in the GRC platform.
  • Use AI-assisted workflows to pre-stage evidence, flag stale artifacts, and reduce the manual burden on engineering and IT teams.
  • Serve as the primary operational point of contact for external auditors during Stage 1, Stage 2, and surveillance audits.
  • Manage auditor portals, respond to RFIs, track open items to closure, and ensure auditors have a complete, accurate view of AlphaSense’s controls.
  • Perform ongoing monitoring and periodic testing of implemented controls.
  • Document control effectiveness, identify gaps, and work with control owners to remediate deficiencies on defined timelines.
  • Map findings to applicable framework requirements across SOC 2, ISO 27001, and ISO 42001.
  • Contribute to transitioning point-in-time control testing toward continuous, automated validation.
  • Maintain and update security policies, standards, and procedures aligned with operational reality and framework requirements.
  • Ensure documentation is version-controlled, accessible, distributed, and attested to without relying on static PDFs or manual tracking.
  • Identify and implement opportunities to use AI tools to streamline evidence gathering, control narrative drafting, audit preparation, and gap analysis.
  • Validate AI-assisted compliance output for accuracy, completeness, and confidentiality before anything ships.
  • Share effective AI-augmented compliance practices with the broader GRC team.
  • Support compliance efforts related to AI regulations and standards including EU AI Act, ISO 42001, and NIST AI RMF.
  • Assist with risk assessments, documentation, and audit evidence for AI governance controls.
  • Collaborate with Engineering and Product to ensure secure and responsible use of generative AI tools across the organization.
  • Partner with Engineering, IT, Legal, and Product to ensure control ownership is clear, evidence is available, and compliance requirements are embedded into operational processes.
  • Provide risk and control guidance on post-implementation reviews and remediation activities.
  • Help stakeholders interpret requirements and build controls into how they actually work.

What they require

  • 6+ years of experience in GRC, information security, risk management, or IT audit, preferably in a SaaS or cloud-native environment.
  • Strong understanding of security and compliance frameworks including SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; working knowledge of ISO 42001 and NIST AI RMF.
  • AI-native mindset: you use AI tools—LLMs, agents, automation—for real, substantive work including analysis, drafting, evidence gathering, and workflow automation.
  • You apply judgment about where AI creates leverage and where a human must stay in the loop.
  • Proficiency with GRC platforms for evidence management and control testing, such as Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent.
  • Familiarity with cloud environments such as AWS, Azure, or GCP and security and compliance posture tooling including CSPM, SIEM, and identity platforms.
  • Experience supporting external audits across security or privacy domains, including evidence collection, control walkthroughs, and auditor interaction.
  • Ability to interpret technical controls and translate findings into compliance, risk, and policy documentation that engineers and non-technical stakeholders both understand.
  • Working knowledge of risk registers, control libraries, and policy governance lifecycles.
  • Working knowledge of privacy and data protection requirements including GDPR and CCPA/CPRA and how they intersect with security controls, in partnership with Legal and Product teams.
  • Strong written communication, analytical thinking, and attention to detail.
  • Able to produce clear audit responses, risk narratives, and control documentation under deadline.
  • Hands-on experience managing end-to-end audit evidence collection across ISO 27001, SOC 2 Type II, or equivalent frameworks in a SaaS or cloud environment.
  • Direct operational experience working with external auditors as the primary compliance or audit liaison, including walkthroughs, RFI responses, and finding management.
  • Automation-first mentality with demonstrated experience working in an organization that has implemented automated evidence collection.
  • You default to building workflows over doing things manually, and actively improve the automation rather than working around it.
  • Demonstrated use of AI tools, including LLMs and AI-assisted GRC workflows, to accelerate compliance work such as drafting, research, evidence review, or gap analysis.
  • Clear practice of validating AI output before it ships.
  • Experience maintaining policy governance lifecycles from drafting through distribution, attestation, and version control.
  • Strong organizational skills and ability to manage multiple concurrent audit workstreams without losing detail.
  • Preferred: Relevant certifications: CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/Implementer.
  • Preferred: Experience with AI governance frameworks including ISO 42001, NIST AI RMF, EU AI Act, or OECD AI Principles.
  • Preferred: Exposure to SOX ITGC cycles—managing evidence, walkthroughs, and findings with external auditors.
  • Preferred: Privacy program crossover: data mapping, DPIAs, GDPR/CCPA operational compliance.
  • Preferred: Scripting or automation experience applied to GRC or compliance workflows.
  • Preferred: Experience with ISO 42001 AI management system audits or EU AI Act compliance documentation.
  • Preferred: Familiarity with policy-as-code and compliance-as-code approaches.
  • Preferred: Programming or scripting skills applied to compliance workflows, evidence automation, or GRC platform integrations.
  • Preferred: Experience building or operating a security awareness and phishing simulation program.
  • Preferred: Background in privacy compliance operations in partnership with Legal.

AlphaSense delivers AI-driven market intelligence and search built on public and private content including equity research, company filings, event transcripts, expert calls, news, trade journals, and clients’ own research content.

🇺🇸 United StatesTechnologyEnterprisealphasense.net/

Details

Apply routeGreenhouse
Salary not disclosed