The Senior Security Compliance Analyst will be key to continuing the advancement of Security Compliance at dbt Labs. In this role you will be assisting in advancing the maturity of our Security Compliance program, supporting customer trust activities, and more as the organization continues to grow.

In this role, you can expect to:

  • Be responsible for timely delivery of key projects (e.g. maintaining our continuous monitoring activities, reviewing control language, interfacing with various stakeholders in the org to implement key controls, additions to our tech stack)
  • Manage and document scalable Security processes to support our growth and compliance stance
  • Collaborate with Engineering, Legal, IT, and Security in maintaining and updating company security policies
  • Support and collaborate with various stakeholders to ensure our SaaS tools are configured and managed within our policies (e.g., perform internal audits and risk assessments of our security posture, provide security training to various parts of the organization)
  • Develop, maintain, and track remediation of items on the risk register
  • Document, track, and follow-up on security-related findings (e.g. non-compliance with security policies, track and report on privacy and security awareness training, maintaining risk register)
  • Coordinate external audits and evidence collection related to SOC2, ISO27001, ISO27701, and other future frameworks
  • Assist in completion of customer assurance activities, such as security questionnaires
  • Perform vendor security evaluations of existing and net new vendors

You are a good fit if you:

  • Have 4+ years of work experience with Security auditing and/or maintaining information security controls
  • Have 3+ years working with AWS and Azure
  • Have a working knowledge of ISO27001, SOC2 Trust Services Principles, GDPR, CCPA, NIST CSF, etc.
  • Have a passion for working with Security compliance, governance, and risk (GRC)
  • Are experienced developing and working with a governance, risk, and compliance (GRC) tool
  • Have procured, built, and/or delivered security awareness training
  • Have experience completing customer security questionnaires in support of enterprise-level accounts
  • Have built and/or maintained a security risk register
  • Are experienced in evaluating, leading and running business continuity and disaster recovery exercises
  • Can execute with urgency and attention to detail

You’ll have an edge if you have:

  • Working knowledge of data breach notification laws, international privacy regulations, HIPAA, ISO27701, current or upcoming AI frameworks, and more
  • Experience with quantitative risk management
  • Experience writing automations for security compliance activities (i.e. SQL, Python, dbt)
  • 1+ years working with Google Cloud
  • Additional Industry related certifications (ISO Lead Auditor, CISA, CISM, CISSP, CCSP, etc.)
  • Experience working in fast paced or hyper-growth companies
  • Working knowledge of the current best practices, and regulatory compliance landscape for AI

Compensation & Benefits

  • Salary: $125K-147K
  • Equity Stake
  • Benefits:
    • Unlimited vacation,
    • 401k w/ 3% guaranteed contribution,
    • excellent healthcare,
    • office and cell/internet stipends,
    • paid parental leave
    • and much more!
What to expect in the hiring process (all video interviews via Zoom unless accommodations are needed):

  • Interview with a Talent Acquisition Partner
  • Interview with Hiring Manager
  • Three Team Interviews (1:1s)
  • Final interview with one of our Values Carriers

#LI-RC1

Job Overview
Job alerts

Subscribe to our weekly job alerts below and never miss the latest jobs

Sign in

Sign Up

Forgotten Password

Job Quick Search

Cart

Basket

Share