
Compliance Engineer
TRM Labs
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
Salary
💰 $125,000 - $142,000 per year
About the role
- Develop scalable and sustainable processes and tools for normalized controls, collecting audit evidence, monitoring controls, and conducting gap analyses.
- Manage TRM’s existing security compliance and certification lifecycle (e.g., SOC 2 Type II, ISO 27001/27701, FedRAMP, CMMC) while planning for and prioritizing future compliance needs.
- Operationalize the GRC program to maintain our regulatory certifications.
- Manage customer due diligence requests including developing and maintaining security collateral for customers (e.g., SIG, CAIQ).
- Conduct enterprise risk assessments and manage the risk registry.
- Develop a vendor risk management program.
- Identify areas for improvement based on input from customers, the go-to-market teams, and overall business objectives. Anticipate customer needs with respect to compliance and due diligence.
Requirements
- Develop automation to programmatically implement controls validations and evidence collections. Experience with Python or other programming and scripting languages is required.
- Work to align advanced technologies and Privacy by Design principles from the first stages of development and ensure that the data use meets established regulatory compliance needs.
- Strong understanding of Public Sector compliance security standards including NIST 800-53, SOC 2, CMMC, ISO, CyberEssentials UK, and other common compliance frameworks.
- Experience with leading a cloud-first SaaS company through the audit procesess.
- Strong focus on normalizing controls across frameworks and standards, with an eye toward improving maturity, scalability, and consistency over time, while looking beyond just “checking the box”.
- Privacy and GDPR experience is a plus.
- Security certifications (e.g., CISSP, CISM) are a plus.
Benefits
- Opportunity to participate in TRM’s equity plan
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
Pythonprogramming languagesscripting languagesautomationcontrols validationsevidence collectionsrisk assessmentsvendor risk managementcompliance frameworksdata use compliance
Soft Skills
customer focusanticipation of customer needscollaborationproblem-solvingorganizational skillscommunication skillsleadershipadaptabilitystrategic thinkingattention to detail
Certifications
SOC 2 Type IIISO 27001ISO 27701FedRAMPCMMCCISSPCISMNIST 800-53CyberEssentials UKGDPR