Overview
Senior Compliance Analyst to operate AlphaSense’s compliance program, owning evidence collection and auditor engagement across ISO 27001, SOC 2, and ISO 42001.
What you'll do
- Own end-to-end evidence collection lifecycle for active audit and continuous compliance cycles.
- Coordinate with control owners to gather, validate, and organize evidence in a GRC platform (Drata or equivalent).
- Serve as primary operational point of contact for external auditors during Stage 1, Stage 2, and surveillance audits.
- Perform ongoing monitoring and periodic testing of implemented controls and document effectiveness.
- Maintain and update security policies, standards, and procedures aligned to framework requirements with version control.
- Identify and implement AI-augmented workflows for evidence gathering, control narrative drafting, and gap analysis.
- Support AI governance efforts related to EU AI Act, ISO 42001, and NIST AI RMF, including risk assessments and audit evidence.
What you'll need
- 6+ years of experience in GRC, information security, risk management, or IT audit.
- Strong understanding of SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; working knowledge of ISO 42001 and NIST AI RMF.
- AI-native mindset using AI tools (LLMs, agents, automation) with human-in-the-loop validation.
- Proficiency with GRC platforms for evidence management and control testing (e.g., Drata, Vanta, AuditBoard, ServiceNow GRC).
- Familiarity with cloud environments (AWS, Azure, or GCP) and related security/compliance posture tooling (CSPM, SIEM, identity platforms).
- Experience supporting external audits, including evidence collection, control walkthroughs, and auditor interaction.
- Hands-on experience managing end-to-end audit evidence collection for ISO 27001 and SOC 2 Type II (or equivalent).
Nice to have
- Relevant certifications such as CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/Implementer.
- Exposure to SOX ITGC cycles and privacy program crossover (data mapping, DPIAs, GDPR/CCPA operational compliance).
- Scripting/automation experience (Python, JavaScript, or low-code tools) applied to GRC/compliance workflows.
- Experience with ISO 27001 and ISO 42001 AI management system audits or EU AI Act compliance documentation.
- Programming skills for policy-as-code/compliance-as-code approaches and compliance workflow automation.
- Experience building or operating a security awareness and phishing simulation program.