Compliance Analyst
This Compliance Analyst role at Harvey involves owning and maintaining compliance documentation, coordinating evidence collection, and supporting third-party assessments. The role requires hands-on compliance work, close collaboration with Engineering and Security teams, and a detail-oriented approach to ensure program health and continuous monitoring.
About the job
What You'll Do
- Own and maintain core compliance documentation — including compliance packages and security assessment reports — keeping them accurate and audit-ready
- Coordinate evidence collection across Engineering, Infrastructure, and Security for regulated assessments
- Support third-party assessor engagements end-to-end: scheduling, preparing teams, triaging findings, and drafting responses
- Conduct gap analyses against applicable frameworks and produce remediation tracking artifacts teams can act on directly
- Manage continuous monitoring activities including control reviews, change notifications, and incident documentation to maintain compliance status
- Partner with Engineering and Security to validate control implementations and translate regulatory language into testable technical configurations
What You Have
- 3–5+ years in information security compliance with hands-on exposure to government and industry frameworks in a SaaS or cloud environment
- Solid working knowledge of applicable government compliance frameworks; ability to map controls to technical implementations and evaluate evidence quality
- Experience maintaining compliance documentation and tracking remediation activities; familiarity with compliance automation tooling
- Exceptional attention to detail — able to manage multiple concurrent workstreams and keep documentation aligned with a dynamic cloud environment
- Clear communicator: able to write crisp control implementation statements and explain compliance requirements to engineering audiences
Compensation
$99,200 - $148,800
Skills
Information Security Compliance, Government Compliance Frameworks, SaaS, Cloud Environments, Compliance Automation Tooling
Similar jobs
Security Engineering jobsDevelop and operate global physical security systems, controls, and compliance processes across data centers and other facilities. The role manages investigations, risk mitigation, audits, vendor deployments, and cross-functional security initiatives, with approximately 35% travel required.
Security Engineer responsible for building detection and prevention controls, automating security operations, conducting threat hunts, and supporting incident response across a remote-first organization. Requires 3+ years of security or software development experience, cloud-native security expertise, and automation skills.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.