Compliance & Security Analyst
Austin, TXOnsite1+ YOE
Summary
Supports Head of IT & Compliance in SOC 2 program by collecting evidence, coordinating audits, and tracking security vulnerabilities. Requires 1-3+ years in compliance/security, experience with Drata, and cross-functional collaboration.
About the role
Key Responsibilities
- Collect, organize, and maintain evidence required for SOC 2 compliance audits
- Partner closely with Engineering, IT, Security, and other internal teams to gather required documentation and artifacts
- Work within compliance platforms (primarily Drata) to track controls, monitor status, and ensure timely completion of tasks
- Assist in preparing for audits by ensuring all evidence is complete, accurate, and audit-ready
- Collaborate with external auditors to respond to requests and provide additional documentation as needed
- Identify gaps or inconsistencies in compliance documentation and drive follow-ups with stakeholders
- Support ongoing compliance initiatives and process improvements
Security & Application Security:
- Track and help coordinate remediation of vulnerabilities identified through security scans and penetration tests
- Assist in planning and coordinating periodic penetration tests (scoping, scheduling, and documentation)
- Support documentation and validation of application security controls and secure development practices
- Partner with Engineering to ensure security findings are properly addressed and reflected in compliance artifacts
Qualifications
- 1–3+ years of experience in compliance, security, or audit support roles
- Hands-on experience with SOC 2 evidence collection and audit processes
- Experience with compliance automation platforms, Drata strongly preferred
- Familiarity with vulnerability management and/or application security workflows, i.e. pentesting
- Experience working cross-functionally with Engineering, IT, or Security teams
- Strong organizational skills with high attention to detail
- Ability to manage multiple requests and deadlines in a fast-paced environment
Nice to Have
- Familiarity with security tools (SAST, DAST, vulnerability scanners)
- Experience in SaaS or technology environments
- Familiarity with additional frameworks (ISO 27001, HIPAA, etc.)
Perks & Benefits
- Competitive salary
- Equity compensation
- Medical, dental, vision, and life insurance
- Unlimited PTO
- 401(k) match
- Maternity/paternity leave
- Fully-subsidized downtown parking
- Weekly lunch stipend
- Full access to onsite gym and locker rooms
- Monthly team get-togethers (Lunches, social events, sports outings, etc)
Skills
SOC 2DrataVulnerability ManagementPenetration TestingSASTDASTISO 27001HIPAA