# Senior Analyst, Security Compliance

**Company:** [Kraken](https://hotfix.jobs/companies/kraken)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** Soc 1, SOC 2, Sox 404, It Audit, Icfr, It General Controls, It Application Controls, Cloud Computing, Iaas, Paas, SaaS, Access Management, Change Management, Nist, ISO 27001
**Posted:** 2026-02-13

> Leads SOC examinations, SOX compliance, IT control assessments, and remediation across security, technology, engineering, and finance teams. Requires 5+ years of external IT audit or technology risk experience, strong ICFR/SOX expertise, and familiarity with cloud environments.

## Job Description

## Responsibilities
- Lead and manage SOC 1 and SOC 2 examinations under AICPA standards, partnering with external auditors and internal teams to design, implement, and improve IT control processes.
- Support end-to-end SOX planning and execution, including IT system scoping, audit readiness, and training for control owners.
- Advise Security, IT, Infrastructure, Engineering, Data, and Finance teams by translating SOX and audit requirements into practical, scalable controls.
- Lead security and IT control gap assessments, evaluate control design and operating effectiveness, and drive remediation to completion.
- Mature IT general controls (ITGCs) and IT application controls (ITACs) while balancing regulatory expectations with product and platform innovation.
- Oversee audit initiatives, identify control gaps, assess risk, and guide teams through complex audit and compliance matters.
- Perform SOX control-deficiency impact assessments and develop risk-based remediation plans.
- Implement and enhance controls monitoring and defense-in-depth across key IT risk areas.
- Identify systemic program challenges, recommend process improvements, and drive durable solutions.
- Develop auditor-ready documentation, including data-flow diagrams and process flowcharts for high-risk security and financial processes.
- Work with internal and external auditors to navigate the IT control environment and ensure efficient, high-quality audits.
- Support evidence collection and continuous improvement, including automation to improve efficiency, consistency, and scalability.

## Requirements
- 5+ years of experience in external IT audit and/or technology risk assurance or advisory.
- Hands-on experience with Internal Controls over Financial Reporting (ICFR), including SOX 404 frameworks, control design, and operating-effectiveness testing.
- Experience at a Big Four or other large public accounting firm, or equivalent experience working with external auditors in a highly regulated environment.
- Experience leading compliance and audit initiatives from planning and risk assessment through remediation and audit close.
- Experience auditing or assessing hybrid and cloud-based environments, including IaaS, PaaS, and SaaS.
- Knowledge of access management, change management, and logging and monitoring controls.
- Ability to operate autonomously in ambiguous, fast-paced environments and drive cross-functional outcomes.
- Strong oral and written communication skills for technical and non-technical stakeholders.
- Ability to manage multiple priorities, coordinate cross-functional work, and hold stakeholders accountable.
- Strong organizational and time-management skills, self-motivation, and effectiveness in remote or distributed environments.

## Nice to Have
- Exposure to fintech, payments, crypto, or digital asset business models, including crypto audit experience.
- Familiarity with NIST, ISO 27001, or COBIT.
- CPA, CISA, CRISC, or similar professional certification.

## Compensation and Benefits
- Work in a modern infrastructure environment with exposure to cloud-native architectures and complex, real-time systems.
- Collaborate with globally distributed teams and professionals across engineering, security, and other technical disciplines.
- Influence how controls are designed and scaled in a fast-growing, regulated technology business.
- Gain ownership and visibility while helping shape a maturing audit and compliance program.

## Similar jobs

- [Senior Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96) - Docker - Remote - €119k – €170k/yr
- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr

**Apply:** https://hotfix.jobs/jobs/d0636665-94df-4977-9525-c00c7e8e847e
**Canonical:** https://hotfix.jobs/jobs/d0636665-94df-4977-9525-c00c7e8e847e