Snorkel AI Logo

Snorkel AI

Senior Technical Compliance Analyst

Posted One Month Ago
In-Office
San Francisco, CA, USA
150K-220K Annually
Mid level
In-Office
San Francisco, CA, USA
150K-220K Annually
Mid level
Maintain SOC 2 Type I and Type II compliance, coordinate audits and remediation, automate evidence collection through Vanta and Drata, manage access reviews and policy governance, support customer security questionnaires, and align controls with NIST, FedRAMP, and CMMC requirements. Partner with engineering and security teams on compliance-as-code, cloud controls, vendor risk management, metrics, incident evidence preservation, and federal readiness.
The summary above was generated by AI

About Snorkel

At Snorkel, we believe meaningful AI doesn’t start with the model, it starts with the data.

We’re on a mission to help enterprises transform expert knowledge into specialized AI at scale. The AI landscape has gone through incredible changes since 2015, when Snorkel started as a research project in the Stanford AI Lab, to the generative AI breakthroughs of today. But one thing has remained constant: the data you use to build AI is the key to achieving differentiation, high performance, and production-ready systems. We work with some of the world’s largest organizations to empower scientists, engineers, financial experts, product creators, journalists, and more to build custom AI with their data faster than ever before. Excited to help us redefine how AI is built? Apply to be the newest Snorkeler!

Job Description

We are seeking a hands-on, builder-minded Senior Technical Compliance Analyst to serve as the operational engine behind our Trust & Security program.

You will maintain our SOC 2 Type II posture, drive our second entity from Type I to Type II, and act as the bridge between compliance requirements and engineering & delivery execution. You will also lay the technical groundwork to evolve us toward **CMMC 2.0**, ensuring we are ready for federal contracts without slowing down our product velocity.

**This is not a "compliance cop" role.** We practice **"Yes, if..."** security—you will influence architecture, automate policy enforcement, and unblock enterprise sales by ensuring the Security team has pristine, verifiable evidence at their fingertips.

 
What You will Do

Powering Customer Trust & Revenue Enablement

  • The Engine Behind Revenue: Help drafting accurate, technically precise responses to RFPs, security questionnaires (CAIQ, SIG, custom risk assessments), and customer portals.
  • Repository Stewardship: Own and continuously update the "Library of Truth"—a pristine repository of pre-vetted security evidence, technical configurations, and policy documents. By keeping this repository audit-ready, you enable the Security team to respond to enterprise prospects in hours, not days.
  • Technical Depth on Demand: When a customer asks about AWS KMS encryption, logging pipelines, or IAM privilege escalation paths, you retrieve the granular evidence and draft the written narrative the Security and Legal Team needs to confidently close the deal.

Building Compliance into the DNA

  • Compliance Partner: Partner with IT, Security, Product, Engineering, and Delivery early in the development lifecycle. Review new features, infrastructure changes, and vendor integrations to influence architectural decisions that bake in compliance by design—without creating friction or slowing sprints.
  • Policy as Guardrails: Write, update, and operationalize security policies that accelerate delivery. Translate abstract SOC 2 and NIST controls into clear, developer-friendly tasks (e.g., IAM hardening, log retention, Zero Trust implementation).
  • Compliance-as-Code: Where possible, automate policy enforcement in CI/CD pipelines so that security checks are invisible, automated, and frictionless for engineering teams.
  • Enablement, Not Enforcement: Conduct lightweight compliance enablement sessions with engineering teams—showing them how to self-serve evidence collection and interpret compliance requirements—so security becomes everyone's responsibility, not just yours.

Operational GRC & Audit Excellence

  • Audit Lifecycle Management: Drive and coordinate the end-to-end SOC 2 Type I and Type II audit cycles across our business entities. Manage audit schedules, coordinate with external auditors, and drive remediation of findings to keep us perpetually audit-ready.
  • GRC Automation: Be the power-user of our modern GRC stack (Vanta, Drata). Automate evidence collection, continuously monitor technical controls, and eliminate manual spreadsheet tracking.
  • Operational Cadences: Manage the compliance ticketing queue in Jira. Execute routine mandates including quarterly User Access Reviews (UAR), security awareness training, phishing simulations, and managing the Risk Acceptance/Exception process.
  • Metrics & Reporting: Build and maintain compliance dashboards (KPIs/KRIs) for the Security Lead and executive team. Track audit readiness scores, remediation SLAs, and control health trends to provide clear visibility into our posture.
  • Policy Governance: Manage the annual policy review and attestation cycle—ensuring process owners review, sign off, and update documentation on schedule, keeping our policies evergreen.

Future Federal & Supply Chain Roadmap

  • Foundation for Federal Growth: Assist the Security Team in aligning current controls with federal standards—specifically NIST SP 800-53, NIST SP 800-171 Rev 3, FedRAMP, and CMMC 2.0. Help draft early System Security Plans (SSPs) and Plan of Action & Milestones (POA&Ms).
  • Supply Chain Risk Management (C-SCRM): Own the third-party vendor review process, assessing critical partners (Cloud, HRIS, CRM) to meet strict federal supply chain requirements and offload this operational work from the Security Lead.
  • Incident Readiness: Support the Security Team during security incidents by preserving audit-relevant evidence, documenting the chronology of events, and drafting post-incident reports to satisfy regulatory and audit requirements.
Who You Are
  • Experience: 2–5 years of experience in technical compliance, IT audit, or GRC within a SaaS or fast-paced startup environment.
  • Audit Mastery: Proven end-to-end experience supporting external SOC 2 Type I and Type II audits—with specific expertise auditing IT General Controls (ITGC) (Change Management, Logical Access, System Operations). You know how to manage auditors and translate their requests into actionable developer tasks.
  • Technical Acumen: Strong understanding of modern cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD pipelines, encryption standards, and vulnerability management. You can read a Terraform plan or an AWS Config rule and interpret its compliance impact.
  • Tooling: Experience operating automated compliance platforms (Vanta, Drata), tracking work in Jira, and security awareness platform (KnowBe4)
  • Mindset: You are a business enabler. You practice "Yes, if..." security—you negotiate secure alternatives rather than blocking releases or ignoring risks. You thrive in a partnership role, ensuring IT, Security, Engineering, and Delivery teams have everything they need to succeed.
  • Communication: Exceptional written and verbal communication skills with the ability to explain technical controls to customers and business risks to engineers. 
Why Join Us?
  • Direct Revenue Impact: Your work directly correlates to revenue. By building the "Library of Truth," you ensure the Security team can close enterprise deals faster and more confidently.
  • Be a Builder, Not a Bureaucrat: You won't just check boxes. You will build automated, scalable compliance programs that enable the business to engineer quicker and sell faster.
  • Modern, Automated Tooling: Say goodbye to manual spreadsheet tracking. We leverage continuous-monitoring GRC tech so you can focus on technical risk and architecture, not admin overhead.
  • Future-Proof Career Growth: Gain rare, hands-on exposure to evolving a commercial SaaS startup into a federal-ready entity (FedRAMP/CMMC), highly accelerating your market value in the GRC space.

**This role is Hybrid Only. 3 days a week in our SF or NYC office.**

Actual compensation will be determined based on factors including skills, qualifications, experience, and geographic location.

Salary range(s) for this role
$150,000$220,000 USD

Be Your Best at Snorkel

Joining Snorkel AI means becoming part of a company that has market proven solutions, robust funding, and is scaling rapidly—offering a unique combination of stability and the excitement of high growth. As a member of our team, you’ll have meaningful opportunities to shape priorities and initiatives, influence key strategic decisions, and directly impact our ongoing success. Whether you’re looking to deepen your technical expertise, explore leadership opportunities, or learn new skills across multiple functions, you’re fully supported in building your career in an environment designed for growth, learning, and shared success.

Snorkel AI is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. Snorkel AI embraces diversity and provides equal employment opportunities to all employees and applicants for employment. Snorkel AI prohibits discrimination and harassment of any type on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local law. All employment is decided on the basis of qualifications, performance, merit, and business need.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

HQ

Snorkel AI Redwood, California, USA Office

55 Perry Street, Redwood, CA, United States, 94063

Similar Jobs

7 Minutes Ago
Remote or Hybrid
United States
Senior level
Senior level
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Design and implement AI agents, plugins, automations, and enterprise integrations for HR Technology platforms. Lead requirements gathering, technical analysis, solution design, testing, documentation, deployment, security, and data integrity efforts across HR, IT, and business stakeholders. Integrate platforms including ServiceNow, Workday, and other enterprise applications while supporting the HR automation and AI roadmap.
Top Skills: APIsAutomation AnywhereAWSAzureConcurGCPKnimeServicenowServicenow RpaUipathWorkdayWorkday Hcm
7 Minutes Ago
Remote or Hybrid
United States
106K-141K Annually
Senior level
106K-141K Annually
Senior level
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Leads aftersales performance across a regional dealership territory, driving revenue, customer retention, customer satisfaction, and KPI achievement. Advises dealer leadership, executes Customer Care and Aftersales initiatives, develops business plans, analyzes dealership performance, improves service operations, and resolves customer concerns. The role requires extensive field travel, automotive service and parts expertise, data analysis, consultative influence, and autonomous decision-making.
Top Skills: Automotive Parts And Service SystemsData Analytics ToolsDealer Operating ReportsFixed Ops Analysis ToolsExcelSales Reporting Tool (Srt)
7 Minutes Ago
Hybrid
80K-126K Annually
Junior
80K-126K Annually
Junior
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Implements lean manufacturing systems, analyzes throughput and bottlenecks, develops standardized work, and drives continuous improvement in a high-volume automotive manufacturing environment. The role coordinates plant-floor problem solving, process changes, ergonomic improvements, facility and workstation layouts, safety adherence, and production readiness. It works closely with production, manufacturing engineering, suppliers, and other departments to optimize labor, materials, equipment, space, quality, and cost.
Top Skills: Assembly Processing Systems (Aps)CadLean Manufacturing SystemsMS OfficePlant Simulation SoftwareStandard Time Data Systems (Stds)

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account