Delivery — Cybersecurity
Compliance & Risk Analyst
Build the compliance frameworks that make clients audit-ready.
Remote / US or IndiaRemoteFull-TimeReq CDC-022
About the role
The Compliance & Risk Analyst supports security engagements with regulatory compliance mapping, risk assessment, and continuous control evidence generation across frameworks including SOC 2, ISO 27001, PCI DSS, HIPAA, and FISMA.
What you will do
- Conduct risk assessments and gap analyses against compliance frameworks
- Map client security controls to SOC 2, ISO 27001, PCI DSS, HIPAA, NIST, and FISMA
- Develop policies, procedures, and control documentation for audit readiness
- Coordinate with auditors and assessors on behalf of clients
- Maintain continuous compliance evidence and control logging
- Support data center compliance reviews: physical security, access logs, and environmental controls
- Advise on NCA (National Cybersecurity Authority) compliance for Middle East engagements
What we need
- 4+ years in GRC, compliance, or risk management within technology or data center environments
- Working knowledge of SOC 2, ISO 27001, PCI DSS, HIPAA, and NIST frameworks
- Strong documentation and policy writing skills
- CISA, CISM, or CRISC certification preferred
Nice to have
- FedRAMP, FISMA, or NCA compliance experience
- GRC tool experience: ServiceNow GRC, Archer, or Vanta
Apply
Apply for Compliance & Risk Analyst
Tell us about yourself and attach your resume. We review every application personally.