Remote - India Remote (Country) Employment

AlphaSense is hiring a Senior Compliance Analyst

Responsibilities

  • Own the full evidence collection lifecycle across all active audit and continuous compliance cycles.
  • Coordinate with control owners to gather, validate, and organize evidence artifacts in the GRC platform (Drata or equivalent).
  • Use AI-assisted workflows to pre-stage evidence, flag stale artifacts, and reduce the manual burden on engineering and IT teams—making it easier for control owners to do this right than to skip it.
  • Serve as the primary operational point of contact for external auditors during Stage 1, Stage 2, and surveillance audits.
  • Manage auditor portals, respond to RFIs, track open items to closure, and ensure auditors leave each engagement with a complete, accurate view of how AlphaSense's controls operate in practice.
  • Findings get closed before they become repeat findings.
  • Perform ongoing monitoring and periodic testing of implemented controls.
  • Document control effectiveness, identify gaps, and work with control owners to remediate deficiencies on defined timelines.
  • Map findings to applicable framework requirements across SOC 2, ISO 27001, and ISO 420001.
  • Contribute to transitioning point-in-time control testing toward continuous, automated validation.
  • Maintain and update security policies, standards, and procedures to keep them aligned with current operational reality and framework requirements.
  • Ensure documentation is version-controlled, accessible, and demonstrably distributed and attested to—satisfying auditor requirements without relying on static PDFs or manual tracking.
  • Identify and implement opportunities to use AI tools to streamline evidence gathering, control narrative drafting, audit preparation, and gap analysis.
  • Operate in a human-in-the-loop model: AI accelerates the work, you validate for accuracy, completeness, and confidentiality before anything ships.
  • Actively share what works with the broader GRC team.
  • Assist with risk assessments, documentation, and audit evidence for AI governance controls.
  • Collaborate with Engineering and Product to ensure secure and responsible use of generative AI tools across the organization.
  • Partner with Engineering, IT, Legal, and Product to ensure control ownership is clear, evidence is readily available, and compliance requirements are embedded into operational processes—not bolted on at audit time.
  • Provide risk and control guidance on post-implementation reviews and remediation activities.
  • Help stakeholders interpret requirements and build controls into how they actually work.

Requirements

  • 6+ years of experience in GRC, information security, risk management, or IT audit, preferably in a SaaS or cloud-native environment
  • Strong understanding of security and compliance frameworks including SOC 2, ISO 27001, NIST CSF 2.0, and CIS Controls; working knowledge of ISO 42001 and NIST AI RMF
  • AI-native mindset: you use AI tools—LLMs, agents, automation—for real, substantive work including analysis, drafting, evidence gathering, and workflow automation. You apply judgment about where AI creates leverage and where a human must stay in the loop
  • Proficiency with GRC platforms for evidence management and control testing (Drata, Vanta, AuditBoard, ServiceNow GRC, or equivalent)
  • Familiarity with cloud environments (AWS, Azure, or GCP) and the security and compliance posture tooling that runs on them (CSPM, SIEM, identity platforms)
  • Experience supporting external audits across security or privacy domains, including evidence collection, control walkthroughs, and auditor interaction
  • Ability to interpret technical controls and translate findings into compliance, risk, and policy documentation that engineers and non-technical stakeholders both understand
  • Working knowledge of risk registers, control libraries, and policy governance lifecycles
  • Working knowledge of privacy and data protection requirements (GDPR, CCPA/CPRA) and how they intersect with security controls, in partnership with Legal and Product teams
  • Strong written communication, analytical thinking, and attention to detail; able to produce clear audit responses, risk narratives, and control documentation under deadline
  • Hands-on experience managing end-to-end audit evidence collection across ISO 27001, SOC 2 Type II, or equivalent frameworks in a SaaS or cloud environment
  • Direct operational experience working with external auditors as the primary compliance or audit liaison—walkthroughs, RFI responses, finding management
  • Automation-first mentality with demonstrated experience working in an organization that has implemented automated evidence collection—you default to building workflows over doing things manually, and you actively improve the automation rather than working around it
  • Demonstrated use of AI tools (LLMs, AI-assisted GRC workflows) to accelerate compliance work: drafting, research, evidence review, or gap analysis—with a clear practice of validating AI output before it ships
  • Experience maintaining policy governance lifecycles from drafting through distribution, attestation, and version control
  • Strong organizational skills and ability to manage multiple concurrent audit workstreams without losing detail

Nice to Have

  • Relevant certifications: CISA, CRISC, CISM, CISSP, CCSK, or ISO 27001 Lead Auditor/Implementer
  • Experience with AI governance frameworks including ISO 42001, NIST AI RMF, EU AI Act, or OECD AI Principles
  • Exposure to SOX ITGC cycles—managing evidence, walkthroughs, and findings with external auditors
  • Privacy program crossover: data mapping, DPIAs, GDPR/CCPA operational compliance
  • Scripting or automation experience (Python, JavaScript, or low-code tools) applied to GRC or compliance workflows
  • Experience with ISO 42001 AI management system audits or EU AI Act compliance documentation
  • Familiarity with policy-as-code and compliance-as-code approaches: controls expressed as enforceable automated checks, policies in version control, and requirements validated programmatically rather than through manual review
  • Programming or scripting skills (Python, JavaScript, or low-code tools such as n8n, Tines, or Zapier) applied to compliance workflows, evidence automation, or GRC platform integrations
  • Experience building or operating a security awareness and phishing simulation program
  • Background in privacy compliance operations (GDPR, CCPA data mapping, DPIAs) in partnership with Legal
Required Skills
GRCInformation SecurityRisk ManagementIT Audit
About company
AlphaSense
AlphaSense provides AI-driven market intelligence and search to help sophisticated companies make decisions. The platform includes public and private content like equity research, company filings, transcripts, news, and client research. It serves over 6,000 enterprise customers, including a majority of the S&P 500.
All jobs at AlphaSense Visit website
Job Details
Category other
Posted 20 days ago