1

Security Compliance Analyst Jobs (NOW HIRING)

Filevine is looking for a High Security Compliance Analyst to join our Information Security team to ensure that our platform, applications, and infrastructure are compliant and secured at the highest ...

Top Skill & Years of Experience Required: * 5+ years of experience with knowledge of security and compliance frameworks relevant to public sector environments, such as NIST CSF, NIST 800 53, and ...

Senior Security & Compliance Analyst

Lansing, MI · On-site

$97K - $127K/yr

We are currently seeking a Senior Security & Compliance Analyst. Candidates must be located within 90 miles of Lansing, MI. Interviews will be held in person in Lansing, MI. There is no option for a ...

This position is not a member of the Security Operations Center, rather it is dedicated to working with software development teams on secure coding practices. Candidates must have a strong ...

Showing results 21-40

Security Compliance Analyst information

See salary details

$46K

$104.1K

$147.5K

How much do security compliance analyst jobs pay per year?

As of Sep 11, 2026, the average yearly pay for security compliance analyst in the United States is $104,051.00, according to ZipRecruiter salary data. Most workers in this role earn between $85,500.00 and $125,000.00 per year, depending on experience, location, and employer.

What is a Security Compliance Analyst?

A Security Compliance Analyst is a professional responsible for ensuring that an organization adheres to regulatory requirements and internal security policies. They assess and monitor security controls, conduct risk assessments, and help prepare for audits. Their role often involves interpreting complex regulations, providing guidance to other teams, and documenting compliance efforts. Security Compliance Analysts work to minimize risks related to data breaches and ensure that the organization avoids legal and financial penalties.

What are the key skills and qualifications needed to thrive as a Security Compliance Analyst, and why are they important?

To thrive as a Security Compliance Analyst, you need a solid understanding of information security principles, risk management, and relevant regulatory frameworks such as GDPR or HIPAA, often supported by a degree in cybersecurity or a related field. Familiarity with compliance management tools, audit software, and certifications like CISSP or CISA is highly beneficial. Strong attention to detail, analytical thinking, and effective communication are essential soft skills for interpreting regulations and collaborating across departments. These competencies ensure organizations remain compliant with evolving standards, mitigate risks, and maintain trust with stakeholders.

What are some of the common challenges Security Compliance Analysts face when working across different departments?

Security Compliance Analysts often encounter challenges when collaborating with various departments due to differing priorities and varying levels of understanding about compliance requirements. For example, departments focused on business growth may view compliance as an obstacle, while technical teams may be more receptive but lack the resources for thorough documentation. Effective communication and the ability to translate regulatory requirements into practical, actionable steps for non-technical stakeholders are essential skills. Building relationships and promoting a culture of compliance can help mitigate these challenges and ensure smoother cooperation across the organization.

What is the difference between Security Compliance Analyst vs Security Auditor?

AspectSecurity Compliance AnalystSecurity Auditor
CertificationsISO 27001 Lead Implementer, CISSP, CISACISA, CISSP, ISO 27001 Lead Auditor
Work EnvironmentCorporate, IT departments, compliance teamsAudit firms, consulting agencies, internal audit teams
Employer & IndustryFinancial, healthcare, tech companiesAudit firms, regulatory agencies, large corporations
Search & Comparison IntentUnderstanding compliance roles, preparing for auditsAssessing security controls, audit processes

The Security Compliance Analyst focuses on ensuring organizations meet security standards and regulations through ongoing compliance efforts. In contrast, a Security Auditor conducts formal evaluations of security controls, often through audits. Both roles require similar certifications and work in related environments, but their primary functions differ: compliance versus assessment.

More about Security Compliance Analyst jobs

What cities are hiring for Security Compliance Analyst jobs?

Cities with the most Security Compliance Analyst job openings:

What are the most commonly searched types of Security Compliance Analyst jobs?

The most popular types of Security Compliance Analyst jobs are:

What states have the most Security Compliance Analyst jobs?

States with the most job openings for Security Compliance Analyst jobs include:

What are popular job titles related to Security Compliance Analyst jobs?

For Security Compliance Analyst jobs, the most frequently searched job titles are:

Infographic showing various Security Compliance Analyst job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, and 4% Contract. Highlights an 89% Physical, 2% Hybrid, and 9% Remote job distribution, with an average salary of $104,051 per year, or $50 per hour.

Security Compliance Analyst

Salt Lake City, UT

Filevine
Software Development • 11 - 50 employees

Full-time

Medical, Dental, Vision

Re-posted 8 days ago


Job description

Filevine is a Legal AI company delivering Legal Operating Intelligence for the future of legal work. Grounded in a singular system of truth, Filevine brings together data, documents, workflows, and teams into one unified platform—where modern legal work happens with clarity and consistency.
 
Powered by LOIS, the Legal Operating Intelligence System, Filevine connects context across every matter to transform legal operations from reactive to proactive. LOIS reads, understands, and reasons across your data to surface insight, automate complexity, and give professionals the clarity and confidence to see more, know more, and do more. Fueled by a team of exceptional collaborators and innovators, Filevine’s rapid growth has earned AI awards and recognition from Deloitte and Inc. as one of the most innovative and fastest-growing technology companies in the country.

About Filevine
Filevine is forging the future of legal work with cloud-based workflow tools. We have a reputation for intuitive, streamlined technology that helps professionals manage their organization and serve their clients better. We’re also known for our team of extraordinary and passionate professionals who love working together to help organizations thrive. Our success has catapulted Filevine to the forefront of our field—we are ranked as one of the most innovative and fastest-growing technology companies in the country by both Deloitte and Inc.
 
Department Statement
The IT Audit team is responsible for performing timely audits and ensuring compliance and risk assessment efforts are aligned with industry standards and best practices.  
 
Filevine is looking for a High Security Compliance Analyst to join our Information Security team to ensure that our platform, applications, and infrastructure are compliant and secured at the highest levels thus protecting and enhancing customer trust. If you are bright, hardworking, ambitious, and enjoy taking ownership of security and compliance, we want to talk to you. This is an exciting opportunity to join a world-class team.
Responsibilities:
  • Manage CJIS obligations, including monthly and yearly audits, clearances for employees, and associated CJIS efforts
  • Assist with Federal and international government security audits (e.g. FedRAMP, StateRAMP, Canadian government compliance obligations Strategize and outline goals and objectives of the GRC (IT Audit and Risk management) programs.
  • Assist with security efforts to meet HIPAA, SOC 2 Type I & II, and other compliance requirements.
  • Work directly with Information Security, Legal, HR, Compliance and Development teams to ensure secure IT and IS best practices are fully adopted at Filevine.
  • Help train employees on auditing secure coding techniques to mitigate the need for break-fix/out-of-band patching.
  • Review audit, compliance and risk assessment issues that arise and manage them to resolution.
  • Provide audit frameworks and risk assessment methodologies contemplating new software solutions to help mitigate security vulnerabilities and other business risks.
  • Maintain documented Policy and Procedure libraries for compliance purposes.
  • Complete Third-party vendor risk management and security questionnaires for Filevine.
  • Provided annual Internal audit and risk assessment functions.
  • Facilitate and lead annual penetration testing and auditing efforts.
  • Develop a familiarity with new auditing and risk assessment tools and techniques.
Qualifications:
  • Bachelor's Degree or equivalent in Computer Science, Computer Engineering, Information Technology, or related field
  • 4+ years of experience in IT Auditing, Compliance Analysst and/or direct experience related to risk assessment methodologies.
  • Proven work experience as IT Audit & Risk Assessor with a passion for details and security.
  • Familiarity with auditing and assessing the OWASP Top 10.
  • Experience with managing risks, fraud, and security threats.
  • Knowledge of web related technologies (Web applications, Web Services and Service Oriented Architectures, Web Databases) and of network/web related protocols.
  • Experience assessing, testing, or auditing technical IT and security controls.
  • Working knowledge of and demonstrated experience with ISO 27701, ISO 27018, ISO 27001
  • Experience with FedRAMP is preferred, as well as SOC II Type I & II, HIPAA Security Rule, CJIS, GDPR, CCPA/CPRA and other compliance frameworks.
  • Demonstrated knowledge of assessing development methodologies (Agile, Waterfall).
  • Ability to work in a fast-paced environment.
  • Must exhibit excellence in partnering, teamwork, and quality performance.
  • Able to effectively give, receive, and respond to feedback.
  • Excellent oral and written communication skills with the ability to communicate security concepts to a technical and non-technical audience including senior management.
  • Demonstrated ability to establish relationships and build rapport to influence colleagues at all levels, uncover issues, and identify needs.
  • This will be a hybrid schedule position ( 3/2 or 4/1 - TBD)
Preferred Qualifications:
  • Significant experience with auditing frameworks, formal audits, and risk assessment experience.
  • Significant experience with automated auditing and compliance tools.
  • GRC tool Certification or equivalent experience.
  • CISSP Certification or equivalent experience.
  • CISM Certification or equivalent experience.
  • CISA Certification or equivalent experience.
  • CIPP/US Certification or equivalent experience.
  • CRISC Certification or equivalent experience.
Work Location Expectation: This position is based out of our Salt Lake City, Chicago, or San Francisco offices. Candidates residing in or near these metro areas are expected to work on a hybrid (2-3 days in-office/week) or fully onsite basis.
 
 
Cool Company Benefits:
- A dynamic, rapidly growing company, focused on helping organizations thrive 
- Medical, Dental, & Vision Insurance (for full-time employees)
- Competitive & Fair Pay
- Maternity & paternity leave (for full-time employees)
- Short & long-term disability
- Opportunity to learn from a dedicated leadership team
- Top-of-the-line company swag
 
Privacy Policy Notice
Filevine will handle your personal information according to what’s outlined in our Privacy Policy.
 
Communication about this opportunity, or any open role at Filevine, will only come from representatives with email addresses using "filevine.com". Other addresses reaching out are not affiliated with Filevine and should not be responded to.
 

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.