1

Security Compliance Jobs (NOW HIRING)

Security Compliance Analyst The Security Compliance Analyst leads the full certification lifecycle for key security frameworks, acting as the primary bridge between technical engineering teams and ...

The Security Compliance Manager leads the organization's security compliance and assurance efforts-ensuring we meet and maintain certification requirements (e.g., ISO 27001, SOC 2) and always remain ...

As a Senior Security Compliance Engineer, you'll focus primarily on: * Compliance operations & audits (for SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs) * Continuous control monitoring * GRC ...

As a Senior Security Compliance Engineer, you'll focus primarily on: * Compliance operations & audits (for SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs) * Continuous control monitoring * GRC ...

TSTC is looking for a security compliance lead with depth of knowledge in nuance of government security compliance requirements and policies. We need someone who is self-motivated, able to work in a ...

They are seeking a Senior Security Compliance Engineer to design and optimize automated compliance solutions, ensuring the security and trust of their customers and partners. Responsibilities : • ...

As a Senior Security Compliance Engineer, you'll focus primarily on: * Compliance operations & audits (for SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs) * Continuous control monitoring * GRC ...

Security Compliance Architect

$66.50 - $86/hr

Role We are looking for a Security Compliance Architect to join our team. This is a San Jose, CA preferred; remote candidates will be considered for the role, which is reporting to the Director ...

As a Senior Security Compliance Engineer, you'll focus primarily on: * Compliance operations & audits (for SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs) * Continuous control monitoring * GRC ...

As a Senior Security Compliance Engineer, you'll focus primarily on: * Compliance operations & audits (for SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs) * Continuous control monitoring * GRC ...

KPMG is currently seeking a Director, Security Compliance to join our Digital Security team. Responsibilities: * Apply a comprehensive specialist-level knowledge of risk, compliance, and information ...

TSTC is looking for a security compliance lead with depth of knowledge in nuance of government security compliance requirements and policies. We need someone who is self-motivated, able to work in a ...

TSTC is looking for a security compliance lead with depth of knowledge in nuance of government security compliance requirements and policies. We need someone who is self-motivated, able to work in a ...

TSTC is looking for a security compliance lead with depth of knowledge in nuance of government security compliance requirements and policies. We need someone who is self-motivated, able to work in a ...

Showing results 41-60

Security Compliance information

See salary details

$32.5K

$81.1K

$123.5K

How much do security compliance jobs pay per year?

As of Jul 26, 2026, the average yearly pay for security compliance in the United States is $81,143.00, according to ZipRecruiter salary data. Most workers in this role earn between $60,500.00 and $100,000.00 per year, depending on experience, location, and employer.

What does security compliance do?

Security compliance involves ensuring that an organization adheres to relevant security standards, regulations, and policies to protect data and systems. Professionals in this field develop, implement, and monitor security controls, often working with frameworks like ISO 27001 or NIST, to reduce risks and maintain regulatory requirements.

Can you make $500,000 a year in cyber security?

Security compliance roles, such as Security Compliance Manager or Director, can reach annual salaries of $500,000 or more, especially with extensive experience, advanced certifications like CISSP or CISA, and leadership responsibilities. High-level positions in large organizations or consulting firms tend to offer the highest compensation in cybersecurity.

What is security compliance?

Security compliance refers to the process of ensuring that an organization follows established laws, regulations, and industry standards related to information security. This involves implementing policies, procedures, and controls to protect data and systems from threats and unauthorized access. Security compliance professionals help organizations identify relevant requirements, assess risks, and maintain documentation to demonstrate adherence. Common frameworks and regulations include GDPR, HIPAA, ISO 27001, and PCI DSS.

How does a Security Compliance professional typically collaborate with other departments to ensure adherence to regulations?

Security Compliance professionals regularly work cross-functionally with IT, legal, HR, and operations teams to implement and monitor compliance with industry standards and regulations. They often lead or participate in risk assessments, develop and deliver training, and coordinate audit activities. Effective communication and relationship-building are key, as they must translate complex regulatory requirements into practical steps for diverse teams. This collaborative approach ensures that all departments understand their roles in maintaining a secure and compliant environment.

What is the highest paying job in compliance?

The highest paying roles in compliance often include Chief Compliance Officer (CCO) and Compliance Director, with salaries exceeding $150,000 annually. These positions require extensive experience, leadership skills, and knowledge of regulations such as GDPR or HIPAA, often supplemented by certifications like Certified Compliance & Ethics Professional (CCEP).

Are compliance jobs well paid?

Security compliance jobs often offer competitive salaries, especially for roles requiring certifications like CISSP or CISA and experience with regulatory standards such as GDPR or HIPAA. Salaries vary based on experience, location, and organization size but generally provide a solid income within the cybersecurity field.

What is the difference between Security Compliance vs Security Analyst?

AspectSecurity ComplianceSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, Security+
Work EnvironmentPolicy development, audits, regulatory adherenceMonitoring, threat analysis, incident response
Employer & Industry UsageOrganizations ensuring regulatory complianceOrganizations analyzing security threats and vulnerabilities

Security Compliance focuses on ensuring organizations meet security standards and regulations through policies and audits. Security Analysts actively monitor and respond to security threats. While both roles require security certifications, Compliance emphasizes policy adherence, whereas Analysts focus on threat detection and incident management.

What are the key skills and qualifications needed to thrive as a Security Compliance professional, and why are they important?

To thrive as a Security Compliance professional, you need a strong understanding of information security principles, regulatory frameworks (such as GDPR, HIPAA, or PCI DSS), and risk management, often supported by a degree in cybersecurity or related fields. Familiarity with compliance management tools, audit software, and certifications like CISSP, CISA, or ISO 27001 is typically required. Attention to detail, analytical thinking, and effective communication are vital soft skills for interpreting regulations and collaborating with stakeholders. These abilities ensure organizations remain compliant with laws and standards, mitigating risks and protecting sensitive data.
More about Security Compliance jobs
What cities are hiring for Security Compliance jobs? Cities with the most Security Compliance job openings:
What are the most commonly searched types of Security Compliance jobs? The most popular types of Security Compliance jobs are:
What states have the most Security Compliance jobs? States with the most job openings for Security Compliance jobs include:
What job categories do people searching Security Compliance jobs look for? The top searched job categories for Security Compliance jobs are:
Infographic showing various Security Compliance job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, and 4% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $81,143 per year, or $39 per hour.
Security Compliance Analyst

Security Compliance Analyst

Actalent

Raleigh, NC • Remote

Contractor

Medical, Dental, Vision, Life, Retirement, PTO

Posted 20 days ago


Job description

Job Title: Security Compliance Analyst

Job Description

The Security Compliance Analyst leads the full certification lifecycle for key security frameworks, acting as the primary bridge between technical engineering teams and external auditors. This role focuses on managing ISO and SOC 2 Type 2 audits end-to-end, translating complex technical environments into audit-ready evidence, and using AI and automation to reduce the compliance burden on engineering teams. The ideal candidate is a hands-on compliance practitioner who understands the realities of SaaS products and can clearly articulate technical control requirements to both technical and non-technical stakeholders.

Responsibilities

  • Own and drive the full lifecycle of ISO and SOC 2 Type 2 audits, from initial planning through final reporting.
  • Define detailed audit requirements and translate control language into clear, actionable technical requests for engineering teams.
  • Request, collect, and organize evidence from technical owners, ensuring completeness, accuracy, and audit readiness.
  • Review and validate the integrity and sufficiency of technical evidence, identifying gaps, inconsistencies, or invalid submissions.
  • Track remediation activities for identified gaps and follow up with stakeholders to ensure timely closure of issues.
  • Serve as the primary liaison with external audit firms, speaking the language of auditors and effectively defending the control environment.
  • Create and maintain an annual audit calendar, including timelines, milestones, and preparation activities for audit windows.
  • Ensure the organization is well prepared for audits by coordinating pre-audit reviews, walkthroughs, and readiness assessments.
  • Utilize AI and large language models to automate evidence collection, parse system logs, draft control descriptions, and identify potential compliance gaps before audits.
  • Apply a human-in-the-loop approach to AI usage by critically reviewing and validating AI-generated outputs for accuracy and completeness.
  • Review technical configuration reports for infrastructure, networking, containers, and databases to determine whether settings align with secure configuration expectations.
  • Research and identify appropriate secure configurations and control implementations for technologies not previously encountered.
  • Clearly explain to engineers what specific evidence or configurations are required, using precise technical language rather than generic control descriptions.
  • Collaborate with engineering and security teams to define and refine technical controls that align with ISO, SOC 2 Type 2, and other relevant frameworks.
  • Communicate complex compliance requirements in clear, accessible terms to non-technical stakeholders across the organization.
  • Push back constructively on auditors when appropriate, providing reasoned explanations and evidence to support the existing control environment.
  • Contribute to the continuous improvement of compliance processes by identifying opportunities to streamline workflows and reduce manual effort through automation and AI.

Essential Skills

  • Proven, specific experience managing end-to-end ISO and SOC 2 Type 2 audits, including planning, execution, and final reporting.
  • Baseline understanding of ISO and SOC 2 Type 2 frameworks and their associated control requirements.
  • Experience running audits, with a preference for technology-focused auditing experience.
  • Demonstrated ability to understand and assess technical controls in cloud and SaaS environments.
  • Technical literacy in cloud platforms, with a particular preference for experience with AWS.
  • Ability to read and interpret technical configuration reports and determine whether configurations meet secure standards.
  • Capability to identify when provided technical evidence is insufficient or invalid and to request appropriate corrective evidence.
  • Demonstrated experience using AI and large language models to streamline compliance and audit tasks, including evidence collection and analysis.
  • A clear human-in-the-loop philosophy for validating AI output to ensure accuracy and reliability.
  • Strong communication skills, including the ability to explain complex compliance requirements to non-technical stakeholders.
  • Ability to understand and articulate detailed technical requests from engineers and translate them into compliance terms.
  • Confidence and professionalism in pushing back on auditors when necessary, supported by clear evidence and reasoning.
  • Comfort discussing and auditing SaaS infrastructure running on public cloud environments such as AWS, Azure, or GCP and private cloud environments.
  • Familiarity with networking concepts and components, including firewalls, switches, routers, VPNs, and secure remote access.
  • Exposure to Linux-based server environments and various database management systems.
  • Understanding of containerized environments, including Kubernetes and Docker.
  • Ability to research and determine appropriate secure settings and configurations for unfamiliar technologies.

Additional Skills & Qualifications

  • Understanding of the NIST framework, particularly as it applies to security controls and policy design.
  • Experience working with security controls that align with NIST-based policies.
  • Creative use of AI to collect, review, and automate evidence handling in a flexible and scalable way.
  • CISSP certification, which demonstrates a deep understanding of technical security controls (strongly valued but not required).
  • Experience at a CISO or senior security leadership level is beneficial, though practical hands-on experience is preferred over certifications alone.
  • Baseline familiarity with NIST and other security frameworks used to structure security controls and policies.
  • Interest in continuously improving audit and compliance processes through automation and innovative tooling.

Work Environment

The role focuses on a SaaS product operating across both public cloud platforms (such as AWS, Azure, and GCP) and private cloud environments. You will regularly interact with infrastructure components, including firewalls, switches, routers, VPNs, and secure remote access solutions, as well as Linux-based server environments and various database management systems. The environment makes extensive use of container technologies like Kubernetes and Docker. Collaboration with engineering and security teams is central to the role, and you will frequently work with technical configuration reports, system logs, and automated tools. AI and large language models are an integral part of the workflow, particularly for evidence collection, log parsing, and drafting control documentation. The position emphasizes a professional, detail-oriented, and collaborative culture, where clear communication, proactive planning, and continuous improvement of compliance processes are highly valued.

Job Type & Location

This is a Contract position based out of Raleigh, NC.

Pay and Benefits

The pay range for this position is $50.00 - $55.00/hr.

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: • Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave)

Workplace Type

This is a hybrid position in Raleigh,NC.

Application Deadline

This position is anticipated to close on Jul 31, 2026.

About Actalent

Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service.

The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email actalentaccommodation@actalentservices.com for other accommodation options.

San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.

Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.


Actalent logo

About Actalent

Sourced by ZipRecruiter

Actalent connects passion with purpose. Our scalable talent solutions and services capabilities drive value and results and provide the expertise to help our customers achieve more. Every day, our experts around the globe are making an impact. We're supporting critical initiatives in engineering and sciences that advance how companies serve the world. Actalent promotes consultant care and engagement through experiences that enable continuous development. Our people are the difference. Actalent is an operating company of Allegis Group, the global leader in talent solutions.

Company size

5,001 - 10,000 Employees

Headquarters location

Hanover, MD, US

Year founded

1983

Social media