Compliance Analyst
Cresta
Cresta unlocks the true potential of the customer experience, turning every conversation into a competitive advantage. Cresta's unified AI platform combines conversational AI agents, real-time human agent augmentation, and comprehensive conversation intelligence to drive revenue and efficiency gains across every channel. The world's leading companies, including United Airlines, Cox Communications, and Marriott, use Cresta to power world-class customer experiences every day.
Born from the Stanford AI Lab, Cresta has raised more than $270 million from the world's leading investors, including a16z, Greylock, and Sequoia. Cresta's leadership includes some of the leading minds in AI today. Our CEO, Ping Wu, founded and led Google's Contact Center AI and Vertex AI platforms before joining Cresta to build the future of AI-driven customer experiences.
Responsibilities :
- Lead and manage all customer-facing security conversations, partnering cross-functionally to ensure timely resolution of issues and seamless execution of the security review lifecycle within sales deals.
- Perform risk assessments to identify gaps, come up with recommendations, and drive the gaps to remediation.
- Streamline and lead SOC 2 Type II, ISO 27001/27701/42001, PCI-DSS, TISAX, HIPAA, and FedRAMP audit processes.
- Perform internal audits and keep the necessary documentation updated as required for audits.
- Perform risk assessments to identify gaps, come up with recommendations, and drive the gaps to remediation.
- Streamline and lead SOC 2 Type II, ISO 27001/27701/42001, PCI-DSS, TISAX, HIPAA and FedRAMP audit processes.
- Perform internal audits and keep the necessary documentation updated as required for audits.
- Perform gap assessments against new regions and target industry markets to comply with compliance regulations as the company expands.
- Conduct new-hire and annual security awareness training to educate personnel and re-iterate security and compliance requirements.
- Oversee and continuously improve the vendor risk management framework, ensuring effective identification, assessment, and mitigation of third-party risks.
- Establish metrics to track compliance program effectiveness and to report risk.
- Interface with both technical (Engineering/Product) and non-technical (Sales/Marketing/Customer Success) teams.
- Respond to customer RFIs, questions, audits and technical documentation requests.
- Help build our common control framework and drive adoption of the framework within the organization.
- Build and automate processes to achieve continuous compliance over the technology control environment.
- Assist with sales and marketing materials representing product security and compliance.
- 4+ years of experience in security governance, IT audit, or security compliance management
- 3+ years of program management, with experience in affecting technology decisions
- End-to-end experience going through SOC 2 Type II, HITRUST, HIPAA, TISAX, ISO 27001/27701/42001, FedRAMP, and PCI-DSS external audits
- Experience in a hands-on technical role, with basic understanding of software implementation and integration
- Experience with cloud environments on AWS, GCP, Azure
- A track record of building relationships and credibility with business leads, external partners, and regulators through collaborative and independent programs
- Experience managing competing efforts and requirements
- Experience with fast-growing cloud native SaaS start-ups
- Bonus: Experience with building GRC engineering tooling
- Bonus: Experience with AI security frameworks such as AIUC
- Comprehensive medical, dental, and vision coverage with plans to fit you and your family
- Flexible PTO to take the time you need, when you need it
- Paid parental leave for all new parents welcoming a new child
- Retirement savings plan to help you plan for the future
- Remote work setup budget to help you create a productive home office
- Monthly wellness and communication stipend to keep you connected and balanced
- In-office meal program and commuter benefits provided for onsite employees
Compensation at Cresta Cresta's approach to compensation is simple: recognize impact, reward excellence, and invest in our people. We offer competitive, location-based pay that reflects the market and what each individual brings to the table. The posted base salary range represents what we expect to pay for this role in a given location. Final offers are shaped by factors like experience, skills, education, and geography. In addition to base pay, total compensation includes equity and a comprehensive benefits package for you and your family. Salary Range: $160,000 - $180,000 + Offers Equity We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates' personal and financial information through fake interviews and offers. All Cresta recruiting email communications will always come from the @cresta.ai domain. Any outreach claiming to be from Cresta via other sources should be ignored. If you are uncertain whether you have been contacted by an official Cresta employee, reach out to View email address on click.appcast.io
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Compliance Analyst. Be the first to apply!
- associate director regulatory affairs cmc United States
- compliance coordinator United States
- compliance data analyst United States
- research regulatory specialist United States
- regulatory specialist United States
- compliance associate United States
- quality compliance specialist United States
- junior regulatory affairs specialist United States
- risk compliance officer United States
- risk and compliance analyst United States
