About the Role
Snorkel is seeking a hands-on Technical Compliance Analyst to be the operational engine behind their Trust & Security program. This role involves maintaining SOC 2 Type II posture, driving a second entity from Type I to Type II, and bridging compliance requirements with engineering execution. The analyst will also prepare for CMMC 2.0 readiness for federal contracts without hindering product velocity. This is a
Responsibilities
- Draft accurate, technically precise responses to RFPs, security questionnaires, and customer portals.
- Own and continuously update the 'Library of Truth' repository of security evidence, technical configurations, and policy documents.
- Retrieve granular evidence and draft narratives for customer inquiries regarding AWS KMS encryption, logging pipelines, or IAM privilege escalation paths.
- Partner with IT, Security, Product, Engineering, and Delivery teams early in the development lifecycle.
- Review new features, infrastructure changes, and vendor integrations to influence architectural decisions for compliance by design.
- Write, update, and operationalize security policies, translating controls into developer-friendly tasks.
- Automate policy enforcement in CI/CD pipelines where possible.
- Conduct lightweight compliance enablement sessions with engineering teams.
- Drive and coordinate end-to-end SOC 2 Type I and Type II audit cycles.
- Manage audit schedules, coordinate with external auditors, and drive remediation of findings.
- Act as a power-user of GRC platforms (Vanta, Drata) to automate evidence collection and continuously monitor controls.
- Manage the compliance ticketing queue in Jira.
- Execute routine mandates including quarterly User Access Reviews, security awareness training, and phishing simulations.
- Manage the Risk Acceptance/Exception process.
- Build and maintain compliance dashboards (KPIs/KRIs) for leadership.
- Track audit readiness scores, remediation SLAs, and control health trends.
- Manage the annual policy review and attestation cycle.
- Assist in aligning current controls with federal standards (NIST SP 800-53, NIST SP 800-171 Rev 3, FedRAMP, CMMC 2.0).
- Help draft early System Security Plans (SSPs) and Plan of Action & Milestones (POA&Ms).
- Own the third-party vendor review process for supply chain risk management.
- Support the Security Team during security incidents by preserving evidence and drafting post-incident reports.
Requirements
- 2–5 years of experience in technical compliance, IT audit, or GRC within a SaaS or fast-paced startup environment.
- Proven end-to-end experience supporting external SOC 2 Type I and Type II audits.
- Specific expertise auditing IT General Controls (ITGC) (Change Management, Logical Access, System Operations).
- Ability to manage auditors and translate their requests into actionable developer tasks.
- Strong understanding of modern cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD pipelines, encryption standards, and vulnerability management.
- Ability to read a Terraform plan or an AWS Config rule and interpret its compliance impact.
- Experience operating automated compliance platforms (Vanta, Drata).
- Experience tracking work in Jira.
- Experience with security awareness platforms (KnowBe4).
- Business enabler mindset, practicing 'Yes, if...' security.
- Ability to negotiate secure alternatives rather than blocking releases or ignoring risks.
- Thrives in a partnership role, ensuring IT, Security, Engineering, and Delivery teams have necessary support.
- Exceptional written and verbal communication skills.
- Ability to explain technical controls to customers and business risks to engineers.
Skills
- Technical Compliance
- IT Audit
- GRC
- SOC 2 Type I
- SOC 2 Type II
- IT General Controls (ITGC)
- Change Management
- Logical Access
- System Operations
- AWS
- GCP
- Azure
- IAM
- CI/CD pipelines
- Encryption standards
- Vulnerability management
- Terraform
- AWS Config
- Vanta
- Drata
- Jira
- KnowBe4
- NIST SP 800-53
- NIST SP 800-171 Rev 3
- FedRAMP
- CMMC 2.0
- System Security Plans (SSPs)
- Plan of Action & Milestones (POA&Ms)
- Supply Chain Risk Management (C-SCRM)
- RFP response
- Security questionnaires
- Risk assessments
Location
- Remote
Work Type
- Full-time
Experience Level
- 2-5 years
Salary/Compensations
- $120,000—$185,000 USD
About the Company
- At Snorkel, we believe meaningful AI doesn’t start with the model, it starts with the data.
- We’re on a mission to help enterprises transform expert knowledge into specialized AI at scale.
- The AI landscape has gone through incredible changes since 2015, when Snorkel started as a research project in the Stanford AI Lab, to the generative AI breakthroughs of today.
- But one thing has remained constant: the data you use to build AI is the key to achieving differentiation, high performance, and production-ready systems.
- We work with some of the world’s largest organizations to empower scientists, engineers, financial experts, product creators, journalists, and more to build custom AI with their data faster than ever before.
- Joining Snorkel AI means becoming part of a company that has market proven solutions, robust funding, and is scaling rapidly—offering a unique combination of stability and the excitement of high growth.
- As a member of our team, you’ll have meaningful opportunities to shape priorities and initiatives, influence key strategic decisions, and directly impact our ongoing success.
- Whether you’re looking to deepen your technical expertise, explore leadership opportunities, or learn new skills across multiple functions, you’re fully supported in building your career in an environment designed for growth, learning, and shared success.
Equal Opportunity
- Snorkel AI is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills.
- Snorkel AI embraces diversity and provides equal employment opportunities to all employees and applicants for employment.
- Snorkel AI prohibits discrimination and harassment of any type on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local law.
- All employment is decided on the basis of qualifications, performance, merit, and business need.
- We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
