Security Compliance Analyst

Sur

United States

On-site

USD 22,000 - 33,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sur is seeking a Security Compliance Analyst to manage security, compliance, and customer assurance programs. You will work with the VP of Information Security & Compliance on audits, questionnaires, control testing, and evidence collection in a hands-on role.

Responsibilities include handling DDQs, RFP security sections, maintaining a library of responses, coordinating with SMEs, and ensuring timely remediation across IT and cloud environments.

Qualifications

  • 3+ years of experience in IT, security, GRC, or related field.
  • Hands-on security compliance, audit evidence, and control testing experience.
  • Excellent spoken English for meetings with US-based customers and auditors.
  • Ability to manage multiple questionnaire requests and deadlines with attention to detail.

Responsibilities

  • Complete customer security questionnaires and related reviews.
  • Research technical questions and provide accurate answers based on environment.
  • Maintain library of approved responses and evidence.
  • Know when SME involvement is needed.
  • Participate in customer security calls for deep discussions.
  • Help speed the customer assurance process while staying accurate.
  • Track findings, remediation, and control-owner commitments.
  • Manage deadlines and report status.
  • Coordinate with teams to close tasks.

Skills

Security concepts
GRC/compliance
Audit evidence
English communication
Organization & deadlines
Windows administration
Cloud architectures
PowerShell scripting
Technical documentation
Questionnaires & DDQs

Tools

AWS
GitHub
Ticketing systems
Endpoint-management tools

Job description

As the Security Compliance Analyst, you will manage security, compliance, and customer assurance programs. You will work directly with the VP of Information Security & Compliance on customer security questionnaires, SOC 2 and other audits, control testing, evidence collection, vendor assessments, and compliance initiatives including CMMC and NIST 800-171. This is a hands-on, technically self-sufficient role, not a policy-only or checklist-driven GRC position.

Responsibilities
  • Complete customer security questionnaires, DDQs, RFP security sections, and related security reviews.
  • Research technical questions and produce accurate, defensible answers based on the company's actual environment and controls.
  • Maintain a reusable library of approved questionnaire responses and supporting evidence.
  • Recognize when an existing answer applies, when something has changed, and when a subject‑matter expert genuinely needs to be involved.
  • Participate in customer security calls when deeper technical or compliance discussions are required.
  • Help make the customer assurance process faster without sacrificing accuracy.
  • Track findings, exceptions, remediation activities, and control‑owner commitments through completion.
  • Manage deadlines, maintain and report status, and
  • 3+ years of relevant experience across IT, security, GRC, compliance, cloud operations, systems administration, or a similar field.
  • Solid understanding of common security concepts.
  • Hands-on experience with security compliance work, audit evidence, security questionnaires, or control testing.
  • Excellent spoken English, with the ability to participate confidently in meetings with U.S.-based customers, auditors, and internal teams.
  • Strong organizational skills and attention to detail, with the ability to manage multiple questionnaires, audit requests, and deadlines simultaneously.
  • Hands-on experience administering Windows and cloud-based architectures, including IT Tier 2 or systems administration work.
  • Comfortable investigating technical systems directly (for example, AWS, identity platforms, endpoint-management tools, GitHub, ticketing systems) to retrieve evidence rather than relying on Engineering or IT for every request.
  • Working knowledge of scripting or automation (for example, PowerShell) to operate efficiently at scale.
  • Ability to write clear, accurate technical documentation.
  • Compensation: $2000 to $3000
  • Schedule: U.S. business hours
  • PTO: Choice of following the U.S. holiday calendar or your home country's calendar.
  • Health & Equipment: Healthcare reimbursement eligibility after 90 days; a device stipend of up to $1,500, or reimbursement if you use your own equipment.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
Security Compliance Analyst III
Security Compliance Analyst III

Bridgehead IT • San Antonio (TX), Northern (KY)

Hybrid
USD 90,000 - 130,000
Security Compliance Engineer
Security Compliance Engineer

ANAUTICS INC • Oklahoma City (OK)

On-site
USD 80,000 - 100,000
Security Compliance Analyst III
Security Compliance Analyst III

Bridgehead IT LLC • San Antonio (TX)

On-site
USD 90,000 - 135,000
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1
GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2
Staff Security Analyst
Staff Security Analyst

Navan • Palo Alto (CA)

On-site
USD 131,000 - 291,000
Compliance Analyst (GRC/RMF Focused)
Compliance Analyst (GRC/RMF Focused)

CL 1e6d8f31 073f 48cd b324 b581c00084bf • Washington

Hybrid
USD 80,000 - 110,000
Technical Compliance Analyst
Technical Compliance Analyst

Jobtailor • California (MO)

Hybrid
USD 90,000 - 150,000