Technology Compliance Associate

Trumid

United States

On-site

USD 150,000 - 175,000

Full time

34 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Remote work flexibility
Competitive compensation
Medical/dental/vision coverage
Team-oriented culture

Job summary

Trumid seeks a Technology Compliance Associate to join the Technology Compliance team. You will own key areas including client security questionnaires, day-to-day security operations, and hands-on exposure to AI governance and SOC 2 program operations, collaborating with clients, auditors, and regulators.

This role is ideal for someone early in their compliance or security career who wants real ownership and the opportunity to learn from a seasoned tech compliance leader as our program scales.

Qualifications

  • 4+ years in information security or GRC/compliance with hands-on technical experience
  • Cloud security knowledge with AWS required
  • Familiarity with AI security risks and governance frameworks (NIST AI RMF, EU AI Act)
  • SOC 2 program experience in production with audits
  • Knowledge of SOC 2, ISO 27001, NIST frameworks
  • Strong client-facing communication skills
  • Experience with security compliance in financial services

Responsibilities

  • Develop and manage AI governance policies and guardrails; implement AI tools security controls
  • Operate SOC 2 program, including controls, evidence, audits
  • Oversee security operations: identity access, vulnerability remediation, and incident response coordination
  • Own DDQ process with clients and vendors; support legal/compliance on contracts and due diligence

Skills

Cloud security
AWS
Security tooling
SOC 2
ISO 27001
NIST frameworks
AI governance
Communication
GRC
Leadership

Education

Bachelor's degree in Computer Science or related field

Tools

CrowdStrike Falcon Complete
Vanta
Vulnerability scanners

Job description

About Us.

Trumid is a dynamic fintech revolutionizing the landscape of fixed income trading. With intelligent, easy-to-use, electronic solutions, we are rapidly growing and seeking exceptional talent to help redefine the boundaries of technology and finance.

About Us.

Trumid is a dynamic fintech revolutionizing the landscape of fixed income trading. With intelligent, easy-to-use, electronic solutions, we are rapidly growing and seeking exceptional talent to help redefine the boundaries of technology and finance. Founded in 2014 by a team of fixed income market experts, Trumid has quickly become one of the top three corporate bond e-trading platforms in the U.S. Today, over 1,300 traders from an extensive and expanding client network of 920+ buy- and sell-side institutions transact on Trumid monthly. With a rich history of innovation and a unique ability to innovate at scale, we collaborate closely with our clients, iterating quickly toward optimal solutions. With market share and client engagement at all-time highs and our pace of product development faster than ever, this is an exciting and transformative time at Trumid. Our business model thrives on participation, and so does our company culture. We rely on every team member's contribution to help us accomplish our goals. To succeed at Trumid, you must be curious, passionate about your craft, ambitious, collaborative, and driven. Learn more at www.trumid.com.

The opportunity.

Trumid is seeking a Technology Compliance Associate to join our Technology Compliance team. Reporting to our Technology Compliance Manager, you’ll take ownership of key areas — including client security questionnaires and day-to-day security operations — while getting hands-on exposure across AI governance and SOC 2 program operations, working alongside clients, auditors, and regulators. This is a great fit for someone early in their compliance or security career who wants real ownership plus the chance to learn directly from an experienced tech compliance leader as our program scales.

What You’ll Do
AI Governance
  • Develop and implement AI usage policies and governance frameworks for the organization
  • Implement guardrails and security controls using AI Gateway and similar tools
  • Conduct security assessments and risk evaluations for AI tools and services
  • Review AI tool usage and provide metrics through observability platforms
  • Ensure data privacy and protection standards are maintained across AI tool adoption
  • Manage vendor assessments and ongoing monitoring for AI service providers
  • Stay current on emerging AI regulation, including NIST AI RMF and EU AI Act developments
Compliance & Risk
  • Operate SOC 2 compliance program including control frameworks, evidence collection, audit coordination, and certification maintenance
  • Conduct security risk assessments, phishing simulations, vulnerability management, and penetration testing coordination
  • Drive BCP/DR planning, testing, and documentation
  • Manage security incident response processes and post-incident reviews
  • Track and report on security metrics, compliance posture, and risk remediation
Security Operations
  • Day-to-day operational oversight of CrowdStrike Falcon Complete including alert triage, monitoring, and liaising with security engineering on configuration and escalations
  • Support identity and access management programs including employee access reviews and privileged access controls
  • Tracking and reporting on vulnerability scan findings; coordinating remediation workflows with engineering
  • Coordinating and managing third-party penetration testing engagements; tracking findings through to remediation
Client, Vendor & DDQ Management
  • Own and manage the end-to-end DDQ (Due Diligence Questionnaire) process, including response accuracy, version control, and automation initiatives; serve as the primary point of contact for client and prospect security questionnaires
  • Conduct vendor security assessments and manage third-party risk
  • Support legal and compliance teams on vendor contracts and technical due diligence
About You.
  • Experience: 4+ years in information security or GRC/Compliance with hands-on technical experience and demonstrated leadership
  • Technical depth: Familiarity with cloud security (AWS required, GCP valued), security tooling (CrowdStrike or similar EDR/XDR platforms), and infrastructure security controls
  • AI security knowledge: Understanding of AI/LLM security risks, data privacy concerns, and emerging AI governance frameworks (NIST AI RMF, EU AI Act)
  • SOC 2 expertise: Operational experience running SOC 2 programs in production environments with successful audit outcomes
  • Security frameworks: Working knowledge of SOC 2, ISO 27001, NIST frameworks and their practical application
  • Client-facing skills: Proven ability to communicate security concepts to institutional clients and represent technical capabilities professionally
  • Compliance knowledge: Experience with security compliance in financial services or other regulated industries
  • Communication: Excellent written and verbal skills across technical and non-technical audiences
  • Certifications: CISSP, CISM, Security+, or equivalent preferred
  • Education: Bachelor's degree in Computer Science, Information Security, or related field
Technical Environment
You'll Work With
  • Cloud Platforms: AWS (primary), GCP
  • Security Tools: CrowdStrike Falcon Complete, Vanta, vulnerability scanners
  • AI & Observability: AI Gateway tools, LLM monitoring platforms, observability tools
  • Infrastructure: Cloud-native services
  • Compliance Frameworks: SOC 2, ISO 27001, NIST
  • Identity & Access: SSO, MFA, access control systems
Employee Benefits
  • Highly competitive compensation
  • Fully paid medical, dental and vision coverage
  • Remote work flexibility
  • Team-oriented and collaborative company culture

In compliance with New York City Pay Transparency Law, the base salary range for this role in New York City is between $150,000 - $175,000. This range does not include discretionary bonus or other forms of compensation or benefits offered in connection with this job. Several factors are considered when determining a candidate's compensation. Please note that the salary range listed for this position is based on the level of experience outlined in the job description. If a candidate's experience differs from the requirements, the salary may be adjusted accordingly.

Trumid is an equal opportunity employer.

Please note: All communication from Trumid's recruiting team comes from @trumid.com email addresses. We conduct remote interviews via Zoom only. We will never ask you to purchase equipment, download software (other than Zoom), or share sensitive personal information during the hiring process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Network Engineer
Senior Network Engineer

Trumid • United States

On-site
USD 225,000 - 250,000
Competitive compensation
Comprehensive medical/dental/vision
Dynamic office with amenities
Sr. Consultant | GRC/AI/Privacy (Remote)
Sr. Consultant | GRC/AI/Privacy (Remote)

Trace3 • Atlanta (GA)

Remote
USD 170,000 - 200,000
Comprehensive medical, dental and view
401(k) Retirement Plan with Employer
Competitive compensation
+4
Associate Security Engineer (Remote)
Associate Security Engineer (Remote)

CrowdStrike • Town of Texas (WI)

On-site
USD 70,000 - 95,000
Market-leading compensation
Comprehensive wellness programs
Paid time off and holidays
Account Director, Cyber & Threat Intel
Account Director, Cyber & Threat Intel

TRM Labs • United States

On-site
USD 150,000 - 210,000
Sr. Strategic Advisory Services Consultant (Remote)
Sr. Strategic Advisory Services Consultant (Remote)

CrowdStrike, Inc. • Sunnyvale (CA)

Remote
USD 115,000 - 160,000
Competitive compensation
Wellness programs
Vacation and holidays
+5
Sr. Engineer II, Cloud - CTIO (Hybrid)
Sr. Engineer II, Cloud - CTIO (Hybrid)

CrowdStrike • Sunnyvale (CA)

On-site
USD 160,000 - 250,000
Market-leading compensation and equity
Wellness programs
Generous vacation and holidays
+5
Sr. Engineer, Cloud Native - AI Detection and Response (AIDR) (Hybrid, Sunnyvale)
Sr. Engineer, Cloud Native - AI Detection and Response (AIDR) (Hybrid, Sunnyvale)

Socket.dev • Sunnyvale (CA)

Hybrid
USD 140,000 - 215,000
Market-competitive compensation
Equity awards
Wellness programs
+5
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)

CrowdStrike • St. Louis (MO)

On-site
USD 85,000 - 120,000
Equity awards
Wellness programs
Vacation and holidays
+4
Sr. Engineer, Cloud Native - AI Detection and Response (AIDR) (Hybrid, Sunnyvale)
Sr. Engineer, Cloud Native - AI Detection and Response (AIDR) (Hybrid, Sunnyvale)

CrowdStrike • Sunnyvale (CA)

Hybrid
USD 140,000 - 215,000
Market leader compensation
Comprehensive wellness programs
Generous vacation and holidays
+4
Director, Security Governance, Risk and Compliance
Director, Security Governance, Risk and Compliance

Tricentis Americas, Inc. • Austin (TX)

On-site
USD 170,000 - 260,000