Trust Analyst

Openkrill

United States

Remote

USD 90,000 - 130,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Abnormal AI is seeking a Trust Analyst II to join the Compliance Trust team, owning governance programs and policy management within the GRC framework. The role emphasizes audit readiness, risk assessment, and collaboration with internal teams and external auditors.

The ideal candidate has strong auditing mindset, detail orientation, and proven project management skills to lead governance committees and drive policy across the organization.

Qualifications

  • 4-7 years of experience in cyber security, technology risk, GRC, and/or technical compliance roles, with at least 2 years focused on ISO 27001 implementation and maintenance.
  • Experience leading cross-functional governance programs or committees such as AI governance, data governance, security governance.

Responsibilities

  • Own and run governance committees including AI Governance, Data Governance, Security Governance, and additional programs.
  • End-to-end ownership of the policy program: drafting, revising, maintaining policies, and managing the Policy Center.
  • Manage risk register, risk assessments, and administration of risk exceptions, including renewal controls.
  • Conduct risk assessments and advise leadership on impact to program strategy and plans.
  • Provide training and guidance on controls and documentation to owners.

Skills

Cyber security
Technology risk
GRC
ISO 27001 implement.
Project management
Governance committees

Tools

ServiceNow

Job description

About the Role

Abnormal AI is looking for a Trust Analyst II to join the Compliance Trust team within Abnormal’s Trust organization. The Trust organization is made up of the Compliance Trust and Customer Trust teams. This role sits on the Compliance Trust team, which owns the company’s GRC (Governance, Risk, and Compliance) programs. The Compliance Trust team drives internal and external audit readiness, manages enterprise and third-party risk, and leads governance across information security, AI, and data to deliver a foundation to maintain company's information security, privacy, and AI compliance certifications...

This role owns Abnormal's governance and policy program, chairing and running the company's governance committees, including AI Governance, Data Governance, Security Governance, and other governance programs as they are implemented. Additionally this role will hold end-to-end ownership of policy management, from drafting through stakeholder acknowledgment and management of the company’s Policy Center. Governance and policy ownership make up the majority of this role's scope. The remainder of the role will be a key stakeholder in risk management operations, including managing the risk register, performing risk assessments, and risk exception administration. Lastly, this role will also include general compliance support such as audit readiness, control evaluation, and issue remediation.

The ideal candidate will have the mindset of an auditor with keen attention to detail, possess exceptional skills in project management, be a good communicator who excels at explaining complex technology to diverse audiences in a way that fosters understanding and ownership, has strong collaboration and business sense, and an adept awareness of our customers' requirements of Abnormal as a leading cybersecurity SaaS provider.

Who You Are
  • - Proven security experience in an audit or advisory capacity
  • - Analytical thinker who exercises good business judgment and resolves ambiguous or judgment call questions without direction
  • - Resolves multi-framework or complex audit questions where the path isn't obvious, and designs an approach when standard procedure falls short and brings a recommendation to the table, not just a problem, and knows when to loop in Legal or Security to get it right
  • - Confidence and willingness to ask questions, raise issues, and concerns in a timely manner
  • - Comfortable owning and running cross-functional governance committees (e.g., AI Governance, Data Governance, Security Governance), setting agendas, driving decisions, and following through on action items without needing to be chased
  • - Experienced managing a policy program end to end. Authoring, revising, and defending policy positions to stakeholders, not just administering logistics
  • - High attention to detail, process, and organization with strong project management skills to ensure accountability and results
  • - Acts as a trusted partner to other Abnormal teams and external auditors on their domain, leading structured discussions grounded in evidence rather than assumption, and represents the function credibly in auditor-facing settings
  • - Comfortable interpreting requirements in business context rather than taking a control requirement at face value, and anticipating how upstream changes affect compliance posture
  • - Ability to adapt to change, including evolving business and technical environments, and manage multiple priorities while meeting deadlines in a fast-paced environment
  • - Team player, collaborative work style
  • - Self-motivated and able to work efficiently with minimal oversight/direction
  • - Owns outcomes rather than activity — accountable for a compliance domain end to end, including audit outcomes and remediation tracking
What You Will Do
  • - Own and run Abnormal's governance committees including AI Governance, Data Governance, Security Governance, and any additional governance programs the business needs. Running these committees will include setting agendas, facilitating cross-functional stakeholders, and driving decisions to closure.
  • - Hold end-to-end ownership of the policy program, including drafting, revising, and maintaining policies across governance domains, and driving stakeholder review and acknowledgment. Manage the company’s Policy Center which hosts all enterprise policies.Own risk management operations, including the risk register, risk assessments, and administration of risk exceptions, including enforcing the 12-month exception cap with mandatory renewal review and required documentation.
  • - Keep abreast of regulatory and industry developments and advise leadership on the potential impact on the program strategy and plans.
  • - Ensure program activities align with strategy and manage the timely and high-quality execution of GRC landmarks.
  • - Drive internal control effectiveness through rigorous internal control monitoring, implementing control enhancements, and providing thought leadership on control design, operations, and supporting processes and policies.
  • - Perform compliance readiness assessments and provide updates, recommendations, and roadmap to senior management both within Security and to our business partners.
  • - Advise, educate, and train process and control owners with the preparation and ongoing maintenance of controls and control documentation (e.g., policies, procedures, narratives, and matrices) to better understand the security controls framework and their responsibilities.
  • - Recommend, develop, and manage the company's risk register, including the definition and reporting on key risk indicators (KRIs) and key performance indicators (KPIs).
  • - Conduct regular risk assessments and work with relevant departments to identify, evaluate, and mitigate risks across the organization.
  • - Advise, educate, and train risk owners with the identification, assessment, mitigation, and monitoring of risks to better understand the risk management process and their responsibilities.
  • - Proactively identify gaps or conflicts in existing policies and processes and work to develop solutions with internal business partners.
  • - Drive remediation and risk mitigation activities, including root cause analysis and owning the design, tracking, and progress of action plans across compliance, policy, or process gap remediation activities and risk mitigation activities in partnership with internal business partners. Tracks risk trends across cycles and flags recurring patterns before they become repeat findings.
  • - Design and manage program operations to support the program goals and implement and maintain technology to support the program and its operations.
  • - Engage in ad-hoc projects as required.
  • - Maintain regular, clear communication with project teams, key partners, and management regarding the status of controls testing, audit progress, risk assessment progress, and progress of issues management.
  • - Effectively communicate program and project execution status, program health and effectiveness, key accomplishments, and risks to senior management both within Security and to our business partners.
Must Haves
  • - 4-7 years of experience in cyber security, technology risk, GRC, and/or technical compliance roles, with at least 2 years focused on ISO 27001 implementation and maintenance
  • - Demonstrated experience leading at least one full ISO 27001 certification cycle (including the 2022 revision of ISO 27001) from start to finish
  • - Proven project management experience, including: managing multiple concurrent compliance projects with competing deadlines; leading cross-functional teams across technical and business units; experience with project management methodologies (Agile, Waterfall) and tools (ServiceNow, etc.); and a track record of delivering complex compliance projects on time and within scope
  • - Experience owning or facilitating cross-functional governance programs or committees (e.g., AI governance, data governance, security governance), inclu
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Trust Analyst
Trust Analyst

Abnormalsecurity • United States

On-site
USD 120,000 - 170,000
Trust Analyst
Trust Analyst

Abnormal AI, Inc. • United States

On-site
USD 115,000 - 165,000
Trust Analyst
Trust Analyst

Abnormal AI • United States

Remote
USD 115,000 - 165,000
Trust Analyst
Trust Analyst

AI Chopping Block, Inc. • Northern (KY)

On-site
USD 115,000 - 165,000
Trust Analyst (Fully Remote)
Trust Analyst (Fully Remote)

Abnormal AI • United States

Remote
USD 100,000 - 140,000
Governance & Policy Trust Analyst
Governance & Policy Trust Analyst

Openkrill • United States

Remote
USD 90,000 - 130,000
Senior Customer Trust Analyst, EMEA
Senior Customer Trust Analyst, EMEA

Abnormal AI • United States

On-site
GBP 120,000 - 150,000
Governance & Policy Trust Analyst II
Governance & Policy Trust Analyst II

Abnormal AI • United States

Remote
USD 115,000 - 165,000
Director of Security Engineering
Director of Security Engineering

Abnormal • United States

On-site
USD 214,000 - 308,000
GRC Policy & Risk Lead (ISO 27001)
GRC Policy & Risk Lead (ISO 27001)

Abnormal AI • United States

Remote
USD 100,000 - 140,000