Technology Compliance Associate

Trumid Financial LLC
New York, NY, United States
5 days ago
Apply on www.builtincolorado.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$150,000.0 - $175,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Software System Penetration Testing Cloud Computing Security CompTIA Security+ Cyber Security Identity and Access Management Phishing Software Vulnerability Management Large Language Models Grafana Information Technology
+3 more
Software Version Control Serverless Computing Vulnerability Analysis

Job description

  • Develop and implement AI usage policies and governance frameworks for the organization
  • Implement guardrails and security controls using AI Gateway and similar tools
  • Conduct security assessments and risk evaluations for AI tools and services
  • Review AI tool usage and provide metrics through observability platforms
  • Ensure data privacy and protection standards are maintained across AI tool adoption
  • Manage vendor assessments and ongoing monitoring for AI service providers
  • Stay current on emerging AI regulation, including NIST AI RMF and EU AI Act developments

Compliance & Risk

  • Operate SOC 2 compliance program including control frameworks, evidence collection, audit coordination, and certification maintenance
  • Conduct security risk assessments, phishing simulations, vulnerability management, and penetration testing coordination
  • Drive BCP/DR planning, testing, and documentation
  • Manage security incident response processes and post-incident reviews
  • Track and report on security metrics, compliance posture, and risk remediation

Security Operations

  • Day-to-day operational oversight of CrowdStrike Falcon Complete including alert triage, monitoring, and liaising with security engineering on configuration and escalations
  • Support identity and access management programs including employee access reviews and privileged access controls
  • Tracking and reporting on vulnerability scan findings; coordinating remediation workflows with engineering
  • Coordinating and managing third-party penetration testing engagements; tracking findings through to remediation

Client, Vendor & DDQ Management

  • Own and manage the end-to-end DDQ (Due Diligence Questionnaire) process, including response accuracy, version control, and automation initiatives; serve as the primary point of contact for client and prospect security questionnaires
  • Conduct vendor security assessments and manage third-party risk
  • Support legal and compliance teams on vendor contracts and technical due diligence, * AI & Observability: AI Gateway tools, LLM monitoring platforms, observability tools
  • Infrastructure: Cloud-native services
  • Compliance Frameworks: SOC 2, ISO 27001, NIST
  • Identity & Access: SSO, MFA, access control systems

Requirements

  • Experience: 4+ years in information security or GRC/Compliance with hands-on technical experience and demonstrated leadership
  • Technical depth: Familiarity with cloud security (AWS required, GCP valued), security tooling (CrowdStrike or similar EDR/XDR platforms), and infrastructure security controls
  • AI security knowledge: Understanding of AI/LLM security risks, data privacy concerns, and emerging AI governance frameworks (NIST AI RMF, EU AI Act)
  • SOC 2 expertise: Operational experience running SOC 2 programs in production environments with successful audit outcomes
  • Security frameworks: Working knowledge of SOC 2, ISO 27001, NIST frameworks and their practical application
  • Client-facing skills: Proven ability to communicate security concepts to institutional clients and represent technical capabilities professionally
  • Compliance knowledge: Experience with security compliance in financial services or other regulated industries
  • Communication: Excellent written and verbal skills across technical and non-technical audiences
  • Certifications: CISSP, CISM, Security+, or equivalent preferred
  • Education: Bachelor’s degree in Computer Science, Information Security, or related field

Benefits & conditions

Remote or Hybrid Hiring Remotely in USA 150K-175K Annually Mid level Easy Apply Remote or Hybrid Hiring Remotely in USA 150K-175K Annually Mid level Own technology compliance and security operations across AI governance, SOC 2, risk assessments, incident response, business continuity, vulnerability management, access reviews, and penetration testing. Manage client security questionnaires, vendor assessments, third-party risk, and audit coordination while monitoring security tools and coordinating remediation with engineering. Advise clients, auditors, regulators, legal teams, and compliance stakeholders on technical security matters. The summary above was generated by AI, * Highly competitive compensation

  • Fully paid medical, dental and vision coverage
  • Remote work flexibility
  • Team-oriented and collaborative company culture

In compliance with New York City Pay Transparency Law, the base salary range for this role in New York City is between $150,000 - $175,000. This range does not include discretionary bonus or other forms of compensation or benefits offered in connection with this job. Several factors are considered when determining a candidate’s compensation. Please note that the salary range listed for this position is based on the level of experience outlined in the job description. If a candidate’s experience differs from the requirements, the salary may be adjusted accordingly.

Trumid is an equal opportunity employer.

About the company

Trumid is a dynamic fintech revolutionizing the landscape of fixed income trading. With intelligent, easy-to-use, electronic solutions, we are rapidly growing and seeking exceptional talent to help redefine the boundaries of technology and finance.

Founded in 2014 by a team of fixed income market experts, Trumid has quickly become one of the top three corporate bond e-trading platforms in the U.S. Today, over 1,300 traders from an extensive and expanding client network of 920+ buy- and sell-side institutions transact on Trumid monthly.

With a rich history of innovation and a unique ability to innovate at scale, we collaborate closely with our clients, iterating quickly toward optimal solutions. With market share and client engagement at all-time highs and our pace of product development faster than ever, this is an exciting and transformative time at Trumid.

Our business model thrives on participation, and so does our company culture. We rely on every team member’s contribution to help us accomplish our goals. To succeed at Trumid, you must be curious, passionate about your craft, ambitious, collaborative, and driven. Learn more at www.trumid.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.builtincolorado.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:44 min

Background and career journey in regulated software systems

Martin Hynie · Coffee With Developers

10:40 min

Visualizing Prometheus open metrics using custom Grafana dashboards

Stijn Polfliet · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:04 min

Visualizing Keycloak performance via standard Grafana troubleshooting dashboards

Alexander Schwartz Alexander Schwartz · World Congress 2025

Videos

See all

Related articles

See all