> Markdown version of [/jobs/ext/2680063-technology-compliance-associate](https://www.wearedevelopers.com/jobs/ext/2680063-technology-compliance-associate). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Technology Compliance Associate - **Company:** Trumid Financial LLC - **Location:** New York, NY, United States (Remote available) - **Experience:** Experienced - **Salary:** $150,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, CompTIA Security+, Cyber Security, Identity and Access Management, Phishing, Software Vulnerability Management, Large Language Models, Grafana, Information Technology, Software Version Control, Serverless Computing, Vulnerability Analysis - **Published:** September 2, 2026 - **Apply:** https://www.builtincolorado.com/auth/login?destination=/job/technology-compliance-associate/10959890 ## About the Role * Experience: 4+ years in information security or GRC/Compliance with hands-on technical experience and demonstrated leadership * Technical depth: Familiarity with cloud security (AWS required, GCP valued), security tooling (CrowdStrike or similar EDR/XDR platforms), and infrastructure security controls * AI security knowledge: Understanding of AI/LLM security risks, data privacy concerns, and emerging AI governance frameworks (NIST AI RMF, EU AI Act) * SOC 2 expertise: Operational experience running SOC 2 programs in production environments with successful audit outcomes * Security frameworks: Working knowledge of SOC 2, ISO 27001, NIST frameworks and their practical application * Client-facing skills: Proven ability to communicate security concepts to institutional clients and represent technical capabilities professionally * Compliance knowledge: Experience with security compliance in financial services or other regulated industries * Communication: Excellent written and verbal skills across technical and non-technical audiences * Certifications: CISSP, CISM, Security+, or equivalent preferred * Education: Bachelor's degree in Computer Science, Information Security, or related field ## Description * Develop and implement AI usage policies and governance frameworks for the organization * Implement guardrails and security controls using AI Gateway and similar tools * Conduct security assessments and risk evaluations for AI tools and services * Review AI tool usage and provide metrics through observability platforms * Ensure data privacy and protection standards are maintained across AI tool adoption * Manage vendor assessments and ongoing monitoring for AI service providers * Stay current on emerging AI regulation, including NIST AI RMF and EU AI Act developments Compliance & Risk * Operate SOC 2 compliance program including control frameworks, evidence collection, audit coordination, and certification maintenance * Conduct security risk assessments, phishing simulations, vulnerability management, and penetration testing coordination * Drive BCP/DR planning, testing, and documentation * Manage security incident response processes and post-incident reviews * Track and report on security metrics, compliance posture, and risk remediation Security Operations * Day-to-day operational oversight of CrowdStrike Falcon Complete including alert triage, monitoring, and liaising with security engineering on configuration and escalations * Support identity and access management programs including employee access reviews and privileged access controls * Tracking and reporting on vulnerability scan findings; coordinating remediation workflows with engineering * Coordinating and managing third-party penetration testing engagements; tracking findings through to remediation Client, Vendor & DDQ Management * Own and manage the end-to-end DDQ (Due Diligence Questionnaire) process, including response accuracy, version control, and automation initiatives; serve as the primary point of contact for client and prospect security questionnaires * Conduct vendor security assessments and manage third-party risk * Support legal and compliance teams on vendor contracts and technical due diligence, * AI & Observability: AI Gateway tools, LLM monitoring platforms, observability tools * Infrastructure: Cloud-native services * Compliance Frameworks: SOC 2, ISO 27001, NIST * Identity & Access: SSO, MFA, access control systems ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [5 steps for running a Kubernetes environment at scale](https://www.wearedevelopers.com/videos/88-5-steps-for-running-a-kubernetes-environment-at-scale) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)