Job Description :
We are seeking a highly skilled and experienced Senior Compliance Analyst / Compliance Lead to join our Governance, Risk, and Compliance (GRC) team. In this role, you will be responsible for driving regulatory compliance, risk management, and internal governance programs across our SaaS products and business operations. The ideal candidate will possess deep expertise in global compliance frameworks such as ISO 27001, ISO 42001, CMMC (Level 2& 3), FedRAMP, GovRAMP, and related standards, while also serving as a strategic advisor to cross-functional teams to maintain secure, compliant, and audit-ready environments.
Key Responsibilities :
- Lead compliance initiatives across multiple regulatory and industry frameworks including ISO 27001, ISO 42001 (AI management systems), FedRAMP, GovRAMP, CMMC Level 2 / 3, SOC 2, and NIST standards.
- Act as point of contact for external auditors, third-party assessors, and regulatory agencies.
- Oversee the development and continuous improvement of the GRC (Governance, Risk, and Compliance) program, ensuring robust processes for risk assessment, control monitoring, and compliance reporting.
- Manage readiness and certification projects such as ISO audits, FedRAMP authorization packages, and CMMC assessments, ensuring alignment with organizational goals.
- Partner with product, engineering, security, privacy and legal teams to embed compliance into the SaaS product lifecycle, including requirements gathering, architecture reviews, secure development, and deployment.
- Conduct gap assessments, internal audits, and risk evaluations to identify vulnerabilities, recommend controls, and ensure timely remediation.
- Maintain up-to-date knowledge of regulatory trends in cloud security, data privacy, AI governance, and SaaS operations, providing proactive guidance to leadership.
- Develop and deliver policies, procedures, awareness trainings, and compliance communications to foster a culture of security and compliance across the organization.
- Drive cross-regional compliance initiatives covering data residency, AI ethics, and international regulations where applicable.
Required Skills & Qualifications :
Bachelor’s or Master’s degree in Computer Science, Business, or related field.7+ years of experience in compliance, risk, and security governance functions, ideally within a SaaS or cloud-first company.Proven expertise in implementing and managing controls for ISO 27001, ISO 42001, CMMC Level 2 / 3, FedRAMP, GovRAMP, SOC 2, and related frameworks.Strong experience with GRC platforms and tools for risk and compliance program management.Excellent understanding of cloud-native environments (AWS, Azure, GCP) and SaaS product compliance challenges.Demonstrated ability to lead third-party audits, assessor interactions, and external certification projects.Strong communication skills with the ability to influence stakeholders across technical and business teams.Preferred Certifications :
ISO 27001 Lead Implementer / Lead AuditorISO 42001 Lead Implementer (or awareness of AI regulatory standards)CISA (Certified Information Systems Auditor)CISM or CISSP (a plus)FedRAMP or GovRAMP program management experienceFamiliarity with NIST 800-53 (Rev. 5), NIST AI RMF, or equivalentAdditional GRC-related certifications are a plusWhat We Offer :
Opportunity to drive compliance strategy for mission-critical SaaS products used globallyCollaborative, innovative-driven environment with exposure to cutting-edge technologiesProfessional development and certification sponsorships.About Aurigo :
Aurigo is revolutionizing how the world plans, builds, and manages infrastructure projects with Masterworks, our industry leading enterprise SaaS platform. Trusted by over 300 customers managing $300 billion in capital programs, Masterworks is setting new standards for project delivery and asset management. Recognized as one of the Top 25 AI Companies of 2024
and a Great Place to Work for three consecutive years, we are leveraging artificial intelligence to create a smarter, more connected future for customers in transportation, water and utilities, healthcare, higher education, and the government, with over 40,000 projects across North America.
At Aurigo, we don’t just develop software—we shape the future. If you’re excited to join a fast-growing comp