Compliance Analyst

Harvey Harvey · AI Frontier · San Francisco, CA · Engineering

This role focuses on maintaining compliance and security for an AI-powered legal tech platform, ensuring adherence to government and industry frameworks. The analyst will manage compliance documentation, coordinate evidence collection, support third-party assessments, and partner with engineering teams to validate control implementations. The role requires strong attention to detail and experience with SaaS/cloud compliance.

What you'd actually do

  1. Own and maintain core compliance documentation — including compliance packages and security assessment reports — keeping them accurate and audit-ready
  2. Coordinate evidence collection across Engineering, Infrastructure, and Security for regulated assessments
  3. Support third-party assessor engagements end-to-end: scheduling, preparing teams, triaging findings, and drafting responses
  4. Conduct gap analyses against applicable frameworks and produce remediation tracking artifacts teams can act on directly
  5. Manage continuous monitoring activities including control reviews, change notifications, and incident documentation to maintain compliance status

Skills

Required

  • Information security compliance
  • Government and industry frameworks (SaaS/cloud)
  • Compliance documentation maintenance
  • Remediation tracking
  • Control implementation validation
  • Communication (written and verbal)

Nice to have

  • Compliance automation tooling
  • Familiarity with AI/ML concepts in a compliance context

What the JD emphasized

  • U.S. citizenship required
  • hands-on compliance work
  • compliance programs healthy
  • maintaining control documentation
  • coordinating evidence collection
  • supporting third-party assessments
  • ensure controls are implemented, tested, and continuously monitored
  • detail-oriented practitioner
  • getting the compliance fundamentals exactly right
  • information security compliance
  • government and industry frameworks
  • SaaS or cloud environment
  • government compliance frameworks
  • map controls to technical implementations
  • evaluate evidence quality
  • maintaining compliance documentation
  • tracking remediation activities
  • compliance automation tooling
  • Exceptional attention to detail
  • manage multiple concurrent workstreams
  • keep documentation aligned
  • dynamic cloud environment
  • Clear communicator
  • write crisp control implementation statements
  • explain compliance requirements to engineering audiences