Posted on: 19/06/2026
How you will help :
The role partners with business and IT leaders across the company, defining appropriate certification requirements, and oversees execution of audit, assessment, and testing activities to achieve and maintain compliance.
The Compliance Analyst is expected to develop and maintain a working expertise of evolving industry and regulatory compliance requirements, enabling Synchronoss to maintain a competitive advantage in the marketplace by sustaining security and data privacy certifications.
In addition, the role will assist with other GRC programs such as Third-Party Risk Management, Internal Self-Assessments, Customer Audits, Risk Management, Data Management, Data Privacy, Business Continuity and Disaster Recovery, and Security Maturity scoring.
Who we have in mind :
- Oversee execution of required SOC2 and PCI audits across multiple product platforms.
- Collaborate with business and IT Subject Matter Experts to identify SOC2 and PCI controls that are applicable to SNCR products.
- Identify supporting evidence and develop testing strategies for in-scope controls.
- Provide direct oversight of control preparedness, ensuring successful audit completion and certifications.
- Guide internal stakeholders to fully understand control requirements and to prepare for audit and testing activities.
- Develop strategies for effective and efficient evidence gathering, storing and delivery to auditors, including the use of Artificial Intelligence to streamline activities.
- Actively manage auditor requests and function as liaison between auditors and internal stakeholders.
- Drive appropriate follow-up to certification results, provide remediation advice and oversee implementation of appropriate remediation activities.
- Provide guidance to identifying appropriate technical and process solutions to meet evolving compliance and security requirements.
- Assist with the management of customer audits and questionnaires.
- Assist with internal control self-assessments as needed, concentrating on IT Internal Controls, Information Security and Business Continuity / Disaster Recovery.
- Develop self-assessment timeline, audit work program as well as execute control review and testing.
- Author final report detailing testing results and management action plans.
- Assist with the build-out of the Business Continuity and Disaster Recovery Program across all products and services.
It would be great if you had :
- 5+ years of experience with risk management and auditing practices include testing of controls, and substantive testing of transactions.
- Background in the IT industry, preferably with Information Security, Software Development or Business Continuity / Disaster Recovery.
- Familiarity with PCI and SOC2 certifications, including strong understanding of assessment processes, compliance requirements, and controls applied to both business processes and IT systems.
- Working knowledge of technologies and security solutions offered by industry for related process and technical controls.
- Firsthand experience in risk management and/or auditing desired; CISSP, CIA, or related certifications are a plus.
- Excellent verbal and written communication and presentation skills. Must have the ability to communicate effectively with auditors, suppliers, internal stakeholders, and management in both formal and informal situations.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1646490