Senior Compliance Analyst, Customer Trust
Menlo Park, United States · Hybrid · Full-time
- Posted 3d ago
- From Snowflake’s careers page
- Location
- Menlo Park, United States
- Work mode
- Hybrid
- Type
- Full-time
- Level
- Senior
- Experience
- 5+ years
- Department
- Engineering
Apply on Snowflake’s site
Opens the listing on jobs.ashbyhq.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
As a Senior Compliance Analyst, Customer Trust at Snowflake, you will:
Customer Trust
- Respond to customer due diligence questionnaires and audits about Snowflake's security and compliance obligations.
- Become an expert on Snowflake's control environment, security features, and best practices for customer deployments.
- Serve as a trusted advisor on customer and regulator inquiries about Snowflake's security and compliance obligations and documentation.
- Join sales conversations to explain Snowflake's security and compliance capabilities.
Third-Party Oversight, Governance, and Risk Management
- Conduct security risk assessments of new and existing vendors, evaluating their security posture against contractual, regulatory, and industry requirements.
- Partner with Legal and Procurement to make sure security requirements are reflected in vendor contracts and security agreements.
- Continuously improve the TPRM program by refining tiering criteria, streamlining intake, and shortening assessment turnaround times.
- Monitor the vendor risk landscape for emerging threats and proactively reassess affected vendors.
- Support customer and regulator inquiries about Snowflake's own third-party risk management practices as part of broader audit engagements.
Our ideal Senior Compliance Analyst, Customer Trust will have:
- 5+ years of technical audit or compliance experience with programs such as SOC 2, ISO certifications, PCI DSS, C5, Cyber Essentials Plus, or IT audits based on ISAE 3402 preferred.
- Experience in vendor risk management, third-party risk, procurement security, or a related GRC function.
- A detailed understanding of evaluating the design and effectiveness of IT controls, collecting evidence, and working with auditors and regulators on these assessments.
- Ability to manage a high volume of concurrent vendor assessments while keeping turnaround times consistent.
- Strong written and verbal communication skills, with the ability to explain compliance concepts to technical and non-technical stakeholders.
- Experience using AI to automate or streamline manual compliance workflows.
Bonus points for the following:
- CISSP, CRISC, CISA, or other GRC or security certifications
- Experience with TPRM or GRC tooling, such as OneTrust, ServiceNow, Prevalent, or Vanta
- Experience with sub-processor management and vendor data privacy obligations (GDPR, CCPA)
- Experience with regulated-industry vendor requirements, such as PCI DSS, HIPAA, or FedRAMP supply-chain provisions
Skills they ask for
Pick one to see other roles that ask for it.
About Snowflake
Cloud data, analytics and AI platformSnowflake provides a managed cloud platform for data engineering, analytics, AI, and building and sharing data applications.
See all 170 roles at SnowflakeMore roles at Snowflake
See all 170- Account EngineerChicagoEngineeringChicago, United States4h
- Account Executive, Enterprise AcquisitionUnited States · RemoteSales · RemoteUnited States10h
- Brand DesignerMenlo ParkMarketingMenlo Park, United States11h
- Director of Engineering - Traffic & NetworkingMenlo Park · Director · On-siteEngineering · Director · On-siteMenlo Park, United States1d
Share this role
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.