Analyst, Cloud Engineering Compliance (Paisly)
About the role
The Analyst, Cloud Engineering Compliance supports the maintenance and evolution of Paisly’s compliance program to ensure adherence to applicable laws, regulatory frameworks, and internal policies. This role assists in initiatives to assess, implement, and monitor controls aligned with industry-specific requirements, with a focus on supporting compliance efforts for regulatory requirements in multiple geographical areas. The Analyst collaborates with engineering, security, legal, and product teams to embed compliance into technical operations and ensure Paisly’s products meet external obligations and internal governance standards. This role also works cross-functionally with Paisly’s matrix partners to support shared risk and compliance objectives.
The ideal candidate is an agile problem-solver who adapts to shifting business priorities, excels in complex projects, and is motivated to deliver results.
Responsibilities
- Support the development, implementation, and continuous improvement of technical compliance policies, procedures, and training programs across the organization.
- Assist in monitoring technical compliance systems and internal controls to ensure adherence to laws and standards (e.g., GDPR, CCPA, PCI-DSS, ISO).
- Conduct compliance research and monitoring specifically for Brazil and Mexico regulatory frameworks to support international business expansion.
- Collaborate with product, engineering, and legal teams to identify and document technical compliance risks in business initiatives.
- Support internal and external audits by gathering evidence and maintaining compliance documentation.
- Perform periodic risk assessments and gap analyses to support compliance planning.
- Other projects and duties as assigned.
Requirements
- Bachelor's degree in a relevant field such as Technical Compliance, Risk Management, or Information Security; OR High School Diploma/GED and at least four (4) years of related work experience.
- Two (2) years’ experience in technical compliance, risk management, or a related analyst function.
- Proven understanding of global data privacy and security regulations and industry standards.
- Experience supporting the implementation of technical compliance controls and audit processes.
- Demonstrated ability to interpret and apply complex regulatory requirements in a fast-paced, technology-driven environment.
- Strong communication skills with experience presenting technical compliance issues and recommendations to stakeholders at various organizational levels.
- Proven ability to work cross-functionally with legal, security, data, product, and engineering teams.
- Detail-oriented, analytical thinker with strong organizational and project management skills.
- Ability to manage confidential and sensitive information with the highest level of integrity.
- Available for occasional overnight travel (10%).
- Must pass a ten (10) year background check.
- Must be legally eligible to work in the country where the position is located; authorization to work in the US is required (this position is not eligible for visa sponsorship).
Preferred Qualifications
- Knowledge of Brazil's General Personal Data Protection Law (LGPD) and Mexico's Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP).
- Experience leading or contributing to technical compliance programs involving privacy, security, consumer protection, or financial regulations.
- Familiarity with governance, risk, and compliance (GRC) tools and regulatory technology platforms.
- Strong understanding of cloud compliance frameworks and certifications (e.g., ISO/IEC 27001, SOC 2, PCI-DSS) across environments such as AWS, Microsoft Azure, or Google Cloud Platform (GCP).
- Experience coordinating internal or external audits, regulatory reviews, or investigations.
- Demonstrated ability to interpret and apply laws such as GDPR, CCPA, and other privacy or industry-specific regulatory frameworks.
- Relevant certifications such as Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or similar.
- Experience working cross-functionally with legal, security, product, and operations teams to operationalize compliance requirements.
Work Environment
- Traditional office environment.
- Occasional overnight travel (10%).
- Potential need to work flexible hours and respond on short notice.
- When working or traveling on JetBlue flights, capable crewmembers may assist with light cleaning of the aircraft if time permits.
Physical Requirements
Generally not required, or up to 10 pounds occasionally (sedentary work).