Jobs · Virginia

Regulatory & Security Compliance Analyst

Takt · Reston, VA · 4 days ago
HybridFull-time

TaktTakt is an AI-powered warehouse intelligence platform that helps some of the world's largest retailers, 3PLs, and e-commerce companies better understand and optimize their operations. Our platform brings together data from labor management systems, warehouse management systems, automation, robotics, and other operational systems to give warehouse teams a unified view of their operations. As we continue to grow globally, security, privacy, and compliance are critical to earning and maintaining the trust of our customers.

About the Role

This is a strong opportunity for someone early in their career who has built a foundation in risk, audit, compliance, or advisory work and wants to take direct ownership of a company's compliance program.

You will be responsible for keeping Takt's compliance program operating effectively day to day, including managing our controls and evidence in Vanta, coordinating audits and certifications, maintaining our privacy program, and helping customers understand how Takt protects their data.

You'll work closely with Engineering, IT, Legal, Sales, Customer Success, and company leadership. This is a hands-on role. You should be comfortable moving between reviewing a Vanta control, preparing evidence for an auditor, responding to a customer's security questionnaire, updating a GDPR record, and explaining our compliance posture to company leadership.

We are not expecting you to arrive as an expert in every framework. We are looking for someone with strong fundamentals, sound judgment, attention to detail, and the ability to learn quickly. Takt will invest in training, certifications, and development to help you grow into the role.

The role reports administratively to the CTO. As part of the role, you will also serve as Takt's Data Protection Officer (DPO) and operate independently in that capacity with direct access to Takt's Leadership Team and Board of Directors when required.

Responsibilities

Compliance Program

  • Own the day-to-day administration of Takt's compliance program in Vanta, including controls, tests, evidence, policies, risks, vendors, personnel, and remediation activities.
  • Manage and continuously improve our SOC 2 Type II compliance program.
  • Support Takt's implementation and ongoing maintenance of ISO 27001 and related security and privacy frameworks.
  • Coordinate annual audits, assessments, penetration tests, and certification activities with external auditors and vendors.
  • Track compliance findings and remediation activities and work with internal owners to ensure they are resolved.
  • Maintain security and compliance policies and ensure required reviews and approvals occur on schedule.
  • Monitor employee security and compliance requirements, including training, policy acceptance, device compliance, and access reviews.
  • Manage Takt's vendor risk management and third-party assessment processes.
  • Maintain an accurate, audit-ready compliance environment rather than preparing for compliance only when an audit approaches.

Privacy & Data Protection

  • Serve as Takt's Data Protection Officer (DPO), with training and external support provided as you grow into the role.
  • Oversee Takt's compliance with GDPR, UK GDPR, and other applicable privacy requirements.
  • Maintain Takt's Records of Processing Activities, data inventories, privacy policies, subprocessors, Data Processing Agreements, and related documentation.
  • Support privacy reviews for new products, features, integrations, and uses of personal data.
  • Coordinate Data Protection Impact Assessments and other privacy risk assessments when required.
  • Manage processes for responding to data subject requests.
  • Serve as a point of contact for customers, data subjects, supervisory authorities, and Takt's privacy representatives where appropriate.
  • Monitor changes in privacy regulations and help translate them into practical actions for the business.
  • Help ensure privacy principles are incorporated into Takt's product development and operational processes.

Customer Trust

  • Own or coordinate responses to customer security questionnaires, privacy questionnaires, RFPs, and due diligence requests.
  • Work with Sales and Customer Success to provide accurate and timely answers to customer security and compliance questions.
  • Maintain a reusable library of approved security, privacy, architecture, and compliance responses.
  • Coordinate customer requests for SOC 2 reports, penetration test summaries, policies, certifications, and other trust documentation.
  • Participate in customer security and privacy calls when deeper compliance expertise is required.
  • Help make the security review process faster and easier for both Takt and our customers.

Reporting & Governance

  • Maintain a clear view of Takt's overall compliance posture, including open risks, control failures, audit findings, privacy issues, and upcoming obligations.
  • Present a monthly compliance and privacy update to Takt's Leadership Team, including key metrics, risks, upcoming audits, and areas requiring leadership attention.
  • Escalate material compliance, security, or privacy concerns directly to executive leadership.
  • In your capacity as DPO, maintain the independence necessary to perform the role and have direct access to the Board of Directors when circumstances require escalation.
  • Prepare compliance and privacy reporting for the Board as requested or when significant risks warrant Board attention.

Requirements

  • 2-4 years of experience in risk advisory, technology risk, IT audit, cybersecurity risk, compliance, or a related field.
  • Experience at a professional services firm such as KPMG, Deloitte, PwC, EY, or a similar risk and advisory organization is strongly preferred.
  • Experience working with controls, risk assessments, audit evidence, testing, or compliance frameworks.
  • Familiarity with SOC 2, ISO 27001, ITGCs, cybersecurity controls, or similar frameworks.
  • Strong analytical skills and attention to detail.
  • Strong written communication skills and the ability to turn complex requirements into clear, practical documentation.
  • Comfortable working directly with technical teams, business stakeholders, auditors, and customers.
  • Highly organized and able to manage multiple workstreams, deadlines, and follow-ups.
  • Curious, self-directed, and interested in building deep expertise in security, privacy, and compliance. You do not need to already be an expert in GDPR, ISO 27001, Vanta, or data protection law. We care more about strong fundamentals, judgment, and your ability to learn.

Nice to Have

  • Experience with SOC 2 or ISO 27001 audits.
  • Experience performing ITGC, technology risk, cybersecurity, or privacy assessments.
  • Familiarity with Vanta or another GRC/compliance platform.
  • Experience responding to customer security questionnaires or supporting third-party risk assessments.
  • Exposure to GDPR or privacy compliance.
  • Experience working with SaaS or cloud technology companies.
  • Familiarity with Google Cloud Platform, Kubernetes, or modern cloud infrastructure.

Training & Development

We expect this role to grow significantly over time and will invest in that development. Depending on your background and interests, Takt will support training and certifications in areas such as:

  • GDPR and data protection
  • CIPP/E or CIPM
  • ISO 27001 implementation and auditing
  • SOC 2 and security assurance
  • Cloud security
  • GRC and risk management

You will also work closely with Takt's CTO, engineering leadership, outside counsel, auditors, and external privacy advisors as you build expertise. Our goal is for this person to develop from a strong risk and compliance analyst into the internal expert responsible for Takt's global security, privacy, and compliance program.

Reporting & Independence

This role reports to the CTO for administrative and managerial purposes, including performance management, career development, prioritization, and day-to-day coordination. The Data Protection Officer function is independent. When performing DPO responsibilities, this person:

  • Reports functionally to Takt's Leadership Team.
  • Provides a formal compliance and privacy update to the Leadership Team at least monthly.
  • Has direct and unrestricted access to the Board of Directors when necessary.
  • May raise privacy or data protection concerns without prior approval from management.
  • Will not receive instructions regarding the conclusions or recommendations they make while performing their DPO responsibilities.
  • Will not be penalized for performing their responsibilities as DPO.
  • Must avoid responsibilities that create a conflict of interest by requiring them to determine the purposes or means of Takt's processing of personal data.

Schedule

This position is based in Reston, Virginia. Team members in this role are expected to work from our Reston office four days per week, with one flexible remote day.

Success in This Role

Within your first year, success will mean:

  • Takt's Vanta environment accurately reflects our compliance posture and requires minimal cleanup ahead of audits.
  • SOC 2 and ISO 27001 activities operate on a predictable, continuous cadence.
  • You have developed a strong working knowledge of Takt's GDPR and privacy obligations and can independently manage the majority of routine privacy matters.
  • Customer security and privacy questionnaires are answered quickly and consistently.
  • Compliance risks and remediation items have clear owners and deadlines.
  • Leadership has a concise, accurate monthly view of Takt's security, privacy, and compliance posture.
  • Employees across Takt know where to go when they have a security, privacy, or compliance question.
  • You are steadily developing into Takt's internal subject-matter expert for security, privacy, and compliance.

Similar jobs