Security Compliance Analyst
Filevine · Salt Lake City, UT · 2 days ago
On-siteLegalFull-time
Filevine is a Legal AI company delivering Legal Operating Intelligence for the future of legal work. Grounded in a singular system of truth, Filevine brings together data, documents, workflows, and teams into one unified platform—where modern legal work happens with clarity and consistency. Powered by LOIS, the Legal Operating Intelligence System, Filevine connects context across every matter to transform legal operations from reactive to proactive. LOIS reads, understands, and reasons across your data to surface insight, automate complexity, and give professionals the clarity and confidence to see more, know more, and do more. Fueled by a team of exceptional collaborators and innovators, Filevine’s rapid growth has earned AI awards and recognition from Deloitte and Inc. as one of the most innovative and fastest-growing technology companies in the country. About Filevine Filevine is forging the future of legal work with cloud-based workflow tools. We have a reputation for intuitive, streamlined technology that helps professionals manage their organization and serve their clients better. We’re also known for our team of extraordinary and passionate professionals who love working together to help organizations thrive. Our success has catapulted Filevine to the forefront of our field—we are ranked as one of the most innovative and fastest-growing technology companies in the country by both Deloitte and Inc. Department Statement The IT Audit team is responsible for performing timely audits and ensuring compliance and risk assessment efforts are aligned with industry standards and best practices. Filevine is looking for a High Security Compliance Analyst to join our Information Security team to ensure that our platform, applications, and infrastructure are compliant and secured at the highest levels thus protecting and enhancing customer trust. If you are bright, hardworking, ambitious, and enjoy taking ownership of security and compliance, we want to talk to you. This is an exciting opportunity to join a world-class team. Responsibilities: Manage CJIS obligations, including monthly and yearly audits, clearances for employees, and associated CJIS effortsAssist with Federal and international government security audits (e.g. FedRAMP, StateRAMP, Canadian government compliance obligations Strategize and outline goals and objectives of the GRC (IT Audit and Risk management) programsAssist with security efforts to meet HIPAA, SOC 2 Type I & II, and other compliance requirementsWork directly with Information Security, Legal, HR, Compliance and Development teams to ensure secure IT and IS best practices are fully adopted at FilevineHelp train employees on auditing secure coding techniques to mitigate the need for break-fix/out-of-band patchingReview audit, compliance and risk assessment issues that arise and manage them to resolutionProvide audit frameworks and risk assessment methodologies contemplating new software solutions to help mitigate security vulnerabilities and other business risksMaintain documented Policy and Procedure libraries for compliance purposesComplete Third-party vendor risk management and security questionnaires for FilevineProvided annual Internal audit and risk assessment functionsFacilitate and lead annual penetration testing and auditing effortsDevelop a familiarity with new auditing and risk assessment tools and techniques Qualifications: Bachelor's Degree or equivalent in Computer Science, Computer Engineering, Information Technology, or related field4+ years of experience in IT Auditing, Compliance Analysst and/or direct experience related to risk assessment methodologiesProven work experience as IT Audit & Risk Assessor with a passion for details and securityFamiliarity with auditing and assessing the OWASP Top 10Experience with managing risks, fraud, and security threatsKnowledge of web related technologies (Web applications, Web Services and Service Oriented Architectures, Web Databases) and of network/web related protocolsExperience assessing, testing, or auditing technical IT and security controlsWorking knowledge of and demonstrated experience with ISO 27701, ISO 27018, ISO 27001Experience with FedRAMP is preferred, as well as SOC II Type I & II, HIPAA Security Rule, CJIS, GDPR, CCPA/CPRA and other compliance frameworksDemonstrated knowledge of assessing development methodologies (Agile, Waterfall)Ability to work in a fast-paced environmentMust exhibit excellence in partnering, teamwork, and quality performanceAble to effectively give, receive, and respond to feedbackExcellent oral and written communication skills with the ability to communicate security concepts to a technical and non-technical audience including senior managementDemonstrated ability to establish relationships and build rapport to influence colleagues at all levels, uncover issues, and identify needsThis will be a hybrid schedule position ( 3/2 or 4/1 - TBD) Preferred Qualifications: Significant experience with auditing frameworks, formal audits, and risk assessment experienceSignificant experience with automated auditing and compliance toolsGRC tool Certification or equivalent experienceCISSP Certification or equivalent experienceCISM Certification or equivalent experienceCISA Certification or equivalent experienceCIPP/US Certification or equivalent experienceCRISC Certification or equivalent experience Filevine is an Equal Opportunity Employer. Qualifications for employment, promotion and other terms and conditions of employment are based upon the ability to perform the job. Equal-employment opportunities are provided to all applicants and employees without regard to race, creed, religion, color, age, national origin, sex, disability, veteran status, or other legally protected class. Filevine is committed to providing reasonable accommodations for qualified individuals with disabilities. If you need assistance or accommodation due to disability, or if you have concerns related to Filevine’s equal employment opportunities, you may contact us at legal@filevine.com Cool Company Benefits: A dynamic, rapidly growing company, focused on helping organizations thrive Medical, Dental, & Vision Insurance (for full-time employees) Competitive & Fair Pay Maternity & paternity leave (for full-time employees) Short & long-term disability Opportunity to learn from a dedicated leadership team Top-of-the-line company swag Privacy Policy Notice Filevine will handle your personal information according to what’s outlined in our Privacy Policy. Communication about this opportunity, or any open role at Filevine, will only come from representatives with email addresses using "filevine.com". Other addresses reaching out are not affiliated with Filevine and should not be responded to. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.