Compliance Engineer
TRM Labs provides a blockchain intelligence platform to help organizations investigate, monitor, and detect crypto and digital asset fraud and financial crime. They serve government agencies, financial institutions, and crypto businesses worldwide.
Investors
About TRM Labs
TRM Labs provides a next-generation blockchain intelligence platform designed to investigate, monitor, and detect crypto and digital asset fraud and financial crime. The platform features extensive asset coverage, supporting over 200 million assets across more than 41 blockchains, including NFTs and DeFi protocols. It offers cross-chain analytics to trace the flow of funds seamlessly between different blockchains and utilizes over 150 risk categories, including FATF's money laundering predicate offenses, for customized risk scoring. TRM's data is built from a large, proprietary database of illicit activity combined with advanced data science. The company serves a global client base, including government agencies, financial institutions, and crypto businesses, helping them to safeguard the crypto financial system, maintain high standards for AML/CFT compliance, and build trust in digital assets.
Skills
About the Role
You will own compliance and GRC initiatives to ensure security and trust for customers. You will develop and implement controls, gather audit evidence, run risk assessments, and respond to due diligence requests. You will maintain mappings to frameworks and help shape security programs.
Requirements
- Experience with Python or other programming and scripting languages is required
- Strong understanding of public sector compliance standards including NIST 800-53 SOC 2 CMMC ISO 27001 and CyberEssentials UK
- Experience leading a cloud first SaaS company through the audit process
- Privacy and GDPR experience is a plus
- Security certifications such as CISSP or CISM are a plus
Responsibilities
- Develop scalable controls and evidence collection processes and monitor control effectiveness
- Manage the compliance and certification lifecycle including SOC 2 Type II ISO 27001 27701 FedRAMP and CMMC
- Operationalize the GRC program to maintain certifications
- Develop and maintain security collateral for customers such as SIG and CAIQ
- Conduct enterprise risk assessments and maintain the risk registry
- Develop a vendor risk management program
- Identify areas for improvement based on input from customers and business objectives
