Jobs and Careers
SM

Sr. Compliance Engineer

Smartsheet
United StatesRemotefull_timeVerifiedPosted 17 Mar 2023
💰 $172,800/yr($110,000/yr$172,800/yr)

About the role

The Senior Compliance Engineer is responsible for ensuring the organization's compliance with relevant regulations, standards, and policies related to Smartsheet Information Systems operations. The ideal candidate has extensive experience in FedRAMP, SOC, and ISO audit practices and standards. They will be responsible for maintaining continuous compliance with various regulations, policies, and standards, as well as identifying and mitigating risks associated with Information Systems operations. In this role, they will work closely with internal and external stakeholders to develop, implement, and maintain our security controls, assess and manage risks, and provide recommendations for process improvements. This role also involves conducting assessments, identifying gaps, and recommending solutions to increase the maturity of the compliance program at Smartsheet. 

In 2005, Smartsheet was founded on the idea that teams and millions of people worldwide deserve a better way to deliver their very best work. Today, we deliver a leading cloud-based platform for work execution, empowering organizations to plan, capture, track, automate, and report on work at scale, resulting in more efficient processes and better business outcomes.

You will report to our Manager, Governance, Risk & Compliance located in our Bellevue, WA office, or you may work remotely from anywhere in the US where Smartsheet is a registered employer.

You Will:

  • Develop and maintain IT compliance programs in accordance with FedRamp, SOC, and ISO standards
  • Conduct and direct external audits to assess compliance with policies, procedures, and standards
  • Plan and execute end-to-end compliance initiatives in accordance with the Security Functional Plan
  • Continuously maintain and improve Smartsheet’s security control framework
  • Draft and implement procedures, guides, whitepapers, and other documentation related to our compliance program
  • Build and maintain security controls that map to NIST 800.53 security compliance requirements and provide implementation recommendations for new controls
  • Identify areas where compliance, and specifically security compliance controls, can be improved through automation
  • Design requirements for security compliance automation tasks
  • Recommend new security compliance metrics and automate reporting of existing metrics
  • Conduct periodic assessments of the organization's IT systems and operations to ensure compliance with regulatory requirements, industry standards, and internal policies 
  • Identify and document gaps and potential risks in the organization's IT practices and recommend appropriate solutions to address these issues 
  • Develop and implement policies, procedures, and controls to ensure compliance with regulatory requirements and industry standards  
  • Collaborate with internal and external stakeholders to provide guidance on compliance requirements and assist with audit preparations and responses 
  • Monitor changes in regulatory requirements and industry standards and recommend updates to policies and procedures accordingly  
  • Provide training where necessary to employees on compliance requirements and best practices 
  • Maintain documentation and tracking of compliance-related activities, including reports, audit findings, and remediation plans 
  • Assist with the development and implementation of Information Systems governance frameworks

You Have:

  • 5+ years of experience in IT compliance, information security, or related field
  • Bachelor’s degree in Computer Science, Information Systems, Information Technology, or related field, or equivalent work experience
  • Experience in FedRAMP audit standards, practices, and controls
  • Knowledge of industry standards such as ISO 27001, NIST, and COBIT 
  • Deep understanding of audit standards and practices, and security control frameworks
  • Extensive knowledge and understanding of information security policies, standards, procedures, and guidelines
  • Knowledge and understanding of end-user computing tools, hardware, application software, networks, communications, and mobile device technologies
  • Ability to work with Security Operations Engineers to identify gaps in technology tools, policies, and procedures
  • Understanding of concepts and philosophies regarding the design and implementation of information technologies and associated architectural concepts, principles, and tools
  • Experience with regulatory requirements such as PCI-DSS, HIPAA, SOX, GDPR, and CCPA 
  • Strong understanding of risk management principles, practices, and frameworks
  • Communication, analytical, and problem-solving skills 
  • Relevant certifications such as CISA, CISSP, or CRISC are preferred, but not

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Smartsheet

View company profile →