Trumid
Technology Compliance Associate
Remote · Posted 3h ago
Job Description
About us.
Trumid is a dynamic fintech revolutionizing the landscape of fixed income trading. With intelligent, easy-to-use, electronic solutions, we are rapidly growing and seeking exceptional talent to help redefine the boundaries of technology and finance.
Founded in 2014 by a team of fixed income market experts, Trumid has quickly become one of the top three corporate bond e-trading platforms in the U.S. Today, over 1,300 traders from an extensive and expanding client network of 920+ buy- and sell-side institutions transact on Trumid monthly.
With a rich history of innovation and a unique ability to innovate at scale, we collaborate closely with our clients, iterating quickly toward optimal solutions. With market share and client engagement at all-time highs and our pace of product development faster than ever, this is an exciting and transformative time at Trumid.
Our business model thrives on participation, and so does our company culture. We rely on every team member's contribution to help us accomplish our goals. To succeed at Trumid, you must be curious, passionate about your craft, ambitious, collaborative, and driven. Learn more at www.trumid.com.
The opportunity.
Trumid is seeking a Technology Compliance Associate to join our Technology Compliance team. Reporting to our Technology Compliance Manager, you’ll take ownership of key areas — including client security questionnaires and day-to-day security operations — while getting hands-on exposure across AI governance and SOC 2 program operations, working alongside clients, auditors, and regulators. This is a great fit for someone early in their compliance or security career who wants real ownership plus the chance to learn directly from an experienced tech compliance leader as our program scales.
What You'll Do:
AI Governance
-
Develop and implement AI usage policies and governance frameworks for the organization
-
Implement guardrails and security controls using AI Gateway and similar tools
-
Conduct security assessments and risk evaluations for AI tools and services
-
Review AI tool usage and provide metrics through observability platforms
-
Ensure data privacy and protection standards are maintained across AI tool adoption
-
Manage vendor assessments and ongoing monitoring for AI service providers
-
Stay current on emerging AI regulation, including NIST AI RMF and EU AI Act developments
Compliance & Risk
-
Operate SOC 2 compliance program including control frameworks, evidence collection, audit coordination, and certification maintenance
-
Conduct security risk assessments, phishing simulations, vulnerability management, and penetration testing coordination
-
Drive BCP/DR planning, testing, and documentation
-
Manage security incident response processes and post-incident reviews
-
Track and report on security metrics, compliance posture, and risk remediation
Security Operations
-
Day-to-day operational oversight of CrowdStrike Falcon Complete including alert triage, monitoring, and liaising with security engineering on configuration and escalations
-
Support identity and access management programs including employee access reviews and privileged access controls
-
Tracking and reporting on vulnerability scan findings; coordinating remediation workflows with engineering
-
Coordinating and managing third-party penetration testing engagements; tracking findings through to remediation
Client, Vendor & DDQ Management
-
Own and manage the end-to-end DDQ (Due Diligence Questionnaire) process, including response accuracy, version control, and automation initiatives; serve as the primary point of contact for client and prospect security questionnaires
-
Conduct vendor security assessments and manage third-party risk
-
Support legal and compliance teams on vendor contracts and technical due diligence
About you.
-
Experience: 4+ years in information security or GRC/Compliance with hands-on technical experience and demonstrated leadership
-
Technical depth: Familiarity with cloud security (AWS required, GCP valued), security tooling (CrowdStrike or similar EDR/XDR platforms), and infrastructure security controls
-
AI security knowledge: Understanding of AI/LLM security risks, data privacy concerns, and emerging AI governance frameworks (NIST AI RMF, EU AI Act)
-
SOC 2 expertise: Operational experience running SOC 2 programs in production environments with successful audit outcomes
-
Security frameworks: Working knowledge of SOC 2, ISO 27001, NIST frameworks and their practical application
-
Client-facing skills: Proven ability to communicate security concepts to institutional clients and represent technical capabilities professionally
-
Compliance knowledge: Experience with security compliance in financial services or other regulated industries
-
Communication: Excellent written and verbal skills across technical and non-technical audiences
-
Certifications: CISSP, CISM, Security+, or equivalent preferred
-
Education: Bachelor's degree in Computer Science, Information Security, or related field
Technical Environment
You'll work with:
-
Cloud Platforms: AWS (primary), GCP
-
Security Tools: CrowdStrike Falcon Complete, Vanta, vulnerability scanners
-
AI & Observability: AI Gateway tools, LLM monitoring platforms, observability tools
-
Infrastructure: Cloud-native services
-
Compliance Frameworks: SOC 2, ISO 27001, NIST
-
Identity & Access: SSO, MFA, access control systems
Employee Benefits
-
Highly competitive compensation
-
Fully paid medical, dental and vision coverage
-
Remote work flexibility
-
Team-oriented and collaborative company culture
In compliance with New York City Pay Transparency Law, the base salary range for this role in New York City is between $150,000 - $175,000. This range does not include discretionary bonus or other forms of compensation or benefits offered in connection with this job. Several factors are considered when determining a candidate's compensation. Please note that the salary range listed for this position is based on the level of experience outlined in the job description. If a candidate's experience differs from the requirements, the salary may be adjusted accordingly.
Trumid is an equal opportunity employer.
Please note: All communication from Trumid's recruiting team comes from @trumid.com email addresses. We conduct remote interviews via Zoom only. We will never ask you to purchase equipment, download software (other than Zoom), or share sensitive personal information during the hiring process.
More jobs like this
Digital Products & Experiences Operations Associate
Pfizer · United States - New York - New York City · $60-100K
Management Trainee (Pittsburgh Airport)
SIXT · Pittsburgh, PA, us · $24-24/hr
Student Internship - Environmental Sciences/Geology
Olsson · Omaha, NE