Senior Compliance and Risk Analyst

Posted Yesterday
Hiring Remotely in USA
Remote
198K-233K Annually
Senior level
HR Tech • Software
The Role
Lead and mature Calendly’s compliance and risk program (SOC 2, ISO 27001). Design and operationalize controls, run audits, perform risk assessments and UARs, manage remediation, optimize compliance automation, produce risk reporting and dashboards, and partner cross-functionally to embed compliance into product and business processes.
Summary Generated by Built In
What’s in it for you? 

Ready to make a serious impact? Millions of people already rely on Calendly, and we’re still in the midst of exciting product growth — it’s a fantastic time to join us. Everything you’ll work on here will accelerate your career to the next level. If you want to learn, grow, and do the best work of your life alongside the best people you’ve ever worked with, then we hope you’ll consider allowing Calendly to be a part of your professional journey.

About the team & opportunity

Our Compliance and Risk team is a strategic partner that enables the business to grow securely and responsibly. We work across Engineering, Security, Product, Legal, HR, and Business Operations to build scalable compliance and risk programs that support innovation while maintaining customer trust.

As a Senior Compliance and Risk Analyst, you will own and mature our compliance program, ensuring the organization maintains certifications such as SOC 2 and ISO 27001 while building scalable, automated processes that support a rapidly growing SaaS business.

This is a high-impact role for someone who enjoys both strategy and execution. You'll design and operationalize controls, strengthen our common controls framework, optimize compliance automation, and embed compliance into business processes and product development. Beyond maintaining audit readiness, you'll help shape how compliance evolves as the organization grows, driving continuous improvement and fostering a proactive culture of risk management.

A day in the life of a Senior Compliance and Risk Analyst

  • Own and manage the organization's compliance program, including SOC 2 and ISO 27001 readiness, certification, and ongoing maintenance.
  • Develop and execute a compliance roadmap aligned with business objectives, regulatory requirements, and organizational risk appetite.
  • Lead internal and external audits by coordinating evidence collection, managing auditor relationships, and driving timely remediation of findings.
  • Monitor changes in regulatory and industry frameworks, assessing their impact on the organization's compliance program.
  • Own the enterprise risk management process, including risk identification, assessment, treatment planning, and ongoing monitoring.
  • Conduct periodic risk assessments and partner with stakeholders to identify control gaps and prioritize remediation activities.
  • Develop and present compliance metrics, risk dashboards, and executive reports for senior leadership.
  • Design, document, and improve internal controls aligned with SOC 2, ISO 27001, and other applicable frameworks.
  • Lead control testing, including evidence collection, effectiveness validation, remediation tracking, and continuous improvement.
  • Expand and mature the organization's common controls framework to support evolving compliance requirements.
  • Administer and optimize compliance automation platforms, improving workflow efficiency and reducing manual effort.
  • Perform User Access Reviews (UARs) and support continuous compliance monitoring through automation and reporting.
  • Partner with Engineering, Security, Product, Legal, HR, and Operations to integrate compliance into business processes and product development.
  • Develop training, playbooks, and self-service resources that empower teams to meet compliance requirements efficiently.
  • Manage multiple compliance initiatives simultaneously while ensuring projects remain on schedule and stakeholders stay informed.

What do we need from you?

  • 5+ years of experience in compliance, risk management, audit, or Governance, Risk, and Compliance (GRC) roles within a technology or SaaS environment.
  • Experience owning or leading compliance programs supporting frameworks such as SOC 2 and ISO 27001.
  • Working knowledge of security and privacy frameworks including NIST, ISO 27001, GDPR, and HIPAA.
  • Experience administering compliance automation platforms such as Drata, Vanta, Tugboat Logic, or similar solutions.
  • Experience performing User Access Reviews (UARs) using GRC or compliance automation platforms.
  • Strong understanding of internal controls, risk assessment methodologies, and audit processes.
  • Demonstrated ability to manage multiple initiatives and deliver results in a fast-paced environment.
  • Excellent project management, analytical, and problem-solving skills.
  • Strong communication skills with the ability to translate technical and regulatory requirements into practical business solutions.
  • Proven ability to collaborate effectively with technical and non-technical stakeholders across the organization.

Preferred Qualifications

  • Experience leveraging AI to improve compliance processes or automate workflows.
  • Experience scaling compliance programs within a high-growth SaaS organization.
  • Hands-on experience developing or expanding a common controls framework.
  • Advanced expertise configuring compliance automation platforms, including integrations, custom controls, and reporting.
  • Familiarity with additional compliance frameworks such as PCI DSS, FedRAMP, or other industry standards.
  • Experience developing compliance training, awareness programs, or self-service enablement resources.
  • Professional certifications such as CISA, CRISC, CISSP, CCSK, or equivalent.
Tier 1 Salary Hiring Range
$198,238$233,221 USD
Tier 2 Salary Hiring Range
$181,718$213,786 USD
Tier 3 Salary Hiring Range
$165,198$194,351 USD

The ranges listed above are the expected annual base salary for this role, subject to change.

Calendly takes a number of factors into consideration when determining an employee’s starting salary, including relevant experience, relevant skills sets, interview performance, location/metropolitan area, and internal pay equity.

Base salary is just one component of Calendly’s total rewards package. All full-time (30 hours/week) employees are also eligible for our Top Performer Bonus program (or Sales incentive), equity awards, and competitive benefits.

Calendly uses the zip code of an employee’s remote work location, or the onsite building location if hybrid, to determine which metropolitan pay range we use. Current geographic zones are as follows:

  • Tier 1: San Francisco, CA, San Jose, CA, New York City, NY
  • Tier 2: Chicago, IL, Austin, TX, Denver, CO, Boston, MA, Washington D.C., Philadelphia, PA, Portland, OR, Seattle, WA, Miami, FL, and all other cities in CA.
  • Tier 3: All other locations not in Tier 1 or Tier 2

If you are an individual with a disability and would like to request a reasonable accommodation as part of the application or recruiting process, please let your Recruiter know when first connecting with them. Calendly is registered as an employer in many, but not all, states. If you are located in Alaska, Delaware, Hawaii, Idaho, Iowa, Montana, Nebraska, North Dakota, Rhode Island, South Dakota, and West Virginia, you will not be eligible for employment. Note that all individual roles will specify location eligibility.

All candidates can find our Candidate Privacy Statement here

Candidates residing in California may visit our Notice at Collection for California Candidates here: Notice at Collection

This role may require occasional travel for company events, team collaboration, or offsites.

Skills Required

  • 5+ years of experience in compliance, risk management, audit, or GRC roles within a technology or SaaS environment.
  • Experience owning or leading compliance programs supporting frameworks such as SOC 2 and ISO 27001.
  • Working knowledge of security and privacy frameworks including NIST, ISO 27001, GDPR, and HIPAA.
  • Experience administering compliance automation platforms such as Drata, Vanta, Tugboat Logic, or similar solutions.
  • Experience performing User Access Reviews (UARs) using GRC or compliance automation platforms.
  • Strong understanding of internal controls, risk assessment methodologies, and audit processes.
  • Demonstrated ability to manage multiple initiatives and deliver results in a fast-paced environment.
  • Excellent project management, analytical, and problem-solving skills.
  • Strong communication skills with the ability to translate technical and regulatory requirements into practical business solutions.
  • Proven ability to collaborate effectively with technical and non-technical stakeholders across the organization.
  • Experience leveraging AI to improve compliance processes or automate workflows.
  • Experience scaling compliance programs within a high-growth SaaS organization.
  • Hands-on experience developing or expanding a common controls framework.
  • Advanced expertise configuring compliance automation platforms, including integrations, custom controls, and reporting.
  • Familiarity with additional compliance frameworks such as PCI DSS or FedRAMP.
  • Experience developing compliance training, awareness programs, or self-service enablement resources.
  • Professional certifications such as CISA, CRISC, CISSP, CCSK, or equivalent.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Atlanta, GA
414 Employees
Year Founded: 2013

What We Do

At Calendly, we are excited about changing the way the world schedules. We are a profitable company, offering ample opportunities to accelerate your career. We’re obsessed with providing an elegant, delightful experience for our customers. This shapes how we develop, design, market and support. We work hard, move fast and pitch in across departments—and always make time to celebrate our accomplishments. Join a diverse workforce, leading the way in scheduling automation. Calendly, a powerful yet simple automated scheduling tool, takes the work out of connecting with others so you can accomplish more. Millions of users benefit from an enjoyable scheduling experience, more time to spend on top priorities and flexibility to accommodate individual users and large teams alike. Calendly works with Google, Office 365 and Outlook calendars and apps like Salesforce, Stripe, PayPal, Google Analytics, GoToMeeting and Zapier for a seamless user experience.

Similar Jobs

Remote
USA
198 Employees
83K-124K Annually

HealthPartners Logo HealthPartners

Compliance Analyst

Healthtech • Information Technology
In-Office or Remote
2 Locations
5537 Employees

Elevate Leadership Logo Elevate Leadership

Sales Development Representative

HR Tech • Professional Services • Sales • Consulting
Remote
United States
14 Employees

Zscaler Logo Zscaler

Sr. Production Engineer

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
San Jose, CA, USA
8697 Employees
118K-148K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account