The Crown Is Yours
As a Senior Technical Compliance Analyst, you'll strengthen our technical compliance programs and help teams stay ready for audits, certifications, and evolving regulatory requirements. You'll own key compliance domains from end to end, translating complex requirements into practical controls and scalable processes that support the business. Working across Engineering, Security, Legal, Compliance, Internal Audit, and other teams, you'll shape evidence strategies, validate controls, address risks, and provide clear guidance to stakeholders. Your work will also help advance our governance, risk, and compliance capabilities through stronger tooling, automation, and repeatable processes.
What You'll Do
- Own assigned technical compliance domains across frameworks such as Service Organization Control 2 (SOC 2), International Organization for Standardization (ISO) 27001, Payment Card Industry Data Security Standard (PCI DSS), Sarbanes-Oxley Information Technology General Controls (SOX ITGC), National Institute of Standards and Technology (NIST), and other relevant requirements.
- Lead audit and certification activities from planning through completion, coordinating timelines, deliverables, evidence collection, control validation, and responses across technical teams.
- Partner with Engineering, Security, Legal, Privacy, Internal Audit, and external auditors to assess control design and implementation, address audit questions, and resolve identified gaps.
- Translate regulatory, contractual, and certification requirements into practical technical controls, scalable workflows, and clear guidance for stakeholders.
- Build evidence strategies that improve the quality, completeness, reusability, and efficiency of audit and assessment processes.
- Identify compliance risks and control gaps, establish clear remediation ownership, track progress, and drive open issues through resolution.
- Develop program health metrics, audit status reporting, and leadership-ready insights that provide visibility into compliance performance and emerging risks.
- Advance our governance, risk, and compliance capabilities through improved tooling, automation, repeatable evidence-gathering processes, and post-audit improvements while sharing expertise and supporting consistent execution across the team.
What You'll Bring
- A Bachelor's Degree in Computer Science, Information Technology, or a related field, with at least 5 years of experience in technical compliance, information technology audit, security compliance, privacy compliance, risk management, or governance within a technology-driven or regulated environment.
- Working knowledge of compliance and security frameworks such as SOC 2, ISO 27001, PCI DSS, SOX ITGC, NIST, or similar standards.
- Experience leading or supporting audit readiness, evidence collection, control validation, remediation tracking, and external audits or certification activities.
- Technical fluency across areas such as access management, change management, vulnerability management, logging and monitoring, incident response, data protection, cloud infrastructure, and secure development.
- Experience assessing control design and implementation and translating compliance requirements into clear technical and operational expectations.
- Experience writing scripts, including Python, and using artificial intelligence tools to automate evidence collection, control testing, or compliance workflows is a plus.
- Strong stakeholder management and communication skills, with the ability to influence across teams and explain compliance requirements, risks, and remediation needs to technical and non-technical audiences.
- A continuous improvement mindset and strong attention to detail, with experience improving compliance processes, documentation, audit playbooks, evidence workflows, or control monitoring practices; relevant certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), or similar credentials are a plus.
Join Our Team
We're a publicly traded (NASDAQ: DKNG) technology company headquartered in Boston. As a regulated gaming company, you may be required to obtain a gaming license issued by the appropriate state agency as a condition of employment. Don't worry, we'll guide you through the process if this is relevant to your role.
The US base salary range for this full-time position is 111,200.00 USD - 139,000.00 USD, plus bonus, equity, and benefits as applicable. Our ranges are determined by role, level, and location. The compensation information displayed on each job posting reflects the range for new hire pay rates for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific pay range and how that was determined during the hiring process. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Skills Required
- Bachelor's degree in Computer Science, Information Technology, or a related field
- At least 5 years of experience in technical compliance, IT audit, security compliance, privacy compliance, risk management, or governance within a technology-driven or regulated environment
- Working knowledge of SOC 2, ISO 27001, PCI DSS, SOX ITGC, NIST, or similar compliance and security frameworks
- Experience leading or supporting audit readiness, evidence collection, control validation, remediation tracking, and external audits or certification activities
- Technical fluency in access management, change management, vulnerability management, logging and monitoring, incident response, data protection, cloud infrastructure, and secure development
- Experience assessing control design and implementation and translating compliance requirements into technical and operational expectations
- Strong stakeholder management and communication skills across technical and non-technical audiences
- Experience improving compliance processes, documentation, audit playbooks, evidence workflows, or control monitoring practices
- Python scripting and use of artificial intelligence tools for compliance automation
- CISA, CISSP, CRISC, CISM, or similar certification
What We Do
It's simple, at DraftKings, we believe life is more fun when you're in on the action. For that reason, we’re committed to responsibly creating the world’s favorite games and betting experiences. We’re developing the most innovative and entertaining real money products and offers; to forever transform how people experience sports; to be a fully vertically integrated sports betting operator. It's our ultimate goal to build the best, most trusted, and most customer-centric destination for our players. We’re defining what it means to build and deliver the most extraordinary sports and entertainment experiences. Our global team is trailblazing new markets, developing cutting-edge products, and shaping the future of responsible gaming.
Why Work With Us
Here, “impossible” isn’t part of our vocabulary. You’ll face some of the toughest but most rewarding challenges of your career. They’re worth it. Channeling your inner grit will accelerate your growth, help us win as a team, and create unforgettable moments for our customers. Ready to own what’s next?
Gallery
DraftKings Teams
DraftKings Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Our flexible hybrid policy empowers team members to work where they’re most productive—whether at home or in our collaborative offices. We trust our teams to choose what works best for them to thrive and innovate.

















