Trust Analyst
About the Role
About the Role Abnormal AI is looking for a Trust Analyst II to join the Compliance Trust team within Abnormal’s Trust organization. The Trust organization is made up of the Compliance Trust and Customer Trust teams. This role sits on the Compliance Trust team, which owns the company’s GRC (Governance, Risk, and Compliance) programs. The Compliance Trust team drives internal and external audit readiness, manages enterprise and third-party risk, and leads governance across information security, AI, and data to deliver a foundation to maintain company's information security, privacy, and AI compliance certifications... This role owns Abnormal's governance and policy program, chairing and running the company's governance committees, including AI Governance, Data Governance, Security Governance, and other governance programs as they are implemented. Additionally this role will hold end-to-end ownership of policy management, from drafting through stakeholder acknowledgment and management of the company’s Policy Center. Governance and policy ownership make up the majority of this role's scope. The remainder of the role will be a key stakeholder in risk management operations, including managing the risk register, performing risk assessments, and risk exception administration. Lastly, this role will also include general compliance support such as audit readiness, control evaluation, and issue remediation. The ideal candidate will have the mindset of an auditor with keen attention to detail, possess exceptional skills in project management, be a good communicator who excels at explaining complex technology to diverse audiences in a way that fosters understanding and ownership, has strong collaboration and business sense, and an adept awareness of our customers' requirements of Abnormal as a leading cybersecurity SaaS provider. Who You Are Proven security experience in an audit or advisory capacity Analytical thinker who exercises good business judgment and resolves ambiguous or judgment call questions without direction Resolves multi-framework or complex audit questions where the path isn't obvious, and designs an approach when standard procedure falls short and brings a recommendation to the table, not just a problem, and knows when to loop in Legal or Security to get it right Confidence and willingness to ask questions, raise issues, and concerns in a timely manner Comfortable owning and running cross-functional governance committees (e.g., AI Governance, Data Governance, Security Governance), setting agendas, driving decisions, and following through on action items without needing to be chased Experienced managing a policy program end to end. Authoring, revising, and defending policy positions to stakeholders, not just administering logistics High attention to detail, process, and organization with strong project management skills to ensure accountability and results Acts as a trusted partner to other Abnormal teams and external auditors on their domain, leading structured discussions grounded in evidence rather than assumption, and represents the function credibly in auditor-facing settings Comfortable interpreting requirements in business context rather than taking a control requirement at face value, and anticipating how upstream changes affect compliance posture Ability to adapt to change, including evolving business and technical environments, and manage multiple priorities while meeting deadlines in a fast-paced environment Team player, collaborative work style Self-motivated and able to work efficiently with minimal oversight/direction Owns outcomes rather than activity — accountable for a compliance domain end to end, including audit outcomes and remediation tracking What You Will Do Own and run Abnormal's governance committees including AI Governance, Data Governance, Security Governance, and any additional governance programs the business needs. Running these committees will include setting agendas, facilitating cross-functional stakeholders, and driving decisions to closure. Hold end-to-end ownership of the policy program, including drafting, revising, and maintaining policies across governance domains, and driving stakeholder review and acknowledgment. Manage the company’s Policy Center which hosts all enterprise policies.Own risk management operations, including the risk register, risk assessments, and administration of risk exceptions, including enforcing the 12-month exception cap with mandatory renewal review and required documentation. Keep abreast of regulatory and industry developments and advise leadership on the potential impact on the program strategy and plans. Ensure program activities align with strategy and manage the timely and high-quality execution of GRC landmarks. Drive internal control effectiveness through rigorous internal control monitoring, implementing control enhancements, and providing thought leadership on control design, operations, and supporting processes and policies. Perform compliance readiness assessments and provide updates, recommendations, and roadmap to senior management both within Security and to our business partners. Advise, educate, and train process and control owners with the preparation and ongoing maintenance of controls and control documentation (e.g., policies, procedures, narratives, and matrices) to better understand the security controls framework and their responsibilities. Recommend, develop, and manage the company's risk register, including the definition and reporting on key risk indicators (KRIs) and key performance indicators (KPIs). Conduct regular risk assessments and work with relevant departments to identify, evaluate, and mitigate risks across the organization. Advise, educate, and train risk owners with the identification, assessment, mitigation, and monitoring of risks to better understand the risk management process and their responsibilities. Proactively identify gaps or conflicts in existing policies and processes and work to develop solutions with internal business partners. Drive remediation and risk mitigation activities, including root cause analysis and owning the design, tracking, and progress of action plans across compliance, policy, or process gap remediation activities and risk mitigation activities in partnership with internal business partners. Tracks risk trends across cycles and flags recurring patterns before they become repeat findings. Design and manage program operations to support the program goals and implement and maintain technology to support the program and its operations. Engage in ad-hoc projects as required. Maintain regular, clear communication with project teams, key partners, and management regarding the status of controls testing, audit progress, risk assessment progress, and progress of issues management. Effectively communicate program and project execution status, program health and effectiveness, key accomplishments, and risks to senior management both within Security and to our business partners. Must Haves 4-7 years of experience in cyber security, technology risk, GRC, and/or technical compliance roles, with at least 2 years focused on ISO 27001 implementation and maintenance Demonstrated experience leading at least one full ISO 27001 certification cycle (including the 2022 revision of ISO 27001) from start to finish Proven project management experience, including: managing multiple concurrent compliance projects with competing deadlines; leading cross-functional teams across technical and business units; experience with project management methodologies (Agile, Waterfall) and tools (ServiceNow, etc.); and a track record of delivering complex compliance projects on time and within scope Experience owning or facilitating cross-functional governance programs or committees (e.g., AI governance, data governance, security governance), including running working groups and driving decisions with senior stakeholders Strong understanding of security concepts and practical usage, including Information Security Management System (ISMS) implementation and maintenance, control mapping across multiple frameworks, and continuous control monitoring and automation Experience implementing and managing compliance programs aligned with ISO 27001 and ISO 27701, including development and maintenance of Statement of Applicability, risk treatment plans and risk acceptance criteria, internal audit programs, and management review processes Proven track record working with external auditors, including internal stakeholder management Experience with audit automation and continuous control monitoring tools Proven ability to manage multiple stakeholders and vendors while maintaining project momentum Nice to Have Bachelor's degree or equivalent military experience ISO 27001, 27701, or 42001 Lead Auditor Certification CRISC, CISSP, CPA, CISA, PMP, CISM certification(s) Experience with NIST CSF, NIST SP 800-53 / 171 or other control frameworks Familiarity with AI governance frameworks (e.g., ISO/IEC 42001, NIST AI RMF) Experience preferably at a technology or SaaS / Cloud company and/or with a regulated public company 2+ years of Big 4 experience #LI-ML1Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.Base salary range:$114,800—$165,000 USDA note on AI in our process: Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards. Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.