Senior Security Compliance Analyst
Listed on 2026-02-19
-
IT/Tech
Cybersecurity, Information Security
Position Title:
Senior Security Compliance Analyst
Department: R&D Development Team
Location:
Alpharetta, GA (Hybrid 3 days in office)
Reports to:
Chief Information Security Officer
The Senior Security Compliance Analyst is a highly experienced individual contributor responsible for supporting and advancing Kahua’s enterprise security compliance and risk initiatives. Reporting directly to the Chief Information Security Officer, this role plays a critical part in ensuring the company’s adherence to complex regulatory and customer requirements across frameworks such as FedRAMP, SOC 2 Type 2, ISO 27001, and other certifications or authorizations as needed.
This individual will work closely with the Manager of Risk and Compliance to coordinate cross-functional compliance initiatives, ensure audit readiness, and assist with control implementation efforts. In addition to compliance program expertise, the ideal candidate brings architectural-level security insight, demonstrating a solid understanding of how controls apply across interconnected systems, applications, networking components, endpoints, and cloud services.
This role requires strong technical acumen to quickly gain a deep understanding of Kahua’s infrastructure, platforms, and security posture in order to support audits and respond effectively to customer security assessments. It is a high-impact role for a security professional who thrives in a fast-paced, high-growth SaaS environment and can balance tactical execution with long-term strategic thinking.
U.S. Citizenship is required for this position, and the candidate must be able to pass an initial employment and government background check to support HSPD-12 clearance eligibility.
Key Responsibilities- Drive and support ongoing security compliance activities across multiple frameworks, including FedRAMP, SOC 2 Type 2, ISO 27001, and additional certifications or attestations as required.
- Manage audit preparedness, evidence collection, documentation accuracy, and control lifecycle activities across internal teams.
- Translate regulatory and contractual requirements into technically sound, operationally feasible controls in coordination with technical stakeholders.
- Work closely with Engineering, Dev Ops, IT, and Product teams to evaluate, enhance, and validate the technical implementation of security controls in platforms such as Microsoft 365, Entra , and Microsoft Defender.
- Collaborate with the Manager of Risk and Compliance to track third-party risk management activities, coordinate internal risk assessments, and maintain continuous compliance operations.
- Serve as a key resource in responding to customer security assessments and questionnaires, demonstrating deep understanding of Kahua’s infrastructure, control implementations, and technical security posture.
- Analyze existing system architecture and operational processes to recommend improvements in security control design and implementation.
- Assist in maintaining and improving Kahua’s Information Security Management System (ISMS), policy governance process, and risk register.
- Support monthly compliance meetings, track program-level metrics, and contribute to long-term compliance strategy planning and reporting.
- Bachelor’s degree in Information Security, Information Systems, Computer Science, or a related field (or equivalent practical experience).
- 5+ years of experience in information security, risk management, or compliance roles, with direct responsibility for one or more major security frameworks (e.g., FedRAMP, SOC 2, ISO 27001, NIST 800-53).
- Strong working knowledge of Microsoft cloud and enterprise technologies, including Microsoft 365, Entra , Teams, and Microsoft Defender.
- Demonstrated ability to assess, design, and validate security controls in technical environments aligned to compliance frameworks.
- Experience supporting compliance program operations in a SaaS or regulated cloud environment.
- Security-related certifications preferred (e.g., CISSP, CISA, CISM, CCSP, or ISO Lead Auditor/Implementer).
- Exceptional written and verbal communication skills;…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).