Who we are
At Twilio, we’re shaping the future of communications. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.
We believe in remote‑first work and a strong culture of connection and global inclusion. No matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day.
See yourself at TwilioJoin the team as Twilio’s next Security Compliance & Regulatory Affairs Analyst
About the jobWe are actively recruiting for this role to support Twilio’s global security regulatory program and to directly support the SCRA Lead in executing and scaling the company’s regulatory strategy.
This position is responsible for independently owning delegated components of regulatory analysis, triage, normalization, and operationalization of global cybersecurity and telecom regulatory obligations (e.g., NIS 2, TSA UK, Singapore IMDA), while contributing to broader program‑level initiatives led by the SCRA Lead.
The role operates with high autonomy and is expected to take ownership of assigned work streams end‑to‑end, requiring strong critical thinking, defensible regulatory interpretation, designing and executing cross‑functional initiatives, and the ability to operate without detailed instruction.
Responsibilities- Support the SCRA Lead in executing Twilio’s global security regulatory strategy, including program design, prioritization, and long‑term regulatory planning.
- Independently interpret complex and ambiguous regulatory frameworks and provide structured outputs that support lead‑level strategy and decision‑making.
- Support the development and maintenance of regulatory repositories and systems of record, ensuring accuracy, traceability, and audit readiness.
- Execute and continuously improve the Cyber Regulation Intake & Triage process in partnership with Legal, ensuring consistent classification, routing, and lifecycle tracking of regulatory obligations.
- Map regulatory requirements to internal control frameworks (e.g., UCF, ISO 27001, internal standards), identifying gaps and supporting lead‑driven control strategy decisions.
- Develop regulator‑ready and high‑quality artifacts, including evidence mappings, control narratives, risk statements, and audit support documentation.
- Identify, analyze, and elevate regulatory risks and audit obligations, supporting proactive planning and risk visibility at the program level.
- Partner cross‑functionally with Legal, Public Policy, R&D, Security, Product, Sales, and Risk teams, aligning regulatory interpretation with technical and business implementation.
- Drive execution of process improvements, tooling enhancements, and automation initiatives defined by the SCRA program.
- Operate with high ownership and accountability, executing work independently while aligning to strategic direction set by the SCRA Lead.
- Experience: 5–8+ years of experience in security compliance, telecom compliance, regulatory affairs, GRC, or related domain within a global technology, cloud, or telecom environment.
- Experience: Interpreting and operationalizing security frameworks and regulations (e.g., NIS 2, ISO 27001, SOC 2, telecom regulatory regimes).
- Experience: Mapping regulatory requirements to control frameworks, policies, and technical implementations.
- Technical Domain Expertise: Broad understanding of security architecture, networking, access control, software development, cryptography, and operations; fluency in how security controls are implemented across applications, systems, and cloud platforms.
- Technical Domain Expertise: Ability to analyze ambiguous regulations and produce defensible interpretations.
- Communication: Strong written communication skills with ability to produce audit‑ready and regulator‑defensible documentation.
- Stakeholder Partnership: Proven ability to collaborate across Legal, Engineering, Security, Product, Sales, and Risk teams.
- Strategic Mindset: High level of self‑sufficiency, critical thinking, and ownership, with ability to execute without detailed instruction.
- Adaptability: Demonstrated ability to independently…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: