🏢
Calendly
Senior Compliance and Risk Analyst
Job Description
ABOUT THE ROLE
We're seeking a highly skilled Senior Compliance and Risk Analyst to join Calendly's Compliance and Risk team. As a strategic partner to the business, this role will enable growth while maintaining customer trust. You will own and mature our compliance program, ensuring we maintain certifications such as SOC 2 and ISO 27001, and build scalable, automated processes to support our rapidly growing SaaS business.
WHAT YOU'LL DO
As a Senior Compliance and Risk Analyst, your day-to-day responsibilities will include:
- Owning and managing the organization's compliance program, including SOC 2 and ISO 27001 readiness, certification, and ongoing maintenance.
- Developing and executing a compliance roadmap aligned with business objectives, regulatory requirements, and organizational risk appetite.
- Leading internal and external audits by coordinating evidence collection, managing auditor relationships, and driving timely remediation of findings.
- Monitoring changes in regulatory and industry frameworks, assessing their impact on the organization's compliance program.
- Owning the enterprise risk management process, including risk identification, assessment, treatment planning, and ongoing monitoring.
- Conducting periodic risk assessments and partnering with stakeholders to identify control gaps and prioritize remediation activities.
- Developing and presenting compliance metrics, risk dashboards, and executive reports for senior leadership.
- Designing, documenting, and improving internal controls aligned with SOC 2, ISO 27001, and other applicable frameworks.
- Leading control testing, including evidence collection, effectiveness validation, remediation tracking, and continuous improvement.
- Expanding and maturing the organization's common controls framework to support evolving compliance requirements.
- Administering and optimizing compliance automation platforms, improving workflow efficiency and reducing manual effort.
- Performing User Access Reviews (UARs) and supporting continuous compliance monitoring through automation and reporting.
- Partnering with Engineering, Security, Product, Legal, HR, and Operations to integrate compliance into business processes and product development.
- Developing training, playbooks, and self-service resources that empower teams to meet compliance requirements efficiently.
- Managing multiple compliance initiatives simultaneously while ensuring projects remain on schedule and stakeholders stay informed.
WHAT YOU'LL NEED
To be successful in this role, you will need:
- 5+ years of experience in compliance, risk management, audit, or Governance, Risk, and Compliance (GRC) roles within a technology or SaaS environment.
- Experience owning or leading compliance programs supporting frameworks such as SOC 2 and ISO 27001.
- Working knowledge of security and privacy frameworks including NIST, ISO 27001, GDPR, and HIPAA.
- Experience administering compliance automation platforms such as Drata, Vanta, Tugboat Logic, or similar solutions.
- Experience performing User Access Reviews (UARs) using GRC or compliance automation platforms.
- Strong understanding of internal controls, risk assessment methodologies, and audit processes.
- Demonstrated ability to manage multiple initiatives and deliver results in a fast-paced environment.
- Excellent project management, analytical, and problem-solving skills.
- Strong communication skills with the ability to translate technical and regulatory requirements into practical business solutions.
- Proven ability to collaborate effectively with technical and non-technical stakeholders across the organization.
WHY REMOTE
As a remote employee, you will have