/jobs/4547011005?questions=true

Compliance Analyst, Cyber

Qohash is a cybersecurity provider, modernizing industry practices around the detection and protection of enterprise-sensitive information. Through our Qostodian platform, we introduce a groundbreaking approach to data security. As a leader in Data Security Posture Management (DSPM), we specialize in tracking specific data elements at scale. Our platform feeds real insights into our customers’ risk strategy, providing compliance, vulnerability reduction, and breach protection across some of the world’s largest and most sensitive enterprises.

object(stdClass)#4795 (18) { ["absolute_url"]=> string(55) "https://job-boards.greenhouse.io/qohash/jobs/4547011005" ["data_compliance"]=> array(1) { [0]=> object(stdClass)#4603 (6) { ["type"]=> string(4) "gdpr" ["requires_consent"]=> bool(false) ["requires_processing_consent"]=> bool(false) ["requires_retention_consent"]=> bool(false) ["retention_period"]=> NULL ["demographic_data_consent_applies"]=> bool(false) } } ["internal_job_id"]=> int(4363404005) ["location"]=> object(stdClass)#4361 (1) { ["name"]=> string(6) "Remote" } ["metadata"]=> NULL ["id"]=> int(4547011005) ["updated_at"]=> string(25) "2025-03-28T15:17:21-04:00" ["requisition_id"]=> string(2) "79" ["title"]=> string(25) "Compliance Analyst, Cyber" ["company_name"]=> string(6) "Qohash" ["first_published"]=> string(25) "2025-03-28T15:17:21-04:00" ["content"]=> string(5644) "<p><strong>Qohash</strong> is a cybersecurity provider, modernizing industry practices around the detection and protection of enterprise-sensitive information. Through our <strong>Qostodian</strong> platform, we introduce a groundbreaking approach to data security. As a leader in <strong>Data Security Posture Management (DSPM)</strong>, we specialize in tracking specific data elements at scale. Our platform feeds real insights into our customers’ risk strategy, providing compliance, vulnerability reduction, and breach protection across some of the world’s largest and most sensitive enterprises.</p> <h3><strong>Who you are</strong></h3> <p>The <strong>Compliance Analyst</strong> is a highly organized and proactive individual who thrives on enabling others to succeed by maintaining operational excellence. You have strong project management and documentation skills and enjoy working cross-functionally to drive consistent and repeatable compliance outcomes. You value clear communication and can translate regulatory requirements into actionable processes across technical and non-technical teams. In a fast-paced startup, you’re comfortable balancing independence with collaboration and are eager to shape the way compliance functions evolve at Qohash.</p> <h3><strong>What you will do</strong></h3> <p>As a <strong>Compliance Analyst</strong>, your responsibilities will be as follows:<br><br></p> <ul> <li>Act as the primary point of contact for operational compliance matters, providing consistent coordination across teams.</li> <li>Ensure compliance with security frameworks (e.g., SOC 2, ISO 27001) using compliance tools.</li> <li>Track and remediate security control gaps.</li> <li>Prepare for audits by collecting evidence and managing documentation.</li> <li>Manage documentation for security policies, compliance procedures, and access control.</li> <li>Coordinate compliance activities (e.g., access reviews, vendor risk assessments).</li> <li>Liaise between teams to align on compliance requirements.</li> <li>Maintain vendor compliance records and support assessments.</li> <li>Create dashboards to track compliance activities.</li> <li>Contribute to security awareness and training.</li> <li>Assist with data protection and privacy compliance.</li> <li>Identify automation opportunities.</li> <li>Act as primary contact for operational compliance matters.</li> </ul> <p><br><br></p> <h3><strong>What your resume shows</strong></h3> <p><strong>Must Haves</strong></p> <ul> <li>2–4 years of experience in information security compliance</li> <li>Familiarity with a security compliance framework (SOC 2, ISO 27001, etc.)</li> <li>Strong coordination, documentation, and process management skills</li> <li>One of the following certifications: GSEC, CCSP (Associate), Security+, ITIL Foundation, COBIT 5 Foundation</li> </ul> <p><strong>Nice to Haves</strong></p> <ul> <li>Experience with engineering or IT teams and understanding of cloud technologies, APIs, and software development</li> <li>Experience using compliance management tools (Drata, Vanta, SecureFrame)</li> <li>Startup experience and comfort in a fast-paced environment</li> <li>Preference for candidates based in Quebec</li> <li>Bilingual (English/French)</li> </ul> <h3><strong>Company culture &amp; core values</strong></h3> <p>At Qohash Inc., we believe in fostering a culture of <strong>innovation, integrity, and customer-centricity</strong>. Candidates are encouraged to familiarize themselves with our<a href="https://qohash.com/about-us/"> core values</a>.</p> <h3><strong>What’s in it for you?</strong></h3> <ul> <li>Competitive salary range.<br><br></li> <li>Enjoy up to <strong>six weeks of paid time off</strong> annually. At Qohash, we recognize your dedication and believe in giving you ample time to rejuvenate.<br><br></li> <li><strong>Comprehensive health benefits package</strong>, including life insurance, short- and long-term disability insurance, paramedical and telemedicine services, and a health spending account (HSA) and participation in our Employee Options plan.Competitive salary range.</li> <li>Up to six weeks of paid time off annually.</li> <li>Comprehensive health benefits package, including life insurance, short- and long-term disability insurance, paramedical and telemedicine services, and a health spending account (HSA).</li> <li>Participation in Employee Options plan.<br><br></li> </ul> <p><strong>Qohash</strong> is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by applicable law. Only those candidates selected for the interview will be contacted.</p>" ["departments"]=> array(1) { [0]=> object(stdClass)#4633 (4) { ["id"]=> int(4020853005) ["name"]=> string(24) "General & Administrative" ["child_ids"]=> array(2) { [0]=> int(4020724005) [1]=> int(4020723005) } ["parent_id"]=> NULL } } ["offices"]=> array(1) { [0]=> object(stdClass)#4595 (5) { ["id"]=> int(4009694005) ["name"]=> string(6) "Remote" ["location"]=> NULL ["child_ids"]=> array(7) { [0]=> int(4008836005) [1]=> int(4008838005) [2]=> int(4008837005) [3]=> int(4008833005) [4]=> int(4008832005) [5]=> int(4008835005) [6]=> int(4008834005) } ["parent_id"]=> NULL } } ["compliance"]=> NULL ["demographic_questions"]=> NULL ["questions"]=> array(12) { [0]=> object(stdClass)#4589 (4) { ["description"]=> NULL ["label"]=> string(10) "First Name" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4587 (3) { ["name"]=> string(10) "first_name" ["type"]=> string(10) "input_text" ["values"]=> array(0) { } } } } [1]=> object(stdClass)#4632 (4) { ["description"]=> NULL ["label"]=> string(9) "Last Name" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4586 (3) { ["name"]=> string(9) "last_name" ["type"]=> string(10) "input_text" ["values"]=> array(0) { } } } } [2]=> object(stdClass)#4597 (4) { ["description"]=> NULL ["label"]=> string(5) "Email" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4594 (3) { ["name"]=> string(5) "email" ["type"]=> string(10) "input_text" ["values"]=> array(0) { } } } } [3]=> object(stdClass)#4348 (4) { ["description"]=> NULL ["label"]=> string(5) "Phone" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4557 (3) { ["name"]=> string(5) "phone" ["type"]=> string(10) "input_text" ["values"]=> array(0) { } } } } [4]=> object(stdClass)#4591 (4) { ["description"]=> NULL ["label"]=> string(9) "Resume/CV" ["required"]=> bool(true) ["fields"]=> array(2) { [0]=> object(stdClass)#4592 (3) { ["name"]=> string(6) "resume" ["type"]=> string(10) "input_file" ["values"]=> array(0) { } } [1]=> object(stdClass)#4593 (3) { ["name"]=> string(11) "resume_text" ["type"]=> string(8) "textarea" ["values"]=> array(0) { } } } } [5]=> object(stdClass)#4575 (4) { ["description"]=> NULL ["label"]=> string(42) "What province or state are you located in?" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4574 (3) { ["name"]=> string(19) "question_7440399005" ["type"]=> string(25) "multi_value_single_select" ["values"]=> array(63) { [0]=> object(stdClass)#4573 (2) { ["label"]=> string(7) "Alberta" ["value"]=> int(16784794005) } [1]=> object(stdClass)#4572 (2) { ["label"]=> string(16) "British Columbia" ["value"]=> int(16784795005) } [2]=> object(stdClass)#4571 (2) { ["label"]=> string(8) "Manitoba" ["value"]=> int(16784796005) } [3]=> object(stdClass)#4570 (2) { ["label"]=> string(13) "New Brunswick" ["value"]=> int(16784797005) } [4]=> object(stdClass)#4569 (2) { ["label"]=> string(25) "Newfoundland and Labrador" ["value"]=> int(16784798005) } [5]=> object(stdClass)#4568 (2) { ["label"]=> string(11) "Nova Scotia" ["value"]=> int(16784799005) } [6]=> object(stdClass)#4567 (2) { ["label"]=> string(7) "Ontario" ["value"]=> int(16784800005) } [7]=> object(stdClass)#4566 (2) { ["label"]=> string(20) "Prince Edward Island" ["value"]=> int(16784801005) } [8]=> object(stdClass)#4565 (2) { ["label"]=> string(6) "Quebec" ["value"]=> int(16784802005) } [9]=> object(stdClass)#4564 (2) { ["label"]=> string(12) "Saskatchewan" ["value"]=> int(16784803005) } [10]=> object(stdClass)#4563 (2) { ["label"]=> string(21) "Northwest Territories" ["value"]=> int(16784804005) } [11]=> object(stdClass)#4789 (2) { ["label"]=> string(7) "Nunavut" ["value"]=> int(16784805005) } [12]=> object(stdClass)#4791 (2) { ["label"]=> string(5) "Yukon" ["value"]=> int(16784806005) } [13]=> object(stdClass)#4786 (2) { ["label"]=> string(7) "Alabama" ["value"]=> int(16784807005) } [14]=> object(stdClass)#4555 (2) { ["label"]=> string(6) "Alaska" ["value"]=> int(16784808005) } [15]=> object(stdClass)#4596 (2) { ["label"]=> string(7) "Arizona" ["value"]=> int(16784809005) } [16]=> object(stdClass)#4363 (2) { ["label"]=> string(8) "Arkansas" ["value"]=> int(16784810005) } [17]=> object(stdClass)#4804 (2) { ["label"]=> string(10) "California" ["value"]=> int(16784811005) } [18]=> object(stdClass)#4604 (2) { ["label"]=> string(8) "Colorado" ["value"]=> int(16784812005) } [19]=> object(stdClass)#4803 (2) { ["label"]=> string(11) "Connecticut" ["value"]=> int(16784813005) } [20]=> object(stdClass)#4802 (2) { ["label"]=> string(8) "Delaware" ["value"]=> int(16784814005) } [21]=> object(stdClass)#4801 (2) { ["label"]=> string(7) "Florida" ["value"]=> int(16784815005) } [22]=> object(stdClass)#4800 (2) { ["label"]=> string(7) "Georgia" ["value"]=> int(16784816005) } [23]=> object(stdClass)#4799 (2) { ["label"]=> string(6) "Hawaii" ["value"]=> int(16784817005) } [24]=> object(stdClass)#4798 (2) { ["label"]=> string(5) "Idaho" ["value"]=> int(16784818005) } [25]=> object(stdClass)#4797 (2) { ["label"]=> string(8) "Illinois" ["value"]=> int(16784819005) } [26]=> object(stdClass)#4796 (2) { ["label"]=> string(7) "Indiana" ["value"]=> int(16784820005) } [27]=> object(stdClass)#4790 (2) { ["label"]=> string(4) "Iowa" ["value"]=> int(16784821005) } [28]=> object(stdClass)#4805 (2) { ["label"]=> string(6) "Kansas" ["value"]=> int(16784822005) } [29]=> object(stdClass)#4806 (2) { ["label"]=> string(8) "Kentucky" ["value"]=> int(16784823005) } [30]=> object(stdClass)#4807 (2) { ["label"]=> string(9) "Louisiana" ["value"]=> int(16784824005) } [31]=> object(stdClass)#4808 (2) { ["label"]=> string(5) "Maine" ["value"]=> int(16784825005) } [32]=> object(stdClass)#4809 (2) { ["label"]=> string(8) "Maryland" ["value"]=> int(16784826005) } [33]=> object(stdClass)#4810 (2) { ["label"]=> string(13) "Massachusetts" ["value"]=> int(16784827005) } [34]=> object(stdClass)#4811 (2) { ["label"]=> string(8) "Michigan" ["value"]=> int(16784828005) } [35]=> object(stdClass)#4812 (2) { ["label"]=> string(9) "Minnesota" ["value"]=> int(16784829005) } [36]=> object(stdClass)#4813 (2) { ["label"]=> string(11) "Mississippi" ["value"]=> int(16784830005) } [37]=> object(stdClass)#4814 (2) { ["label"]=> string(8) "Missouri" ["value"]=> int(16784831005) } [38]=> object(stdClass)#4815 (2) { ["label"]=> string(7) "Montana" ["value"]=> int(16784832005) } [39]=> object(stdClass)#4816 (2) { ["label"]=> string(8) "Nebraska" ["value"]=> int(16784833005) } [40]=> object(stdClass)#4817 (2) { ["label"]=> string(6) "Nevada" ["value"]=> int(16784834005) } [41]=> object(stdClass)#4818 (2) { ["label"]=> string(13) "New Hampshire" ["value"]=> int(16784835005) } [42]=> object(stdClass)#4819 (2) { ["label"]=> string(10) "New Jersey" ["value"]=> int(16784836005) } [43]=> object(stdClass)#4820 (2) { ["label"]=> string(10) "New Mexico" ["value"]=> int(16784837005) } [44]=> object(stdClass)#4821 (2) { ["label"]=> string(8) "New York" ["value"]=> int(16784838005) } [45]=> object(stdClass)#4822 (2) { ["label"]=> string(14) "North Carolina" ["value"]=> int(16784839005) } [46]=> object(stdClass)#4823 (2) { ["label"]=> string(12) "North Dakota" ["value"]=> int(16784840005) } [47]=> object(stdClass)#4824 (2) { ["label"]=> string(4) "Ohio" ["value"]=> int(16784841005) } [48]=> object(stdClass)#4825 (2) { ["label"]=> string(8) "Oklahoma" ["value"]=> int(16784842005) } [49]=> object(stdClass)#4826 (2) { ["label"]=> string(6) "Oregon" ["value"]=> int(16784843005) } [50]=> object(stdClass)#4827 (2) { ["label"]=> string(12) "Pennsylvania" ["value"]=> int(16784844005) } [51]=> object(stdClass)#4828 (2) { ["label"]=> string(12) "Rhode Island" ["value"]=> int(16784845005) } [52]=> object(stdClass)#4829 (2) { ["label"]=> string(14) "South Carolina" ["value"]=> int(16784846005) } [53]=> object(stdClass)#4830 (2) { ["label"]=> string(12) "South Dakota" ["value"]=> int(16784847005) } [54]=> object(stdClass)#4831 (2) { ["label"]=> string(9) "Tennessee" ["value"]=> int(16784848005) } [55]=> object(stdClass)#4832 (2) { ["label"]=> string(5) "Texas" ["value"]=> int(16784849005) } [56]=> object(stdClass)#4833 (2) { ["label"]=> string(4) "Utah" ["value"]=> int(16784850005) } [57]=> object(stdClass)#4834 (2) { ["label"]=> string(7) "Vermont" ["value"]=> int(16784851005) } [58]=> object(stdClass)#4835 (2) { ["label"]=> string(8) "Virginia" ["value"]=> int(16784852005) } [59]=> object(stdClass)#4836 (2) { ["label"]=> string(10) "Washington" ["value"]=> int(16784853005) } [60]=> object(stdClass)#4837 (2) { ["label"]=> string(13) "West Virginia" ["value"]=> int(16784854005) } [61]=> object(stdClass)#4838 (2) { ["label"]=> string(9) "Wisconsin" ["value"]=> int(16784855005) } [62]=> object(stdClass)#4839 (2) { ["label"]=> string(7) "Wyoming" ["value"]=> int(16784856005) } } } } } [6]=> object(stdClass)#4840 (4) { ["description"]=> NULL ["label"]=> string(41) "Are you professionally fluent in English?" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4841 (3) { ["name"]=> string(19) "question_7440400005" ["type"]=> string(25) "multi_value_single_select" ["values"]=> array(2) { [0]=> object(stdClass)#4842 (2) { ["label"]=> string(3) "Yes" ["value"]=> int(1) } [1]=> object(stdClass)#4843 (2) { ["label"]=> string(2) "No" ["value"]=> int(0) } } } } } [7]=> object(stdClass)#4844 (4) { ["description"]=> NULL ["label"]=> string(99) "How many years of professional, hands-on experience do you have in Information Security Compliance?" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4845 (3) { ["name"]=> string(19) "question_7440401005" ["type"]=> string(25) "multi_value_single_select" ["values"]=> array(5) { [0]=> object(stdClass)#4846 (2) { ["label"]=> string(3) "1-2" ["value"]=> int(16784857005) } [1]=> object(stdClass)#4847 (2) { ["label"]=> string(3) "2-3" ["value"]=> int(16784858005) } [2]=> object(stdClass)#4848 (2) { ["label"]=> string(3) "3-4" ["value"]=> int(16784859005) } [3]=> object(stdClass)#4849 (2) { ["label"]=> string(3) "4-6" ["value"]=> int(16784860005) } [4]=> object(stdClass)#4850 (2) { ["label"]=> string(2) "6+" ["value"]=> int(16784861005) } } } } } [8]=> object(stdClass)#4851 (4) { ["description"]=> NULL ["label"]=> string(75) "Do you have professional working experience with either SOC 2 or ISO 27001?" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4852 (3) { ["name"]=> string(19) "question_7440402005" ["type"]=> string(25) "multi_value_single_select" ["values"]=> array(2) { [0]=> object(stdClass)#4853 (2) { ["label"]=> string(3) "Yes" ["value"]=> int(1) } [1]=> object(stdClass)#4854 (2) { ["label"]=> string(2) "No" ["value"]=> int(0) } } } } } [9]=> object(stdClass)#4855 (4) { ["description"]=> NULL ["label"]=> string(132) "Do you currently posses one of the following certifications: GSEC, CCSP (Associate), Security+, ITIL Foundation, COBIT 5 Foundation?" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4856 (3) { ["name"]=> string(19) "question_7441127005" ["type"]=> string(25) "multi_value_single_select" ["values"]=> array(2) { [0]=> object(stdClass)#4857 (2) { ["label"]=> string(3) "Yes" ["value"]=> int(1) } [1]=> object(stdClass)#4858 (2) { ["label"]=> string(2) "No" ["value"]=> int(0) } } } } } [10]=> object(stdClass)#4859 (4) { ["description"]=> NULL ["label"]=> string(40) "How did you hear about this opportunity?" ["required"]=> bool(true) ["fields"]=> array(1) { [0]=> object(stdClass)#4860 (3) { ["name"]=> string(19) "question_7440403005" ["type"]=> string(25) "multi_value_single_select" ["values"]=> array(4) { [0]=> object(stdClass)#4861 (2) { ["label"]=> string(8) "LinkedIn" ["value"]=> int(16784867005) } [1]=> object(stdClass)#4862 (2) { ["label"]=> string(12) "ZipRecruiter" ["value"]=> int(16784868005) } [2]=> object(stdClass)#4863 (2) { ["label"]=> string(6) "Indeed" ["value"]=> int(16784869005) } [3]=> object(stdClass)#4864 (2) { ["label"]=> string(5) "Other" ["value"]=> int(16784870005) } } } } } [11]=> object(stdClass)#4865 (4) { ["description"]=> NULL ["label"]=> string(73) "If referred by a Qohash employee, please enter their first and last name:" ["required"]=> bool(false) ["fields"]=> array(1) { [0]=> object(stdClass)#4866 (3) { ["name"]=> string(19) "question_7440404005" ["type"]=> string(10) "input_text" ["values"]=> array(0) { } } } } } ["location_questions"]=> array(0) { } }

Who you are

The Compliance Analyst is a highly organized and proactive individual who thrives on enabling others to succeed by maintaining operational excellence. You have strong project management and documentation skills and enjoy working cross-functionally to drive consistent and repeatable compliance outcomes. You value clear communication and can translate regulatory requirements into actionable processes across technical and non-technical teams. In a fast-paced startup, you’re comfortable balancing independence with collaboration and are eager to shape the way compliance functions evolve at Qohash.

What you will do

As a Compliance Analyst, your responsibilities will be as follows:

  • Act as the primary point of contact for operational compliance matters, providing consistent coordination across teams.
  • Ensure compliance with security frameworks (e.g., SOC 2, ISO 27001) using compliance tools.
  • Track and remediate security control gaps.
  • Prepare for audits by collecting evidence and managing documentation.
  • Manage documentation for security policies, compliance procedures, and access control.
  • Coordinate compliance activities (e.g., access reviews, vendor risk assessments).
  • Liaise between teams to align on compliance requirements.
  • Maintain vendor compliance records and support assessments.
  • Create dashboards to track compliance activities.
  • Contribute to security awareness and training.
  • Assist with data protection and privacy compliance.
  • Identify automation opportunities.
  • Act as primary contact for operational compliance matters.



What your resume shows

Must Haves

  • 2–4 years of experience in information security compliance
  • Familiarity with a security compliance framework (SOC 2, ISO 27001, etc.)
  • Strong coordination, documentation, and process management skills
  • One of the following certifications: GSEC, CCSP (Associate), Security+, ITIL Foundation, COBIT 5 Foundation

Nice to Haves

  • Experience with engineering or IT teams and understanding of cloud technologies, APIs, and software development
  • Experience using compliance management tools (Drata, Vanta, SecureFrame)
  • Startup experience and comfort in a fast-paced environment
  • Preference for candidates based in Quebec
  • Bilingual (English/French)

Company culture &amp; core values

At Qohash Inc., we believe in fostering a culture of innovation, integrity, and customer-centricity. Candidates are encouraged to familiarize themselves with our core values.

What’s in it for you?

  • Competitive salary range.

  • Enjoy up to six weeks of paid time off annually. At Qohash, we recognize your dedication and believe in giving you ample time to rejuvenate.

  • Comprehensive health benefits package, including life insurance, short- and long-term disability insurance, paramedical and telemedicine services, and a health spending account (HSA) and participation in our Employee Options plan.Competitive salary range.
  • Up to six weeks of paid time off annually.
  • Comprehensive health benefits package, including life insurance, short- and long-term disability insurance, paramedical and telemedicine services, and a health spending account (HSA).
  • Participation in Employee Options plan.

Qohash is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by applicable law. Only those candidates selected for the interview will be contacted.