TRM Labs is a blockchain intelligence company committed to fighting crime and creating a safer world. By leveraging blockchain data, threat intelligence, and advanced analytics, our products empower governments, financial institutions, and crypto businesses to combat illicit activity and global security threats. At TRM, you'll join a mission-driven, fast-paced team made up of experts in law enforcement, data science, engineering, and financial intelligence, tackling complex global challenges daily. Whether analyzing blockchain data, developing cutting-edge tools, or collaborating with global organizations, you'll have the opportunity to make a meaningful and lasting impact.
The Security Team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for a Senior Compliance Engineer to own TRM’s compliance and GRC initiatives that ensure we continue to deliver best-in-class security and trust for our customers.
The impact you will have here:
- Develop scalable and sustainable processes and tools for normalized controls, collecting audit evidence, monitoring controls, and conducting gap analyses.
- Manage TRM’s existing security compliance and certification lifecycle (e.g., SOC 2 Type II) while planning for and prioritizing future compliance needs.
- Develop a compliance program to achieve FedRAMP certification.
- Manage customer due diligence requests including developing and maintaining security collateral for customers (e.g., SIG, CAIQ).
- Conduct enterprise risk assessments and manage the risk registry.
- Develop a vendor risk management program.
- Identify areas for improvement based on input from customers, the go-to-market teams, and overall business objectives. Anticipate customer needs with respect to compliance and due diligence.
What we’re looking for:
- Develop automation to programmatically implement controls validations and evidence collections. Experience with Python or other programming and scripting languages is required.
- Work to align advanced technologies and Privacy by Design principles from the first stages of development and ensure that the data use meets established regulatory compliance needs.
- Strong understanding of Public Sector compliance security standards including NIST 800-53, SOC 2, CMMC, ISO, CyberEssentials UK, and other common compliance frameworks.
- Experience with leading a cloud-first SaaS company through the FedRAMP Moderate certification process.
- Strong focus on normalizing controls across frameworks and standards, with an eye toward improving maturity, scalability, and consistency over time, while looking beyond just “checking the box”.
- Privacy and GDPR experience is a plus.
- Security certifications (e.g., CISSP, CISM) are a plus.
About the Team
- The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.
- We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.
- Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.
- Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.
Time Zones:
- Eastern Standard Time (EST - GMT-4)
- Pacific Standard Time (PST - GMT-7)
- Central European Summer Time (CET - GMT+2)
Learn about TRM Speed in this position:
- Automate Repetitive Compliance Checks - Manually verifying compliance across systems or reviewing logs can be time-intensive. At TRM, we build custom integrations through scripts, SOAR platforms, or compliance management software (e.g. Drata) to automate routine tasks like generating compliance reports, tracking or collecting audit evidence, and monitoring control effectiveness.
- Build and leverage APIs for Cross-System Data Integration - Gathering compliance data from multiple systems can lead to delays and data silos. At TRM, we build and leverage automation and API's to pull real-time compliance data from critical systems into a centralized GRC tool or dashboard.
- Shift Left in Compliance - Detecting non-compliance late in a project lifecycle often requires rework and delays. At TRM, we embed compliance checks early in the development lifecycle. We integrate security and compliance standards directly into CI/CD pipelines to flag issues before they reach production.
Leadership Principles
Our LPs are foundational elements of our strategy, guiding how we make decisions, how we treat each other, and how we behave day-to-day.
- Impact-Oriented Trailblazer – We put customers first, driving for speed, focus, and adaptability.
- Master Craftsperson – We prioritize speed, high standards, and distributed ownership.
- Inspiring Colleague – We value humility, candor, and a one-team mindset.
Accelerate your Career
Join a mission-driven team of industry leaders and make a real-world impact—disrupting terrorist networks, recovering stolen funds, and more. At TRM, you will:
- Work alongside top experts and learn every day.
- Embrace a growth mindset with development opportunities tailored to your role.
- Take on high-impact challenges in a fast-paced, collaborative environment.
Thrive as a Global Team
As a remote-first company, TRM Labs is built for global collaboration.
- We cultivate a strong remote culture through clear communication, thorough documentation, and meaningful relationships.
- We invest in offsites, regional meetups, virtual coffee chats, and onboarding buddies to foster collaboration.
- By prioritizing trust and belonging, we harness the strengths of a global team while staying aligned with our mission and values.
Join our mission!
We’re looking for team members who thrive in fast-paced, high-impact environments and love building from the ground up. TRM is remote-first, with an exceptionally talented global team. If you enjoy solving tough problems and seeing your work make a difference for billions of people, we want you here. Don’t worry if your experience doesn’t perfectly match a job description— we value passion, problem-solving, and unique career paths. If you’re excited about TRM’s mission, we want to hear from you.
Recruitment agencies
TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.
Privacy Policy
By submitting your application, you are agreeing to allow TRM to process your personal information in accordance with the TRM Privacy Policy
Learn More: Company Values | Interviewing | FAQs
Top Skills
TRM Labs San Francisco, California, USA Office
450 Townsend St, San Francisco, CA, United States, 94107
Similar Jobs
What you need to know about the San Francisco Tech Scene
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine