
Cybersecurity Compliance Analyst (Hybrid - Bay Area)
Automate your job search with Sonara.
Submit 10x as many applications with less effort than one manual application.1
Reclaim your time by letting our AI handle the grunt work of job searching.
We continuously scan millions of openings to find your top matches.

Overview
Schedule
Full-time
Career level
Senior-level
Remote
Hybrid remote
Compensation
$100,000-$120,000/year
Benefits
Health Insurance
Dental Insurance
Vision Insurance
Job Description
If you’re looking to join a winning information technology team and receive outstanding benefits that support your family—while working for a company that takes a people-first approach to business—we invite you to explore our Cybersecurity Compliance Analyst position.Location: San Francisco Bay AreaHybrid: 2 days in office / 3 days remote per weekPrimary Purpose and FunctionXantrion is seeking a Cybersecurity Compliance Analyst to support our Compliance Service offering and internal compliance programs. You will help assess client security controls, develop practical compliance documentation, evaluate vendor cybersecurity risk, and organize evidence that supports client requirements.This role combines technical IT knowledge with strong analytical and writing skills to support our Client Strategy team across a diverse client base. The team leads client assessments, executive discussions, and remediation planning, while you provide supporting analysis and produce accurate, well-organized deliverables using established templates, standards, and guidance.Travel: None required.Roles and ResponsibilitiesClient Compliance and Documentation
- Support current-state and target-state cybersecurity assessments using NIST Cybersecurity Framework (CSF), CIS Controls, and Xantrion standards.
- Review IT configurations and supporting evidence against established templates and control requirements; document gaps and findings for virtual Chief Information Officer (vCIO) review.
- Draft and maintain incident response plans (IRPs), business continuity plans (BCPs), written information security programs (WISPs), and supporting security policies and procedures.
- Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records.
- Prepare control crosswalks, prioritized remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction.
- Conduct vendor cybersecurity risk reviews by evaluating questionnaires, audit reports, security documentation, and supporting evidence.
- Maintain software and vendor inventories, data inventories, data flow documentation, and evidence indexes.
- Maintain annual testing schedules and track documentation, review dates, and follow-up items.
- Translate technical findings into clear descriptions of risk, supporting evidence, and recommended actions.
- Improve reusable templates and assessment procedures that support consistent delivery across clients.
- Coordinate evidence collection and auditor requests for Xantrion’s annual SOC 2 Type II examination and ISO/IEC 27001 audit activities.
- Organize audit documentation, maintain request trackers, and follow up with internal control owners.
- Review evidence for completeness and consistency and identify missing or outdated documentation.
- Provide seasonal support during internal audit preparation and review periods.
- Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance, including at least one year supporting control assessments, audit evidence collection, or security documentation.
- Practical understanding of business IT environments, including identity and access management, endpoint security, email security, backups, networking, and cloud services.
- Experience reviewing technical configurations or administrative reports against documented standards.
- Working knowledge of NIST CSF and CIS Controls, with familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts.
- Strong writing skills and the ability to produce clear, accurate policies, procedures, assessment findings, and client documentation.
- Ability to distinguish documented policies from evidence that controls are implemented and operating.
- Strong organization, attention to detail, and the ability to manage deliverables across multiple clients.
- Ability to work independently on assigned tasks, identify questions or evidence gaps, and incorporate vCIO feedback.
- Professional communication skills and sound judgment when handling confidential client information.
- Experience supporting registered investment advisers (RIAs) or other financial services organizations.
- Familiarity with cybersecurity and information protection requirements relevant to financial services, including SEC Regulation S-P, the FTC Safeguards Rule under GLBA, and applicable FINRA requirements.
- Experience working for a managed service provider or supporting multiple client environments.
- Hands-on familiarity with Microsoft 365, Entra ID, Intune, and common endpoint and security management tools.
- Experience conducting vendor cybersecurity reviews and evaluating SOC 2 reports.
- Experience supporting SOC 2 Type II examinations or ISO/IEC 27001 audits.
- Familiarity with additional requirements and programs such as HIPAA, CJIS, NIST SP 800-171, CMMC, or FedRAMP.
- Relevant certifications, such as Security+, CGRC, CISA, or an ISO/IEC 27001 credential.
- A relevant degree or certification is welcome but is not required. Equivalent practical experience will be considered.
- Client deliverables are accurate, clearly written, tailored to the client, and completed on schedule.
- Assessment findings are supported by evidence and clearly describe gaps for vCIO review.
- Risk registers, crosswalks, and supporting documentation remain organized and current.
- Internal audit requests are tracked and supported with complete, accessible evidence.
- Templates and processes improve the consistency and efficiency of Xantrion’s compliance services.
- Sitting or Standing for Long Periods: Ability to remain seated or standing at a workstation for extended durations, with regular breaks to prevent fatigue.
- Viewing a Computer Monitor: Sustained ability to focus on a computer screen for tasks such as reading, typing, and data entry, with appropriate lighting and screen settings to reduce eye strain.
- Digital Dexterity and Hand/Eye Coordination: Proficient use of hands and fingers to operate office equipment, including frequent alpha/numeric keyboarding, mouse usage, and handling other peripherals.
- Oral Communications: Engaging in clear and effective verbal communication over the phone, video calls, and occasionally in person, requiring strong speech and active listening skills.
- Use of Peripheral Devices: Handling and operating devices such as a mouse, headset, and other computer accessories with precision.
- Basic Ergonomic Adjustments: Ability to adjust seating, monitor height, and other workstation elements to maintain comfort and reduce physical strain.
- Environmental Awareness: Maintaining a workspace free from excessive noise and distractions to ensure focus and productivity.
- Occasional Lifting and Moving: Ability to lift and move light objects, such as laptops, documents, and office supplies, as needed.
- Periodic Travel to Xantrion’s Office: Willingness and ability to travel to Xantrion's office or shared workspace as needed, which may involve air travel, driving, ride-sharing, or using public transportation.
- Follow and support company policies and procedures as well as all local, state, and federal laws.
- Always maintain confidentiality of company and customer records and information.
- Maintain a professional image, adhering to Xantrion’s dress code.
- Must have an existing cell phone (running current Android or iOS).
- If applicable Xantrion will provide a cell phone, internet connection, and home office equipment allowance. See the Xantrion Handbook for details.
- Must have a reliable, high-speed internet connection that effectively supports work responsibilities, including video conferencing.
- Must have a dedicated, secure, and private workspace. Unless arranged by Xantrion, shared work environments, such as coworking spaces, are unacceptable. Client information must always be kept private.
- Must use Xantrion-provided PC and headset to execute job functions.
- Salary range $100-120K; depending on experience.
- 100% of medical, dental, and vision for you and your family.
- 401K with company match up to 4% of salary.
- Certification reimbursement and annual training budget.
- 17 Days PTO per year in addition to paid training days.
- Bonuses for referring new clients or employees.
Powered by JazzHR
Automate your job search with Sonara.
Submit 10x as many applications with less effort than one manual application.

FAQs About Cybersecurity Compliance Analyst (Hybrid - Bay Area) Jobs at Xantrion
What is the work location for this position at Xantrion?
This job at Xantrion is located in Lafayette, CA, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Xantrion?
Candidates can expect a pay range of $100,000 and $120,000 per year.
What employment applies to this position at Xantrion?
Xantrion lists this role as a Full-time position.
What experience level is required for this role at Xantrion?
Xantrion is looking for a candidate with "Senior-level" experience level.
What benefits are offered by Xantrion for this role?
Xantrion offers following benefits: Health Insurance, Dental Insurance, Vision Insurance, Family/Dependent Health, Paid Vacation, Career Development, 401k Matching/Retirement Savings, Tuition/Education Assistance, and Health & Wellness Programs for this position. Actual benefits may vary depending on the employer's policies and employment terms.
What is the process to apply for this position at Xantrion?
You can apply for this role at Xantrion either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.