Senior Technical Compliance Analyst
As a Senior Technical Compliance Analyst, the individual will strengthen technical compliance programmes and help teams prepare for audits, certifications, and evolving regulatory requirements. The role involves owning key compliance domains from end to end, translating complex requirements into practical controls, and developing scalable processes that support the business.
Working across Engineering, Security, Legal, Compliance, and Internal Audit teams, the analyst will shape evidence strategies, validate controls, address risks, and provide clear guidance to stakeholders. The position also focuses on advancing governance, risk, and compliance capabilities through improved tooling, automation, and repeatable processes.
- Own assigned technical compliance domains across frameworks such as Service Organization Control 2 (SOC 2), International Organization for Standardization (ISO) 27001, Payment Card Industry Data Security Standard (PCI DSS), Sarbanes-Oxley Information Technology General Controls (SOX ITGC), National Institute of Standards and Technology (NIST), and other relevant requirements.
- Lead audit and certification activities from planning through completion, coordinating timelines, deliverables, evidence collection, control validation, and responses across technical teams.
- Partner with Engineering, Security, Legal, Privacy, Internal Audit, and external auditors to assess control design and implementation, address audit questions, and resolve identified gaps.
- Translate regulatory, contractual, and certification requirements into practical technical controls, scalable workflows, and clear guidance for stakeholders.
- Build evidence strategies that improve the quality, completeness, reusability, and efficiency of audit and assessment processes.
- Identify compliance risks and control gaps, establish clear remediation ownership, track progress, and drive open issues through resolution.
- Develop program health metrics, audit status reporting, and leadership-ready insights that provide visibility into compliance performance and emerging risks.
- Advance governance, risk, and compliance capabilities through improved tooling, automation, repeatable evidence-gathering processes, and post-audit improvements.
- A Bachelor’s Degree in Computer Science, Information Technology, or a related field (required).
- At least 5 years of experience in technical compliance, information technology audit, security compliance, privacy compliance, risk management, or governance within a technology-driven or regulated environment (required).
- Working knowledge of compliance and security frameworks such as SOC 2, ISO 27001, PCI DSS, SOX ITGC, NIST, or similar standards (required).
- Experience leading or supporting audit readiness, evidence collection, control validation, remediation tracking, and external audits or certification activities (required).
- Technical fluency across areas such as access management, change management, vulnerability management, logging and monitoring, incident response, data protection, cloud infrastructure, and secure development (required).
- Experience assessing control design and implementation and translating compliance requirements into clear technical and operational expectations (required).
- Experience writing scripts, including Python, and using artificial intelligence tools to automate evidence collection, control testing, or compliance workflows (nice-to-have).
- Strong stakeholder management and communication skills, with the ability to influence across teams and explain compliance requirements, risks, and remediation needs to technical and non-technical audiences (required).
- A continuous improvement mindset and strong attention to detail, with experience improving compliance processes, documentation, audit playbooks, evidence workflows, or control monitoring practices (required).
- Relevant certifications such as Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM), or similar credentials are a plus (nice-to-have).
- Comprehensive health benefits including various medical plans, dental, and vision.
- Wellbeing programme including free therapy sessions with Lyra Mental Health Solution, Lyra Employee Assistance Program, the Calm App, Virtual Yoga Classes, and many more.
- 14 weeks of 100% paid parental leave to all global team members and offer workplace lactation support.
- Partner with Care.com, a care finder and backup childcare partner for US employees.
- Family planning benefits including support for adoption, surrogacy, fertility treatments, or other family planning.
- Flexible PTO for US-based employees.
- Pet insurance.
- Gym reimbursement.
- Financial planning support including 401(k) matching and programs such as Origin Financial.
- Commuter benefits.
- Tuition reimbursement programme.
DraftKings Inc. is a leading American digital sports entertainment and gaming company, headquartered in Boston, Massachusetts. Founded in 2012, it started in daily fantasy sports and has grown into one of the largest US online sportsbook and iGaming operators. The company offers mobile sports betting, online casino and daily fantasy contests across regulated North American markets. DraftKings is listed on the Nasdaq stock exchange and employs several thousand people.