405,710open jobs
14,091companies
78,515added this week
Browse all
Salary
$57k – $65k per year
Location
In office
Employment
Full-Time
Overview
Company
Impact
Profile match
BIS Training Solutions is a technology company that offers compliance and learning management software to meet the needs of Environment, Health, and Safety (EHS) professionals. This cloud-based software application includes a Training Record Manag...

BIS Safety Software is a SaaS company on a mission to change how organizations manage safety, learning, and compliance. Since 2006 we've been building software in a space where trust and data integrity matter, and we're looking for a Software Risk and Compliance Analyst who will be embedded with our technology and product teams, focused entirely on the software itself.

About the Role

You'll be in the room with product and technology every day, knowing the software as well as the people building it, and making sure that new modules, feature improvements, and changes to how data moves keep us aligned with PCI DSS, SOC 2, GDPR, and the data governance commitments we make to our clients.

Risk gets identified while a feature is still being sketched out, the right requirements land in the case up front, and nothing stalls later because a compliance question surfaced too late. When scope shifts partway through, you're the one who notices that what was approved is no longer what's being built.

You'll have the autonomy to raise a concern to anyone here, and we'll expect you to use it. We'll also expect you to bring a way forward. The job isenablement, not gatekeeping, and the difference matters to us.

You'll spend a lot of your time in project tickets and inside the software. The people who love this role are the ones who find that genuinely interesting.

This is anin-person role based out of our Sherwood Park, AB office.

In This Role, You Will Be Expected To:

  • Risk assessments: own the assessments for new features, new modules, and any change to how our software collects, stores, or moves data.
  • Early involvement: join feature mapping and product planning sessions, ask the questions that surface risk before development starts, and get the right requirements written into the case.
  • Ticket to ship: follow cases through their full life, watch for scope creep, and re-review when something changes so approvals stay valid.
  • Hands-on verification: work in the software yourself to confirm it behaves the way our documentation and our controls say it does.
  • AI features: assess how AI capabilities in our product handle personal data, where that data is processed, and whether it stays within the boundaries we've committed to.
  • AI in the build: join the conversations about how we connect AI tools to our data, asking where information gets processed, what a model can reach, and how it stays contained.
  • Audit readiness: review what has changed ahead of our SOC 2 and PCI DSS cycles, confirm our controls still match reality, and close gaps before an auditor finds them.
  • Practical solutions: partner with developers and product to find a compliant path forward so work keeps moving.

You Might Be the Right Fit If You Are:

  • Experienced with a background in risk, compliance, privacy, or data governance
  • Detail-oriented to an unusual degree, the person who reads a case and catches what nobody addressed
  • Experienced in digging until you actually understand it, especially when it comes to how data moves through a system
  • Willing to speak up and stay with it, raising a concern clearly and following through until it's resolved
  • Able to see the second-order impact, the other module, the other commitment, the thing this quietly touches
  • Following AI and privacy developments on your own, closely enough to spot when a new capability changes the risk picture
  • Drawn to technology and happy spending your days in project tickets and software
  • Curious about how AI works underneath the demo, enough to ask whether a tool is doing what it claims with our data
  • Self-directed, comfortable with autonomy and setting your own priorities
  • Solution-minded, arriving with options rather than only objections

Qualifications we are looking for:

  • A background in risk, compliance, privacy, data governance, or information security.
  • Working familiarity with at least one control framework or privacy regime, such as SOC 2, PCI DSS, GDPR, ISO 27001, or something comparable
  • Strong technical aptitude and real curiosity about how software works under the hood, including how data is stored, transmitted, and shared between systems
  • Experience with the privacy and data governance questions that come with AI features: what data a model can reach, where it's processed, and what leaves our environment.
  • Comfort working day to day in project management and ticketing tools, following a case from scoping through to release

Bonus points if you have:

  • Post-secondary education in a relevant field, such as compliance, information security, computer science, or engineering, or equivalent hands-on experience
  • A background in software engineering or QA/QC
  • Experience with AI governance, or a genuine interest in the privacy and data questions that come with AI features
  • Experience working inside a software or SaaS company

Compensation and benefits:

  • Employee Stock Ownership Plan (ESOP)
  • Full medical, dental, and vision coverage
  • Life insurance and disability insurance
  • Health spending account
  • Flexible working hours
  • On-the-job training and growth opportunities
  • Free on-site parking
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
405,710 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Equity • In office • Full-Time • Almaty
Cybersecurity
GDPR
SOC 2
Apply
$226k – $406k per year (Estimated) • Remote/Hybrid • 10+ years exp • San Jose
SQL
Databases
Amazon Neptune
BigQuery
Databricks
Delta Lake
Google BigQuery
Neo4j
AI/ML
AI Agents
Claude
Claude Code
Copilot
Cursor
EU AI Act
Knowledge Graph
Model Context Protocol
NIST AI RMF
DevOps
Amazon S3
AWS
Azure
IAM
Cybersecurity
GDPR
HIPAA
ISO 27001
Least Privilege
Microsoft Entra ID
Apply
$140k – $240k per year • Remote • Full-Time • Bachelor's Degree • United States
Java
Python
DevOps
Ansible
Azure
Chef
CI/CD
Configuration Management
Datadog
GCP
Grafana
Kubernetes
New Relic
Prometheus
Puppet
Splunk
Terraform
Cybersecurity
PCI DSS
SOC 2
Apply
$139k – $345k per year (Estimated) • Equity • In office • 15+ years exp • Master's Degree • Palo Alto
Databases
Databricks
Snowflake
AI/ML
AI Agents
LLM Guardrails
NIST AI RMF
Mobile
Algolia
DevOps
CI/CD
GCP
SLI/SLO/SLA
Cybersecurity
Carbon Black
Crowdstrike
ISO 27001
NIST CSF
Okta
OWASP Top 10
SentinelOne
Management
Obsidian
Apply
Senior AI Architect 2 days ago
$117k – $121k per year • In office • Full-Time • 4+ years exp • Master's Degree • San Francisco
Python
Databases
Databricks
AI/ML
Anthropic
Computer Vision
EU AI Act
LLMOps
OpenAI
DevOps
AWS
Azure
GCP
Terraform
Cybersecurity
GDPR
Apply
$36k – $43k per year • Equity • In office • Full-Time
Management
SharePoint
Apply
$50k – $65k per year • Equity • In office • Full-Time • 4+ years exp
Management
Zapier
Marketing
HubSpot
Mailchimp
Apply
$43k – $50k per year • Equity • In office • Full-Time
JavaScript
TypeScript
DevOps
CI/CD
Git
QA
Cypress
Playwright
Selenium
Apply
See all jobs
This is one of many
405,710 more open roles from verified company boards, updated every day.