Aprio logo
Aprio
Posted 75 days agoVerified live 11h ago

Senior Associate, Compliance as a Service

Brief overview

Remote
3+ yrsMinimum
8 H-1B approvalsDept. of Labor
3 green cardsCertified filings
PCI DSSSOC 1SOC 2ISO 27001ISO 27701HITRUSTCMMCFedRAMPNIST CSFGDPRCloud Security - AWSCloud Security - AzureCloud Security - GCPSIEMIDS/IPSNetwork Security ControlsEncryption

About the company

Independent professional services firm providing accounting and advisory services.

Visa sponsorship history

3 years sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
8H-1B approved
100%approval rate
2new H-1B hires
3PERM certified
$116,070median wage / yr
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20235
20243
LCA Certified ApplicationsAn early filing step, not a visa approval: it signals intent, not confirmed sponsorship.
20231
20241
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20232
20251
Top sponsored roles
Data & Analytics ManagerManager Information Assurance
Sponsored employees from
JapanIndia

Job description

Summary

Aprio is a Top 20 CPA and advisory firm that provides comprehensive services to clients. They are seeking a Senior Associate, Compliance as a Service to lead compliance engagements and support clients in maximizing their opportunities.

Responsibilities

  • Lead and support multiple low to moderately complex managed security compliance engagements, ensuring quality, consistency, and timeliness in all deliverables
  • Execute compliance assessments, gap analyses, remediation planning, and evidence collection across frameworks such as PCI DSS, SOC 1, SOC 2, ISO 27001, ISO 27701, HITRUST, CMMC, FedRAMP, NIST CSF, and GDPR
  • Develop draft policies and procedures, reports, and other common project deliverables based on established template sets
  • Effectively use project management tooling (Motion) to cross-map multiple account calendars, streamline scheduling, manage and prioritize tasks, assign tasks to others, and document processes and important client information
  • Effectively use GRC platforms (Drata, Anecdotes, Hyperproof) to implement and manage Compliance Operations for clients
  • Make efficient use of business tools (Slack, MS Office Suite, project management platforms) to work smarter, not harder
  • Communicate effectively in email, chat, meetings, and other professional settings. Never forget to send weekly status updates
  • Learn and apply AI LLM prompting basics; understand when to trust AI outputs and when to be skeptical
  • Support senior team members in client relationship management and contribute to expanding services within existing accounts
  • Collaborate with internal teams, including audit, advisory, and offensive security, to support integrated service delivery
  • Monitor regulatory developments and industry trends to stay current on compliance requirements and best practices
  • Complete all CPE requirements for current certifications prior to end of Q3
  • Attend firm-sponsored trainings as applicable
  • Manage your schedule in ProStaff and maintain timely, accurate completion of all required compliance and training

Skills

  • Minimum of 3 years' experience in information security, IT compliance, or a related cybersecurity role, with experience in professional services, consulting, or managed services environment
  • Demonstrated experience supporting and delivering compliance engagements across one or more frameworks
  • Foundational knowledge of cloud security (AWS, Azure, GCP) and securing hybrid/multi-cloud environments
  • Developing familiarity with security technologies (e.g., SIEM, IDS/IPS, network security controls, encryption), how to apply them, and the risks they address
  • GRC tooling expertise with at least one platform (e.g., Drata, Hyperproof, Anecdotes)
  • Excellent written and verbal communication skills, with the ability to articulate compliance and security topics to both technical and non-technical stakeholders

Qualifications

Must Haves

  • Minimum of 3 years' experience in information security, IT compliance, or a related cybersecurity role, with experience in professional services, consulting, or managed services environment
  • Demonstrated experience supporting and delivering compliance engagements across one or more frameworks
  • Foundational knowledge of cloud security (AWS, Azure, GCP) and securing hybrid/multi-cloud environments
  • Developing familiarity with security technologies (e.g., SIEM, IDS/IPS, network security controls, encryption), how to apply them, and the risks they address
  • GRC tooling expertise with at least one platform (e.g., Drata, Hyperproof, Anecdotes)
  • Excellent written and verbal communication skills, with the ability to articulate compliance and security topics to both technical and non-technical stakeholders

Benefits

  • Medical, Dental, and Vision Insurance on the first day of employment
  • Flexible Spending Account and Dependent Care Account
  • 401k with Profit Sharing
  • 9+ holidays and discretionary time off structure
  • Parental Leave – coverage for both primary and secondary caregivers
  • Tuition Assistance Program and CPA support program with cash incentive upon completion
  • Discretionary incentive compensation based on firm, group and individual performance
  • Incentive compensation related to origination of new client sales
  • Top rated wellness program
  • Flexible working environment including remote and hybrid options

More jobs like this