Senior Technical Compliance Analyst

Posted 1hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Senior Technical Compliance Analyst strengthening DraftKings’ regulated gaming technology compliance programs. Leading audits, control validation, remediation, and compliance automation across technical teams.

Responsibilities:

  • Own assigned technical compliance domains across SOC 2, ISO 27001, PCI DSS, SOX ITGC, NIST, and other relevant requirements
  • Lead audit and certification activities from planning through completion
  • Coordinate timelines, deliverables, evidence collection, control validation, and responses across technical teams
  • Partner with Engineering, Security, Legal, Privacy, Internal Audit, and external auditors
  • Assess control design and implementation, address audit questions, and resolve identified gaps
  • Translate regulatory, contractual, and certification requirements into practical technical controls, scalable workflows, and stakeholder guidance
  • Build evidence strategies to improve audit and assessment quality, completeness, reusability, and efficiency
  • Identify compliance risks and control gaps, assign remediation ownership, track progress, and drive issues to resolution
  • Develop program health metrics, audit status reporting, and leadership-ready compliance insights
  • Advance governance, risk, and compliance capabilities through tooling, automation, repeatable evidence gathering, and post-audit improvements
  • Share expertise and support consistent execution across the team

Requirements:

  • Bachelor’s Degree in Computer Science, Information Technology, or a related field
  • At least 5 years of experience in technical compliance, information technology audit, security compliance, privacy compliance, risk management, or governance within a technology-driven or regulated environment
  • Working knowledge of compliance and security frameworks such as SOC 2, ISO 27001, PCI DSS, SOX ITGC, NIST, or similar standards
  • Experience leading or supporting audit readiness, evidence collection, control validation, remediation tracking, and external audits or certification activities
  • Technical fluency across access management, change management, vulnerability management, logging and monitoring, incident response, data protection, cloud infrastructure, and secure development
  • Experience assessing control design and implementation and translating compliance requirements into clear technical and operational expectations
  • Experience writing scripts, including Python, and using artificial intelligence tools to automate evidence collection, control testing, or compliance workflows is a plus
  • Strong stakeholder management and communication skills, with the ability to influence across teams and explain compliance requirements, risks, and remediation needs to technical and non-technical audiences
  • Continuous improvement mindset and strong attention to detail
  • Experience improving compliance processes, documentation, audit playbooks, evidence workflows, or control monitoring practices
  • Relevant certifications such as CISA, CISSP, CRISC, CISM, or similar credentials are a plus
  • May be required to obtain a gaming license issued by the appropriate state agency as a condition of employment

Benefits:

  • Bonus
  • Equity
  • Benefits as applicable