Question
Remote
5-10

Compliance Engineer

1/27/2026

The Compliance Engineer will develop scalable processes for compliance controls and manage TRM's security compliance lifecycle. They will also conduct risk assessments and manage customer due diligence requests.

Salary

125000 - 142000 USD

Working Hours

40 hours/week

Company Size

201-500 employees

Language

English

Visa Sponsorship

No

About The Company
TRM Labs is a blockchain intelligence company that helps financial institutions, crypto businesses, and government agencies detect and investigate crypto-related financial crime and fraud. Every day, we tackle challenges in data engineering, data science, and threat intelligence to advance our mission to build a safer financial system for billions of people.  Attention Job Applicants: Recently, it has come to our attention that certain individuals are masquerading as members of TRM's recruitment and human resources team online. We will never request your personal information outside of the standard recruitment process. Every job offer at TRM is extended only after a formal interview process and we will not require candidates to fulfill any financial obligations as part of the hiring process. If you believe you have been targeted with a fraudulent job offer or encountered any suspicious activity, please send us an email with “Recruitment Fraud” in the subject line to recruiting-fraud@trmlabs.com.
About the Role
<div class="content-intro"><h2>Build a Safer World.&nbsp;</h2> <p>TRM Labs provides blockchain analytics and AI solutions to help law enforcement and national security agencies, financial institutions, and cryptocurrency businesses detect, investigate, and disrupt crypto-related fraud and financial crime. TRM’s blockchain intelligence and AI platforms include solutions to trace the source and destination of funds, identify illicit activity, build cases, and construct an operating picture of threats. TRM is trusted by leading agencies and businesses worldwide who rely on TRM to enable a safer, more secure world for all.</p></div><p>The Security Team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business.&nbsp;We are looking for a Senior Compliance Engineer to own TRM’s compliance and GRC initiatives that ensure we continue to deliver best-in-class security and trust for our customers.</p> <ul class="p-rich_text_list p-rich_text_list__bullet" data-stringify-type="unordered-list" data-indent="0" data-border="0"> <li data-stringify-indent="0" data-stringify-border="0"> <p><strong>The impact you will have here:</strong></p> <ul> <li>Develop scalable and sustainable processes and tools for normalized controls, collecting audit evidence, monitoring controls, and conducting gap analyses.</li> <li>Manage TRM’s existing security compliance and certification lifecycle (e.g., SOC 2 Type II, ISO 27001/27701, FedRAMP, CMMC) while planning for and prioritizing future compliance needs.</li> <li>Operationalize the GRC program to maintain our regulatory certifications.</li> <li>Manage customer due diligence requests including developing and maintaining security collateral for customers (e.g., SIG, CAIQ).</li> <li>Conduct enterprise risk assessments and manage the risk registry.</li> <li>Develop a vendor risk management program.</li> <li>Identify areas for improvement based on input from customers, the go-to-market teams, and overall business objectives. Anticipate customer needs with respect to compliance and due diligence.</li> </ul> <p><strong>What we’re looking for:</strong></p> <ul> <li>Develop automation to programmatically implement controls validations and evidence collections. Experience with Python or other programming and scripting languages is required.</li> <li>Work to align advanced technologies and Privacy by Design principles from the first stages of development and ensure that the data use meets established regulatory compliance needs.</li> <li>Strong understanding of Public Sector compliance security standards including NIST 800-53, SOC 2, CMMC, ISO, CyberEssentials UK, and other common compliance frameworks.</li> <li>Experience with leading a cloud-first SaaS company through the audit procesess.</li> <li>Strong focus on normalizing controls across frameworks and standards, with an eye toward improving maturity, scalability, and consistency over time, while looking beyond just “checking the box”.</li> <li>Privacy and GDPR experience is a plus.</li> <li>Security certifications (e.g., CISSP, CISM) are a plus.</li> </ul> <p><strong>Team Characteristics:</strong></p> <ul> <li>Remote first, globally distributed team</li> <li>Strong ownership and accountability</li> <li>Strong technical expertise, previous software development background preferred</li> <li>Open, honest, and timely information sharing</li> <li>Willingness to help each other succeed</li> <li>Healthy debate without personal conflict</li> <li>Shared problem-solving</li> </ul> <strong></strong></li> </ul> <p><strong>About the Team</strong></p> <ul> <li>The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.</li> <li>We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.</li> <li>Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.</li> <li>Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.</li> </ul> <p><strong>Time Zones:</strong></p> <ul> <li>Eastern Standard Time (EST - GMT-4)</li> <li>Pacific Standard Time (PST - GMT-7)</li> <li>Central European Summer Time (CET - GMT+2)</li> </ul> <p><strong>Learn about TRM Speed in this position:</strong></p> <ul> <li>Automate Repetitive Compliance Checks - Manually verifying compliance across systems or reviewing logs can be time-intensive. At TRM, we build custom integrations through scripts, SOAR platforms, or compliance management software (e.g. Drata) to automate routine tasks like generating compliance reports, tracking or collecting audit evidence, and monitoring control effectiveness.</li> <li>Build and leverage APIs for Cross-System Data Integration - Gathering compliance data from multiple systems can lead to delays and data silos. At TRM, we build and leverage automation and API's to pull real-time compliance data from critical systems into a centralized GRC tool or dashboard.</li> <li>Shift Left in Compliance - Detecting non-compliance late in a project lifecycle often requires rework and delays. At TRM, we embed compliance checks early in the development lifecycle. We integrate security and compliance standards directly into CI/CD pipelines to flag issues before they reach production.</li> </ul> <p><strong>The following represents the expected range of compensation for this role:</strong></p> <ul> <li>The estimated base salary range for this role is $125,000 - $142,000.</li> <li>Additionally, this role may be eligible to participate in TRM’s equity plan.</li> <li>Please note – we factor in the different costs for geographies outside the United States.</li> </ul> <p>&nbsp;</p><div class="content-conclusion"><hr> <h3>Life at TRM</h3> <p>We are building a safer world. That promise shows up in how we work every day.</p> <p>TRM runs fast. Really fast. We’re a high‑velocity, high‑ownership team that expects clarity, follow‑through, and impact. People who thrive here are energized by hard problems, experimentation, and direct feedback. If something takes months elsewhere, it often ships here in days.&nbsp;</p> <p>That pace isn’t for everyone. If you are optimizing primarily for consistent work-life balance, use the interview process to pressure-test fit. We want teammates who thrive here, not just survive here.</p> <p></p> <h3>Leadership Principles</h3> <p>We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions.</p> <ul> <li>Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly.</li> <li>Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end‑to‑end, and invest in getting better everyday.</li> <li>Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one‑team mindset — giving and receiving feedback to make the team stronger.</li> </ul> <p><strong>Learn more: </strong><a href="https://www.trmlabs.com/resources/blog/interviewing-at-trm-how-we-hire-and-what-success-looks-like">Interviewing at TRM: How We Hire and What Success Looks Like</a></p> <h3>The impact you will have</h3> <p>This work has real stakes. Depending on your role at TRM, your week might look like:</p> <ul> <li>Driving critical investigations that can’t wait for typical business hours.</li> <li>Shipping products in days when others would schedule quarters.</li> <li>Partnering with teams across time zones to deliver insights while the story is still unfolding.</li> <li>Building new solutions from first principles when the playbook doesn’t yet exist.</li> <li>Protecting victims and customers by tracing illicit activity and disrupting criminal networks.</li> </ul> <h3>Join our Mission</h3> <p>At TRM we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast.</p> <p>TRM is a Series C company with $220M in total funding, backed by Blockchain Capital, Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore.</p> <p></p> <h3><strong>Recruitment agencies</strong></h3> <p>TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.</p> <h3><strong>Privacy Policy</strong></h3> <p>By submitting your application, you are agreeing to allow TRM to process your personal information in accordance with the&nbsp;<a href="https://www.trmlabs.com/policies/privacy-policy">TRM Privacy Policy</a></p> <p><strong>Learn More</strong>:&nbsp;<a href="https://www.trmlabs.com/culture">Company Values</a>&nbsp;|&nbsp;<a href="https://www.trmlabs.com/interviewing">Interviewing</a>&nbsp;|&nbsp;<a href="https://www.trmlabs.com/faq">FAQs</a></p></div>
Key Skills
ComplianceGRCPythonSecurity StandardsCloudAuditRisk ManagementVendor ManagementGDPRCISSPCISMAutomationData IntegrationCI/CDPrivacyTechnical Expertise
Categories
TechnologySecurity & SafetyEngineeringData & AnalyticsConsulting
Benefits
Stock Options
Apply Now

Please let TRM Labs know you found this job on InterviewPal. This helps us grow!

Apply Now
Prepare for Your Interview

We scan and aggregate real interview questions reported by candidates across thousands of companies. This role already has a tailored question set waiting for you.

Elevate your application

Generate a resume, cover letter, or prepare with our AI mock interviewer tailored to this job's requirements.