NextRaiseNextRaiseFind jobs
Sign inSign up free
Jobs / Compliance Specialist in United States of America
4 days ago
Apply with autofill
Apply with autofill
Polymarket·4 days ago
4 days ago

GRC & Privacy Lead

New York, United States of AmericaFull-timeOn-siteSenior · 6-10 years₹1.2Cr – ₹1.7Cr/yr · est.Compliance Specialist

Sign up free to see how well your resume matches this role.

Boost your chances at polymarket

How you compare FREE

?
Your scoreYour score: not yet known
→
19
Top 10%Top 10%: 19 out of 100

Top 10% of NextRaise users matched against Compliance Specialist roles in United States.

Must-have skills for this role

  • soc 2
  • gdpr
  • vendor risk management
  • ccpa

PDF or DOCX · no account needed

Apply faster with autofill FREEpolymarket uses Ashby - autofill it instead of retyping.careers.example.com/applyAutofillingFull namePriya SharmaEmailpriya.sharma@example.comPhone+49 30 1234567LocationBerlGet the extension

What you'll do

  • Triage vendor intake requests daily, assess inherent risk based on data sensitivity and system connectivity, and route appropriately — including flagging vendors that require PIAs or DPA review before onboarding
  • Analyze vendor assurance documentation — SOC 2 reports, ISO certifications, PCI AOCs, and penetration test summaries — and produce clear written risk memos with defensible dispositions
  • Gather and organize evidence for our active SOC 2 Type II engagement, coordinate with control owners to close requests on time, and manage submissions through the auditor portal from start to finish
  • Process DSAR requests across multiple corporate entities, applying correct retention exemptions and routing logic, and track fulfillment to meet statutory deadlines
  • Run privacy impact assessments for new product features and vendor onboarding, working directly with product and engineering to identify risks before they ship
  • Maintain the policy library, track review and acknowledgment cycles, and own remediation tracking for vendor and audit findings through to resolution
  • Help implement and operationalize our privacy compliance platform, including building out the data inventory and mapping flows that reflect how we actually collect and process personal data

What they're looking for

  • Hands-on SOC 2 Type II audit experience — you have personally gathered evidence, coordinated with control owners, and managed auditor requests through a full engagement cycle
  • Demonstrated experience conducting third-party vendor risk assessments, including reading and interpreting SOC 2 reports, PCI AOCs, and pen test summaries, and writing risk memos with clear dispositions
  • Working knowledge of GDPR, CCPA/CPRA, BIPA, and CUBI, and the ability to translate those obligations into concrete process steps that product and engineering teams can follow
  • Experience building compliance or privacy processes from scratch, not just inheriting and maintaining them
  • Comfort operating independently, triaging ambiguous situations, and making defensible decisions without waiting for escalation on routine assessments

Nice to have

  • Experience with PCI DSS scoping or self-assessment activities
  • Familiarity with KYC and identity verification data flows and the privacy considerations specific to biometric and identity data
  • Prior experience at a crypto, fintech, or prediction market company

Summarised by NextRaise from the employer’s description, which follows in full below.

Full description from employer

About Polymarket

Polymarket is the world's largest prediction market platform. We enable individuals to express views on real-world events by trading on outcomes across politics, economics, sports, culture, and current affairs. Built as a peer-to-peer marketplace with no centralized "house," Polymarket aggregates diverse opinions into transparent, market-based probabilities that reflect collective expectations about the future.

We're growing fast — both in terms of volume ($21B traded in 2025) and adoption as an alternative news source. Our ambition is to become a ubiquitous beacon of truth in global media and we need your help adding fuel to the fire.

About the Role

Polymarket's IT and Security team is small, senior, and expected to move fast. This role sits at the intersection of third-party risk, audit execution, and privacy operations — and the person in it will own all three. DSARs need to be processed, vendors need risk dispositions before they get access to our systems, and PIAs need to happen before engineering ships, not after.

This is a senior IC role. You'll make judgment calls independently, build processes that didn't exist before you arrived, and leave behind documentation the team can actually use. We have active audit work underway, a vendor pipeline that needs rigorous day-to-day management, and privacy obligations spanning GDPR, CCPA/CPRA, BIPA, CUBI, and the specific data flows that come with KYC and identity verification at scale.

What You'll Do

  • Triage vendor intake requests daily, assess inherent risk based on data sensitivity and system connectivity, and route appropriately — including flagging vendors that require PIAs or DPA review before onboarding

  • Analyze vendor assurance documentation — SOC 2 reports, ISO certifications, PCI AOCs, and penetration test summaries — and produce clear written risk memos with defensible dispositions

  • Gather and organize evidence for our active SOC 2 Type II engagement, coordinate with control owners to close requests on time, and manage submissions through the auditor portal from start to finish

  • Process DSAR requests across multiple corporate entities, applying correct retention exemptions and routing logic, and track fulfillment to meet statutory deadlines

  • Run privacy impact assessments for new product features and vendor onboarding, working directly with product and engineering to identify risks before they ship

  • Maintain the policy library, track review and acknowledgment cycles, and own remediation tracking for vendor and audit findings through to resolution

  • Help implement and operationalize our privacy compliance platform, including building out the data inventory and mapping flows that reflect how we actually collect and process personal data

What We're Looking For

  • Hands-on SOC 2 Type II audit experience — you have personally gathered evidence, coordinated with control owners, and managed auditor requests through a full engagement cycle

  • Demonstrated experience conducting third-party vendor risk assessments, including reading and interpreting SOC 2 reports, PCI AOCs, and pen test summaries, and writing risk memos with clear dispositions

  • Working knowledge of GDPR, CCPA/CPRA, BIPA, and CUBI, and the ability to translate those obligations into concrete process steps that product and engineering teams can follow

  • Experience building compliance or privacy processes from scratch, not just inheriting and maintaining them

  • Comfort operating independently, triaging ambiguous situations, and making defensible decisions without waiting for escalation on routine assessments

  • (Plus) Experience with PCI DSS scoping or self-assessment activities

  • (Plus) Familiarity with KYC and identity verification data flows and the privacy considerations specific to biometric and identity data

  • (Plus) Prior experience at a crypto, fintech, or prediction market company

Benefits

  • Competitive salary & equity

  • Unlimited PTO

  • Full Health, Vision, & Dental coverage

  • 401k match

  • Hardware setup: new MacBook Pro, big display, & accessories

Pay Transparency

Base salary range: $150,000 to $200,000 annually, plus equity and benefits.

This range reflects a good-faith estimate for this position. Experience levels vary widely within a title here, so please reach out even if your expectations fall outside it. We're always happy to chat.

Company

Polymarket
New York, United States of America

Company facts come from this company's own listings. We only show what the postings themselves carry.

Sourced from Polymarket's careers site·first seen 17 Sept 2026·last verified 18 Sept 2026·How we source jobs

Similar jobs

  • Compliance Advisor, Supervisory Infrastructure at Fidelity InvestmentsWestlake, United States of America–match not yet calculated
  • Crypto Controls and Compliance Advisor at StripeRemote US–match not yet calculated
  • Global Inventory and Compliance Specialist at redwingshoecompanyRed Wing, United States of America–match not yet calculated
  • Dairy Compliance Specialist 1 ,2, or 3 at georgiaPerry, United States of America–match not yet calculated
  • Vendor Compliance Specialist at qvcOntario, United States of America–match not yet calculated

Browse more jobs

  • Compliance Specialist jobs in United States
  • Compliance Manager jobs in United States
  • Company Secretary jobs in United States
  • Data Privacy Officer jobs in United States
  • Compliance Specialist jobs in India
  • Compliance Specialist jobs in United Kingdom