Source Job

US

  • Gain exposure to client-facing security assessments by participating in control testing interviews and assisting with artifact gathering.
  • Contribute to advisory deliverables by analyzing security control artifacts against compliance standards and documenting results.
  • Achieve a comprehensive understanding of cybersecurity essentials with a focus on Governance, Risk, and Compliance (GRC) and security frameworks like FedRAMP, ISO, SOC, and HIPAA.

GRC Security Frameworks Technical Writing Analytical Skills Communication

20 jobs similar to Compliance Advisory - 2027 Summer Internship

Jobs ranked by similarity.

US

  • Assist with IT automation processes and documentation of security practices.
  • Contribute to Virtual Desktop Infrastructure (VDI) implementation and secure remote access.
  • Conduct security audits, vulnerability analysis, and support compliance reporting.

FWI is a company that provides cybersecurity and IT services, supporting federal clients. It has been recognized as a Top Workplace by the Washington Post in 2024 and 2025, offering excellent growth opportunities in a collaborative environment.

$150,000–$200,000/yr
US

  • Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
  • Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
  • Represent the compliance program in customer-facing discussions and security due diligence reviews.

Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.

Canada

  • Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
  • Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
  • Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.

Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.

$6,000–$7,500/mo
US

  • Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
  • Automate compliance workflows, evidence collection, access reviews, and security checks.
  • Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.

Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

$16–$24/hr
US

  • Work on real cybersecurity tasks including Microsoft security configuration, threat research, and automation.
  • Collaborate directly with the Director of Cybersecurity on client security work and compliance support.
  • Build skills in security tooling, scripting, and documentation with a path to full-time employment.

EVOCS is an IT consulting firm that helps businesses operate more effectively through practical expertise and technology solutions. The company is a trusted technology partner to a growing number of organizations, with a team committed to quality and client relationships.

US

  • Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
  • Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
  • Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.

Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.

$112,000–$140,000/yr
US

  • Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
  • Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
  • Perform technical security and compliance reviews of third-party vendors and service providers.

iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.

Global 5w PTO

  • Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
  • Engineer GRC workflows with internal systems to support compliance by design.
  • Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.

Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.

$174,000–$238,000/yr
US

  • Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
  • Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
  • Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.

Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.

US Unlimited PTO 16w maternity 16w paternity

  • Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
  • Interpret controls at the mechanics level and author precise technical guidance.
  • Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.

Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.

US

  • Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
  • Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
  • Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.

RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.

US

  • Support security and compliance initiatives across cloud-based environments.
  • Conduct web application penetration testing and vulnerability assessments.
  • Implement and maintain security controls aligned with compliance frameworks.

Epsilon ASI is a technology company focused on providing secure and compliant environments for its clients. The company is looking for early-career security professionals to join its highly technical team in a remote setting.

United States

  • Work closely with industry-leading subject matter experts on real-world security response and collaborative projects.
  • Complete in-house training programs to enhance your security knowledge and skills.
  • Participate in partner-led vendor training and certifications for hands-on development.

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. The company has over 1,300 employees and is known for its enjoyable workplace atmosphere with strong core values.

US

  • Evaluate security controls and assess alignment with ISO 27001, SOC 2, NIST, and other frameworks.
  • Coordinate with internal teams and external auditors to support audit engagements and maintain control evidence.
  • Apply risk-based monitoring and contribute to compliance oversight, security operations, and secure-by-design initiatives.

The company is a mission-driven cybersecurity partner focused on strengthening information security, privacy, and organizational resilience. While specific size details are not provided, the team fosters a collaborative, high-impact environment with opportunities for continuous learning and career development.

$102,500–$102,500/yr
US Unlimited PTO

  • Own GRC workstreams from initial request through evidence collection, testing, and remediation.
  • Test security controls and conduct risk assessments to identify gaps and drive realistic remediation.
  • Support audits, vendor reviews, customer questionnaires, and policy maintenance across teams.

YipitData is a leading market research and analytics firm for the disruptive economy, providing actionable insights from alternative data. The company has a global presence with offices in the US, APAC, and India, and is recognized as an Inc. Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.

$139,000–$218,000/yr
US

  • Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
  • Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
  • Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.

Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.

$114,800–$173,250/yr
US

  • Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
  • Drive recurring continuous monitoring and evidence workflows across multiple teams.
  • Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.

Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.

Global

  • Assist in monitoring compliance with frameworks like ISO 27001, SOC 2, and Cyber Essentials.
  • Maintain the central Risk Register and track remediation progress across departments.
  • Support policy management and compliance training across the organization.

We are a global Physical AI company using data and AI to improve critical industries like healthcare, water, energy, and telecom. Our teams are ambitious, curious, and practical, with colleagues across Africa, Europe, the UK, and the US.

US Unlimited PTO

  • Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
  • Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
  • Answer customer security questionnaires and ensure compliance documents are accurate.

Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.