About ActiveComply
ActiveComply builds compliance software for regulated financial institutions: banks, credit unions, mortgage lenders, broker-dealers, and registered investment advisors. Our products monitor and archive social media, websites, and remote workspaces so compliance teams can meet obligations like FINRA Rule 3110 and state licensing requirements.
About the role
This is our first dedicated operations hire. The scope supports engineering and internal IT workstreams including employee onboarding and offboarding, SOC 2 administration, and production infrastructure ops.
:
- Internal IT - You keep our people equipped and our devices secure: laptops, accounts, software access, endpoint management, onboarding and offboarding, and coordination of technology vendors and licenses.
- SOC 2 program administration - We are SOC 2 audited and run our program in Vanta: evidence collection, access reviews, onboarding and offboarding checklists, vendor security reviews, and audit support.
- Production operations - Execute prod change-management ops, updating a customer data record, provisioning account configuration. All ops are auditable, ticketed and documented procedures.
You'll report to the CTO and work closely with engineering, finance, and customer-facing teams managing production systems, customer data, and audit evidence.
What you'll do
Internal IT
- Own devices and endpoints: enroll, configure, and patch company laptops through Microsoft Intune; monitor endpoint health and security alerts in Microsoft Defender and follow up on findings.
- Run the employee lifecycle end to end: at onboarding, procure and provision equipment, create accounts, and grant software access appropriate to the role; at offboarding, revoke access across all systems, recover equipment, and complete the documented checklist on schedule (offboarding is a SOC 2 control, so completeness and timing are audited).
- Run day-to-day internal IT: work the Jira ticket queue as first-line support, administering the core systems directly (M365, endpoints, identity) and routing requests to the owners of ancillary software (for example, Salesforce is owned by RevOps); own asset tracking and the software and SaaS inventory, and coordinate technology vendors and licenses (procurement, renewals, seats, and who has access to what).
SOC 2 program administration
Control ownership sits with the CTO (access controls, endpoint security, change management, backup and recovery, infrastructure security) and with finance for HR and Board controls.
You run the recurring supporting work:
- Day-to-day SOC 2 admin in Vanta and audit support: keep evidence current for technical controls (access changes, onboarding and offboarding checklists, endpoint compliance, backup checks) and work open tasks before they go overdue; coordinate with finance when a control's evidence lives with HR or the Board; respond to auditor requests for the systems you administer and support the annual audit cycle.
- Administer the recurring compliance cycles end to end: periodic employee access reviews (prepare the review, collect sign-offs, execute approved revocations through the documented process, file the evidence), the security awareness training cycle (enrollment, completion tracking, follow-up), and technical vendor risk management (new-vendor security reviews, vendor records and questionnaires kept current).
- Follow, and help improve written procedures: access grants are systematized, production ops reside in approved systems, change management is auditable.
Production operations
- Work the operations ticket queue for production and customer changes that do not involve code: customer data record updates, TrustFrame compliance rule provisioning for new accounts, account configuration changes.
- Execute each change through the documented procedure for its type: confirm scope from the ticket, run the preview or dry-run step where the tooling supports one, execute, verify the result, and record the outcome on the ticket; where a change requires access you do not hold (some are restricted to engineering Tech Leads), scope it fully, hand off a ready-to-run request, and verify the result.
- Partner with engineering to improve the operations toolkit: identify recurring manual changes, help document them as runbooks, and help specify safer self-service tooling over time.
What we're looking for
- 3+ years in IT administration, IT operations, technical support, or similar.
- Working experience with the Microsoft endpoint stack (Intune, Defender, Entrable MDM and endpoint-security stack you could translate from.
- Experience supporting a compliance or audit program (SOC 2, ISO 27001, or similar): collecting evidence, running access reviews, or working an auditor request list. Adjacent experience counts if it built the same evidence-and-checklist discipline.
- Comfortable operating inside a documented-change discipline: tickets, checklists, dry runs, verification steps, and audit evidence are how you already like to work, or how you want to work.
- Clear written communication: most of your work product is tickets, checklists that other people rely on.
Nice to have
- Hands-on experience with Vanta or a comparable compliance automation platform
- Vendor management experience: procurement, renewals, and security questionnaires.
- Basic scripting (PowerShell or bash) or basic SQL, enough to sanity-check data and automate small repetitive tasks.
- Exposure to Google Workspace and Google Cloud admin.
- Background in fintech or another regulated industry.
What success looks like
- By 3 months: onboarding, offboarding, device management, and the internal IT ou, on checklist, with evidence current in Vanta.
- By 6 months: day-to-day SOC 2 administration is fully yours (evidence collection, access reviews, training cycle, vendor reviews), the finance team's involvement is limited to HR and Board control evidence, and the operations ticket queue for non-code production
- Ongoing: the runbook library grows, recurring manual work shrinks because you flag the repetitive changes worth automating, and audit cycles are routine rather than a scramble.
Pay: $100,000.00 - $115,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Health insurance
- Vision insurance
Work Location: Remote