hero

Join the innovative companies building on Hedera Hashgraph

Compliance Engineer

TRM Labs

TRM Labs

Legal
United States · Remote
USD 125k-142k / year + Equity
Posted on Jan 23, 2026

Build to Protect Civilization

TRM is a blockchain intelligence company that’s on a mission to build a safer world for billions of people. We’re a lean, high-impact team tackling some of the world’s most critical challenges, ranging from human trafficking and financial fraud to terrorist financing. We are builders who power governments, financial institutions, and crypto companies when the clock is running and the consequences are real. This is why every TRMer is a bet on our future and has the power to change our trajectory.

The Security Team is responsible for and committed to securing all things at TRM. From our customers to our code, and everything in between, the security team is involved in all aspects of the business. We are looking for a Senior Compliance Engineer to own TRM’s compliance and GRC initiatives that ensure we continue to deliver best-in-class security and trust for our customers.

  • The impact you will have here:

    • Develop scalable and sustainable processes and tools for normalized controls, collecting audit evidence, monitoring controls, and conducting gap analyses.
    • Manage TRM’s existing security compliance and certification lifecycle (e.g., SOC 2 Type II, ISO 27001/27701, FedRAMP, CMMC) while planning for and prioritizing future compliance needs.
    • Operationalize the GRC program to maintain our regulatory certifications.
    • Manage customer due diligence requests including developing and maintaining security collateral for customers (e.g., SIG, CAIQ).
    • Conduct enterprise risk assessments and manage the risk registry.
    • Develop a vendor risk management program.
    • Identify areas for improvement based on input from customers, the go-to-market teams, and overall business objectives. Anticipate customer needs with respect to compliance and due diligence.

    What we’re looking for:

    • Develop automation to programmatically implement controls validations and evidence collections. Experience with Python or other programming and scripting languages is required.
    • Work to align advanced technologies and Privacy by Design principles from the first stages of development and ensure that the data use meets established regulatory compliance needs.
    • Strong understanding of Public Sector compliance security standards including NIST 800-53, SOC 2, CMMC, ISO, CyberEssentials UK, and other common compliance frameworks.
    • Experience with leading a cloud-first SaaS company through the audit procesess.
    • Strong focus on normalizing controls across frameworks and standards, with an eye toward improving maturity, scalability, and consistency over time, while looking beyond just “checking the box”.
    • Privacy and GDPR experience is a plus.
    • Security certifications (e.g., CISSP, CISM) are a plus.

    Team Characteristics:

    • Remote first, globally distributed team
    • Strong ownership and accountability
    • Strong technical expertise, previous software development background preferred
    • Open, honest, and timely information sharing
    • Willingness to help each other succeed
    • Healthy debate without personal conflict
    • Shared problem-solving

About the Team

  • The culture of our team is built on mutual respect, where everyone's opinion is valued and heard.
  • We prioritize flexibility and efficiency, always seeking smarter ways to work without compromising quality.
  • Transparency is at the heart of how we operate, both within the team and with the business, as we focus on clearly communicating and addressing cyber risks.
  • Our collaborative approach ensures that we not only mitigate these risks but also align our efforts with business goals to protect and drive success.

Time Zones:

  • Eastern Standard Time (EST - GMT-4)
  • Pacific Standard Time (PST - GMT-7)
  • Central European Summer Time (CET - GMT+2)

Learn about TRM Speed in this position:

  • Automate Repetitive Compliance Checks - Manually verifying compliance across systems or reviewing logs can be time-intensive. At TRM, we build custom integrations through scripts, SOAR platforms, or compliance management software (e.g. Drata) to automate routine tasks like generating compliance reports, tracking or collecting audit evidence, and monitoring control effectiveness.
  • Build and leverage APIs for Cross-System Data Integration - Gathering compliance data from multiple systems can lead to delays and data silos. At TRM, we build and leverage automation and API's to pull real-time compliance data from critical systems into a centralized GRC tool or dashboard.
  • Shift Left in Compliance - Detecting non-compliance late in a project lifecycle often requires rework and delays. At TRM, we embed compliance checks early in the development lifecycle. We integrate security and compliance standards directly into CI/CD pipelines to flag issues before they reach production.

The following represents the expected range of compensation for this role:

  • The estimated base salary range for this role is $125,000 - $142,000.
  • Additionally, this role may be eligible to participate in TRM’s equity plan.
  • Please note – we factor in the different costs for geographies outside the United States.


Life at TRM

We build to protect civilization. That promise shows up in how we work every day.

TRM runs fast. Really fast. We’re a high-velocity team that expects ownership, clarity, and follow-through. People who thrive here are inspired by hard problems, experimentation, direct feedback. If it takes months elsewhere, it often ships here in days. If you are optimizing primarily for consistent work-life balance, use the interview process to pressure-test fit. We want teammates who thrive here, not just survive here.

We coach directly, assume positive intent, and play for the front of the jersey.

Leadership Principles

  • Impact-Oriented Trailblazer: We put customers first, driving for speed, focus, and adaptability.
  • Master Craftsperson: We prioritize speed, high standards, and distributed ownership.
  • Inspiring Colleague: We value humility, candor, and a one-team mindset.

Want to learn more about how we interview at TRM Labs? Check out more about our leadership principles and hiring process here.

What You’ll Do Here

This work has teeth. At TRM, your week might include:

  • Driving critical investigations that can’t wait for typical business hours.
  • Shipping products in days when others would schedule quarters.
  • Partnering with teams across time zones to deliver insights while the story is still unfolding.
  • Building new solutions from first principles when the playbook doesn’t yet exist.
  • Protecting victims and customers by tracing illicit activity and disrupting criminal networks.

Join our Mission

We look for people who want their work to matter, who build with speed and rigor, and who take pride in protecting others through their craft. If you’re excited by TRM’s mission but don’t check every box, apply anyway. We hire for slope, judgment, and the will to learn fast.

Build to protect civilization. Let’s do it together.

Recruitment agencies

TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement.

Privacy Policy

By submitting your application, you are agreeing to allow TRM to process your personal information in accordance with the TRM Privacy Policy

Learn More: Company Values | Interviewing | FAQs