Compliance Jobs in New York
Compliance jobs in New York are among the most active in the country, concentrated in financial services, healthcare, pharmaceuticals, and insurance across a market that runs from entry-level analysts through chief compliance officers. New York City anchors the vast majority of hiring, with significant activity in Albany and Buffalo tied to regulated industries and state government. Major employers with a lasting presence include JPMorgan Chase, Pfizer, and MetLife, and the most sought-after specializations right now are financial crimes and anti-money laundering, healthcare regulatory compliance, and data privacy. Find a role that fits below and apply directly.
Find Compliance JobsOverview
Showing 5 of 265+ Compliance jobs









About Peraton
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
About The Role
Peraton is seeking a Cloud Engineer specializing in Governance, Risk, and Compliance (GRC) to help modernize how it manages audit, risk, and compliance. This person will help move from manual evidence collection to a cloud-engineered, continuously monitored program. This senior role owns the transformation end-to-end: the audit and assessment calendar, System Security Plan and control documentation, continuity and privacy deliverables, and compliance reporting, all rebuilt on automated pipelines this role designs and builds directly.
Work Location: Remote
Shift Schedule: 8am – 5pm Eastern Standard Time (EST)
What you will do:
Audit & Assessment Leadership
- Own the organization's full audit and assessment calendar, ongoing/continuous control assessments, financial and IT-financial audits, internal controls testing, and security compliance audits (e.g., SOC 1 Type II). Serving as the primary point of contact for external auditors and assessors.
- Lead recurring meetings and working sessions with the client, auditors, and assessors across the audit lifecycle: kickoffs, evidence walkthroughs, interviews, findings reviews, and status updates. Represents the organization’s control environment directly to external stakeholders.
- Provide audit support across the full assessment portfolio, including penetration testing, red/purple/white team exercises, and periodic CISA high-value-asset assessments, incorporating all findings into the risk register and remediation lifecycle.
- Support new system authorization (ATO) and periodic reauthorization efforts, coordinating required documentation and evidence on a recurring cycle.
Security Documentation & Control Ownership
- Own ongoing maintenance of the System Security Plan (SSP): control implementation updates, system and technical descriptions, and review of inherited/tailored controls against the NIST 800-53 baseline. Validating control descriptions against the actual cloud architecture and configuration, not just the paper record.
- Lead the annual review and executive sign-off cycle for core security documentation and review the organization's control catalog for accuracy against how the environment is built and configured.
Continuity & Resilience Planning
- Own the annual review, update, and test cycle for business continuity and resilience documentation: business impact analysis, contingency plans, disaster recovery plans, and incident response plans. Grounded in the actual failover, backup, and recovery architecture of the cloud environment, not generic templates.
Privacy
- Lead recurring privacy impact/threshold assessments in coordination with the privacy function, including technical review of how architecture handles the data in scope.
Metrics, Reporting & Automation
- Own recurring compliance reporting deliverables: inventory reports, compliance scorecards, SLA and audit-performance metrics, progress reports, and build the automation that generates them directly from the cloud environment (native services, APIs, infrastructure-as-code state) rather than manual collection.
- Design, build, and maintain automated evidence-collection and continuous-monitoring pipelines using native cloud services and scripting/IaC, reducing manual, screenshot-based collection across the full audit and reporting calendar above.
- Identify the highest-value recurring manual processes across audit, documentation, and reporting work, and personally build the automation to address them. This role is expected to build, not just spec and hand off.
Governance & Stakeholder Coordination
- Maintain governance documents that codify the organization's security and audit-support processes.
- Serve as the point of contact for ad hoc security and privacy inquiries and impact-analysis requests from system and business owners.
- Lead recurring coordination meetings with system owners, risk management, and compliance stakeholders to maintain shared visibility into audit status, findings, and remediation.
Skills:
- Infrastructure depth. Hands-on experience with the organization's full technical environment: cloud (AWS), networking, databases, and midrange software (OS, VDI, Security, and administrative tool stack. Focus is to build in and extract evidence.
- Infrastructure as Code. Able to read, write, and modify IaC (e.g., Terraform, CloudFormation) to validate infrastructure configurations, and to build policy as code compliance checks into the pipeline.
- Automation & scripting. Builds working automation (in any language — Python, Bash, PowerShell) for evidence collection, inventory reporting, and continuous monitoring; this is a hands-on build responsibility across this role's full reporting and audit workload, not an occasional task.
- Security tooling & automation. Able to pull compliance-relevant data and build automated evidence collection from the organization’s security tool stack (e.g., SIEM, firewalls, EDR, centralized logging), not limited to cloud-native services. Capable of managing Cloud Native Application Protection Platforms (Wiz, Prisma Cloud) for enterprise “code to runtime” security with automated remediation.
- Networking fundamentals. Understands network architecture, segmentation, and access boundaries to assess whether a control claim about network security is true in the environment. Including cloud platform's native compliance, logging, and monitoring services (e.g., AWS Config, Security Hub, CloudTrail, Audit Manager) as the primary evidence source, replacing manual collection.
- GRC platform fluency. Administers and configure GRC/compliance automation tooling to consume evidence pulled from the cloud environment.
- NIST 800-53 and control framework depth. Experience with control intent (not just control language) to tailor, inherit, and validate controls against real architecture.
- Written and verbal communication. Translates technical implementation into audit-ready narrative for auditors and translates compliance/control requirements into terms that hold up in architecture and code.
- Program and stakeholder management. Runs the full audit, documentation, and reporting calendar, with organizational discipline.
Qualifications
Required Qualifications:
- Must be a U.S. Citizen with the ability to obtain and maintain the required Public Trust level clearance
- Bachelors Degree and 12 years of experience, a Masters Degree and 10 years of experience, or a High School diploma or equivalent and 16 years of experience
- 10+ years of combined experience across cloud engineering and GRC/IT audit/information security compliance, with genuine hands-on depth in both
- Demonstrated experience building or maintaining cloud infrastructure and automation (IaC, scripting, cloud-native tooling) in a production environment.
- Demonstrated experience serving as the primary point of contact between technical teams and external auditors or assessors, and owning security documentation (e.g., SSP) and control implementation.
- Experience managing findings and remediation from audits, penetration testing, or red/white team engagements through to closure.
- A portfolio or concrete example of a manual compliance or reporting process the candidate personally automated is a strong plus. Frameworks: NIST 800-53, NIST CSF, A-123, FISMA, and SOC 1/2 Type 2.
- One or more of the following relevant certifications: AWS Certified Solutions Architect, AWS Certified Security - Specialty, CISSP, CISA, CRISC, or CGRC
Preferred Qualifications:
- Bachelors Degree in Computer Science, Cybersecurity, Information Systems, or a related field
Details
Target Salary Range: $112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at https://www.careers.peraton.com/benefits.
Application Statements: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. By applying to this job, you are expressing interest in the role and the Company. During the review of your application, you may be required to participate in an on-camera interview, as well as participate in a process to verify your identity. Use of artificial intelligence (AI) tools of any kind during Peraton interviews is strictly prohibited unless the candidate has obtained prior written authorization. All interview responses must be the candidate’s own.
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
See All 265+ Compliance Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Compliance JobsCompliance Jobs by City in New York
Where New York roles are concentrated, by current openings.
Compliance Job Market in New York
A snapshot from current New York openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Banking & Financial Services
- Healthcare & Medical Services
- Education
- Food & Beverage
- Human Resources
What New York Employers Look For
The qualifications that appear most often in compliance jobs across New York.
- Relevant certification such as CCEP, CRCM, or CAMS recognized in New York
- Bachelor's degree in law, finance, business, or a related field
- Working knowledge of New York State and federal regulatory frameworks
- Experience conducting internal audits, risk assessments, or regulatory filings
- Strong written communication skills for policy development and reporting
- Proficiency with compliance management software and documentation systems
Compliance Jobs in New York: Frequently Asked Questions
How do you become a compliance in New York?
Most compliance roles in New York require a bachelor's degree in business, finance, law, or a related field, followed by industry-specific certification. New York does not issue a single state compliance license, but employers in financial services expect credentials such as CAMS for anti-money laundering or CRCM for banking, while healthcare compliance roles favor the CCEP from the Compliance Certification Board. Many candidates enter through legal, audit, or risk analyst roles before moving into dedicated compliance positions.
How much do compliances make in New York?
Compliances in New York earn a median of about $90,080 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $53,330 for the lowest 10% to over $142,370 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire compliances in New York?
Employers hiring compliances in New York right now include KeyBank, Goldman Sachs, and Amazon, based on current listings on Migrate Mate as of September 2026. New York's density of financial institutions, hospital networks, and global pharmaceutical headquarters makes it one of the deepest compliance hiring markets in the country.
Which New York cities have the most compliance jobs?
New York, Rochester, and Albany have the most compliance openings in New York. New York City dominates because of its concentration of global banks, insurance carriers, and life sciences firms, while Albany draws compliance professionals tied to state regulatory agencies and healthcare systems, and Buffalo's growing financial services and regional hospital sector supports a steady secondary market.
Are there remote compliance jobs in New York?
Yes, and more than most fields. About 76% of compliance openings tied to New York are remote or hybrid as of September 2026, reflecting the desk-based, document-driven nature of the work. Roles in data privacy, policy development, and third-party risk management are the most consistently offered on a remote or hybrid basis, while on-site requirements tend to appear in heavily regulated environments such as hospital systems or trading floors.
How can I get hired as a compliance in New York with little or no experience?
The most realistic entry path is a compliance analyst or compliance coordinator role at a mid-size financial services firm or regional hospital network in New York, where candidates with a relevant degree and foundational knowledge of regulatory frameworks are considered ahead of experienced hires. Many large New York employers such as hospital systems affiliated with Northwell Health or regional banks run rotational programs that include compliance exposure. Moving laterally from a paralegal, internal audit, or risk analyst position is also a common route, and earning a CCEP candidate designation while employed significantly strengthens early applications.
Where can I find and apply to compliance jobs in New York?
You can find and apply to compliance jobs in New York on Migrate Mate, which lists current openings across New York's financial services, healthcare, pharmaceutical, and insurance sectors. Find roles that fit your experience and apply directly to the employers posting them.
See All 265+ Compliance Jobs in New York
Find roles in New York that match your experience and apply in just a few clicks.
Find Compliance Jobs