Forma

Compliance Analyst (contract)

United States

Not SpecifiedCompensation
Junior (1 to 2 years)Experience Level
Full TimeJob Type
UnknownVisa
Financial Services, Software & Technology, Health & BenefitsIndustries

Position Overview

  • Location Type: Remote
  • Job Type: Full-Time (Temporary, 4 months)
  • Reports to: Director of Security and IT

Forma is revolutionizing the employee benefits market by offering flexible benefits software that allows companies to provide competitive packages while reducing costs. The platform enables employees to choose how they spend their benefit allowances through The Forma Store, The Forma Visa Card, or reimbursement. Forma serves hundreds of renowned companies, including Stripe, Zoom, Lululemon, and Affirm, with a high customer retention rate and strong satisfaction scores.

About the Role

Forma is seeking a Compliance Analyst to maintain, scale, and operationalize its compliance programs across SOC 2, HIPAA, PCI DSS, and privacy frameworks like GDPR and CCPA. This role is crucial for supporting the sales process by completing customer RFPs and security questionnaires, demonstrating Forma's commitment to security and privacy. The Compliance Analyst will collaborate with InfoSec, Legal, Sales, and Product teams to build customer trust and ensure the platform adheres to the highest security, compliance, and transparency standards.

Responsibilities

  • Own and manage ongoing compliance efforts for SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and CCPA.
  • Maintain and update security and privacy policies, documentation, and evidence for audits and regulatory requirements.
  • Lead coordination and responses for third-party audits, risk assessments, and compliance reviews.
  • Support security incident response planning, tracking of corrective actions, and remediation activities.
  • Partner with Legal and Product teams to assess the regulatory impact of new features, vendors, and jurisdictions.
  • Collaborate with Sales and Customer Success teams to respond to security RFPs, due diligence questionnaires, and client assessments.
  • Own and update a knowledge base of standardized security responses and documentation for efficient RFP and questionnaire handling.
  • Conduct vendor security and privacy assessments, ensuring appropriate controls and agreements are in place.
  • Educate internal stakeholders on security and data protection best practices through training and documentation.
  • Stay current on evolving security standards, privacy laws, and industry trends.

Preferred Skills

  • 5-8 years of experience in security compliance, GRC, data privacy, or legal/compliance roles at a SaaS or fintech company.
  • Hands-on experience with SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, and CCPA frameworks.
  • Familiarity with compliance tools such as Vanta, Drata, OneTrust, TrustArc, or equivalents.
  • Demonstrated success in completing RFPs, security questionnaires, and supporting enterprise client audits.
  • Strong written communication skills, with the ability to explain complex security concepts to non-technical audiences.
  • Excellent attention to detail, organization, and ability to manage multiple priorities concurrently.
  • Bachelor's degree in Information Security, Legal Studies, Business, or a related field.

Skills

SOC 2
HIPAA
PCI DSS
GDPR
CCPA
Security frameworks
Privacy frameworks
Customer RFPs
Security questionnaires
Cross-functional collaboration

Forma

Flexible employee benefits management platform

About Forma

Forma provides a flexible benefits platform designed for HR teams and employers to enhance their employee benefits offerings, particularly in remote and hybrid work settings. The platform allows employers to tailor a variety of benefits to meet the specific needs of their employees, promoting higher utilization and satisfaction. Forma addresses common HR challenges, such as underutilization of benefits, by simplifying access and increasing awareness among employees. Additionally, the platform includes tools for monitoring compliance and risk, ensuring that companies adhere to relevant regulations. Unlike many competitors, Forma focuses on flexibility and accessibility, making it easier for organizations to create a healthier and more engaged workforce. The goal of Forma is to transform employee benefits management, providing a beneficial solution for both employers and employees.

San Francisco, CaliforniaHeadquarters
2017Year Founded
$38.9MTotal Funding
SERIES_BCompany Stage
Consulting, Social Impact, EducationIndustries
201-500Employees

Benefits

Remote Work Options
Health Insurance
Dental Insurance
Vision Insurance
Wellness Program
Home Office Stipend
401(k) Retirement Plan
Unlimited Paid Time Off
Parental Leave

Risks

Emerging startups with similar platforms could reduce Forma's market share.
Economic downturns may lead to reduced spending on employee benefits.
Data privacy concerns could undermine trust in Forma's platform.

Differentiation

Forma offers a curated vendor collection with preferred pricing, eliminating reimbursement hassles.
The platform provides flexible benefits tailored to remote and hybrid work environments.
Forma ensures compliance with regulations through continuous risk and compliance monitoring tools.

Upsides

Growing demand for personalized benefits boosts Forma's market potential.
Remote work trends increase the need for flexible benefits platforms like Forma.
Advancements in AI enable Forma to offer more personalized benefits solutions.

Land your dream remote job 3x faster with AI