Somewhere in a compliance stack right now, an alert is sitting in a queue waiting for someone to decide whether it actually matters. That judgment call, made dozens of times a week, is a good chunk of what a Senior CCPA Compliance Analyst does, and it is why this role sits closer to security operations than most people expect from a compliance title.
CCPA compliance work sits at an odd intersection: half legal literacy, half security operations, and it rarely gets treated as a single discipline anywhere else. Here, both halves live under one role. A vulnerability that would normally stay purely technical instead needs to be weighed for what it means for a consumer's opt-out request, or whether a data-sharing agreement now needs updating. Neither half can really be handed off to a separate team without losing something in translation, which is part of why this position tends to sit senior rather than junior on an org chart.
We are hiring a senior analyst to join a fully remote team responsible for keeping consumer data practices aligned with CCPA requirements while also watching over the security tooling that protects that data day to day. You will not be tied to any office or city; this is a worldwide remote position, and the team already spans several time zones.
Expect your week to move between quiet documentation work and moments that require fast, clear-headed decisions. Some days are mostly reviewing logs and closing out low-priority tickets; other days bring an alert that needs to be escalated within minutes. Specific duties include:
A typical incident might start as a flagged login from an unfamiliar region on a system that stores consumer opt-out records. Before anything gets escalated, you would confirm whether the access pattern is a real threat or a false positive, check what data the account could actually touch, and note whether the incident triggers any CCPA notification obligations. That last step is easy to forget under pressure, and it is usually the one that matters most. Not every alert turns into an incident. Most resolve as routine, and learning to tell the difference quickly, without either overreacting or getting complacent, is a skill that takes months to build and years to sharpen.
This is a senior post, so we are looking for someone who has already spent real time in the trenches of compliance and security work, not someone starting out. You should have a bachelor's degree in computer science, information technology, or a closely related field, plus 42 months of hands-on experience in CCPA compliance work. Forty-two months is not an arbitrary cutoff; by that point most analysts have handled enough real incidents, not just tabletop exercises, to be trusted with the judgment calls this role requires without close supervision.
A CompTIA Security+ certification, or something comparable, is a plus rather than a requirement. If you have it, mention it; if you do not, that alone will not rule you out. Analysts coming from a pure security background sometimes need a short ramp-up on the compliance and legal-adjacent side of the job, and analysts coming from a pure compliance background often need the reverse. Either path works as long as the gap closes quickly.
You will work from wherever you already are, on your own equipment setup, checking in with the team through chat and video calls rather than a shared office. Because incident response cannot wait for everyone to log on at the same hour, the role does carry some on-call rotation, and you will need to be reachable during your assigned windows even outside a normal workday. Remoteroles works with employers who understand that remote arrangements only function well when availability expectations are spelled out clearly, and this posting is no exception. Overlap hours with the core team generally fall in the mid-morning to mid-afternoon range, though exact scheduling is worked out with your manager.
Most day-to-day coordination runs through a ticketing system and a dedicated incident channel, with a weekly team sync to review open items and near-misses. Nobody expects you glued to a screen outside your on-call window, but response time during that window is taken seriously. A monthly retro session looks back at incidents from the previous weeks, partly to improve response time and partly to spot patterns before they turn into a bigger problem. The CCPA landscape itself keeps shifting as amendments and related state laws pile on top of it, so part of the job is simply staying current, reading regulatory updates the way other roles read release notes.
This role pays 124,500 dollars a year, full-time, which sits toward the higher end for compliance analyst work given the seniority and on-call responsibilities involved. Beyond salary, the package includes:
That figure reflects both the CCPA specialization and the on-call expectation baked into the role; a general compliance analyst without that combination typically sees a lower range.
People who succeed in this role tend to have come up through either a security operations background or a compliance-heavy analyst role, and they are usually the type who would rather investigate an anomaly themselves than hand it off. If your last few years have involved CCPA work specifically, even better, since a lot of the documentation and reporting expectations here assume that context already. This is also a reasonable next step for someone eyeing a longer career path toward compliance management or a security leadership track, since the role touches both sides of that line.
Analysts who stay in this kind of role for a few years often find the CCPA specialization opens doors elsewhere too, since state-level privacy law is only expanding, not shrinking.
To apply, send your resume along with a short note on your CCPA and security tooling background. Applications are reviewed on a rolling basis, and shortlisted candidates can expect a first conversation within about two weeks of applying.