About this role.
CertiK is seeking a Compliance Engineer to own first-line review of AI-generated compliance outputs and client-facing regulatory deliverables. The role covers regulatory-framework analysis, licensing readiness, gap assessments, evidence collection, policy review, application preparation, and remediation tracking. The employee will partner with Engineering to turn recurring compliance activities into structured workflows, regulatory mappings, templates, and evaluation cases. This is a client-facing legal and compliance role requiring experience in financial services, fintech, digital assets, or regulatory consulting, with escalation of high-risk conclusions to senior Compliance or Legal.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Job Complexity
4/5Pace & Pressure
4/5Autonomy Level
4/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would explain the applicable regulatory perimeter, how I identified required evidence and policies, coordinated stakeholders, tracked gaps and remediation, and prepared materials for submission or senior review. I would also describe how I maintained a clear audit trail for each requirement and supporting document.
I would validate the regulatory sources, jurisdiction, assumptions, and applicability of each conclusion. I would check that citations and evidence are traceable, identify unsupported claims or hallucinations, compare the output with current requirements, and escalate material interpretations or final conclusions to qualified senior Compliance or Legal reviewers.
I would first clarify the client, jurisdiction, product activity, intended use, deadline, and decision required. I would document assumptions, provide a scoped initial assessment with clearly stated limitations, prioritize the highest-risk issues, and promptly escalate matters that require legal interpretation.
I would break the work into repeatable inputs, decision points, source requirements, review criteria, outputs, and escalation triggers. I would then work with Engineering to build structured mappings and templates, create representative evaluation cases, test accuracy against expert-reviewed examples, and iterate based on failure patterns.
I would map the business model and activities to the licensing framework, identify applicable governance, AML, sanctions, custody, security, consumer-protection, and reporting requirements, and request evidence for each control. I would assess design and implementation gaps, rank remediation by regulatory risk and submission impact, assign owners and timelines, and track closure through documented evidence.
About the Company
Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications through cutting-edge security research, formal verification, and AI-powered technology. Founded in 2017 and headquartered in New York City, CertiK provides end-to-end security solutions including smart contract audits, penetration testing, on-chain monitoring, incident response, and compliance services for some of the largest projects in the digital asset ecosystem.
Today, CertiK supports thousands of enterprise clients and Web3 projects globally, with a distributed international team spanning North America, Asia, and Europe. The company is backed by leading investors including Coatue, Goldman Sachs, Insight Partners, and Sequoia Capital, and has been recognized by organizations such as the World Economic Forum and CB Insights for its contributions to blockchain security innovation.
About You
You are a hands-on compliance professional who understands how regulatory frameworks and licensing applications work from initial scoping through final submission readiness. You can turn complex regulations into clear guidance and client deliverables, manage both structured audit requests and fast-changing BD needs, and know when an issue requires escalation to senior Compliance or Legal.
About the Role
You will be the first-line compliance owner for AI outputs and related client deliverables. You will support stakeholder groups including client-facing teams and commercial services. You will turn the raw AI output into accurate and usable deliverables, and work as/with Engineering to convert recurring compliance work into reusable workflows and knowledge assets.
Responsibilities
- Analyze and decompose regulatory frameworks and licensing requirements.
- Support licensing and regulatory-readiness projects, including scoping, applicability analysis, gap assessment, evidence requests, policy review, application preparation, and remediation tracking.
- Conduct first-line review of AI outputs for regulatory accuracy, evidence support, source traceability, and client suitability.
- Convert unstructured requests into clear scopes and deliverables, including compliance analyses, and review reports.
- Support compliance guidance, evidence checklists, submission-material mapping, and licensing deliverables.
- Work as/with Engineering to build regulatory mappings, templates, review rules, evaluation cases, and structured AI workflows.
- Escalate high-risk regulatory interpretations and final legal or compliance conclusions to senior reviewers or Legal.
Requirements
- 3 or more years of Engineering experience in compliance, regulatory consulting, digital assets, fintech, financial services, compliance audit, or a law firm.
- Hands-on experience with at least 1 licensing application, regulatory registration, or end-to-end regulatory-readiness project.
- Strong understanding of regulatory analysis, evidence review, and licensing documentation.
- Ability to produce clear guidance, mappings, presentations, and client reports.
- Strong client communication and cross-functional project-management skills.
- Ability to manage urgent and ambiguous requests from client-facing team while maintaining quality.
- Strong written and spoken English; professional Chinese proficiency is preferred but not required.
- Familiarity with digital-asset regulation, VASP licensing or similar frameworks is preferred.
- Basic understanding of LLM limitations, hallucination risk, source traceability, and human-in-the-loop review.
Compensation
Additional Information
This role must be performed outside the United States. We are unable to consider candidates who will work from within the U.S.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.





