2 дня назад
Information Security Analyst (AI Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Analyst (AI Cybersecurity): Supporting customer security reviews, vendor risk assessments, compliance activities, and risk management for an AI-powered cybersecurity platform with an accent on security assurance, regulatory frameworks, and technical risk communication. Focus on completing complex assessments, resolving compliance alerts in Vanta, improving risk and compliance processes, and coordinating remediation across technical and business teams.
Location: Remote in Europe or the UK; regular opportunities to meet colleagues in person
Company
is a cybersecurity company building an autonomous AI-powered penetration testing platform that identifies and responsibly discloses real-world vulnerabilities.
What you will do
- Complete technical security questionnaires, risk assessments, and customer due-diligence requests.
- Explain security controls, architecture, and compliance posture to Sales, Customer, and external stakeholders.
- Assess and manage third-party and SaaS vendor security risks.
- Investigate and resolve compliance alerts using Vanta.
- Maintain risk registers, policies, evidence, assessment frameworks, and remediation tracking.
- Support SOC 2, FedRAMP 20x, ISO 27001, ISO 42001, audits, and internal assurance activities.
Requirements
- 7+ years of experience in risk, compliance, security assurance, or related roles.
- Hands-on experience in Engineering, IT, or operational security.
- Experience completing or reviewing technical security questionnaires and customer risk assessments.
- Experience with security and data protection frameworks including SOC 2, ISO 27001, NIST, GDPR, and HIPAA.
- Experience conducting vendor or third-party risk assessments, with strong written communication and organizational skills.
- Comfort working in a fast-moving, remote-first startup environment and using modern AI tooling to improve productivity while managing risk.
Nice to have
- Experience in a SaaS or security-focused company.
- Experience handling GDPR Subject Access Requests.
- CRISC, CISSP, or other security and risk certifications.
- Knowledge of cloud security best practices.
Culture & Benefits
- Full-time position with competitive salary and meaningful stock options.
- Remote-first work in the UK or EU with regular in-person collaboration opportunities.
- Opportunity to work with security and AI specialists on complex technical challenges.
- Individual contributor role with potential to grow in scope as the risk and compliance function matures.
Hiring process
- Talent introduction.
- GRC and Security Knowledge Interview focused on practical security and GRC experience.
- Hiring Manager Interview with a member of the leadership team.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →