Назад
Company hidden
2 дня назад

Senior Information Security Specialist (Cybersecurity)

120 000 - 160 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Information Security Specialist (Cybersecurity/GRC): Strengthening enterprise-wide security posture through third-party risk management, security testing coordination, compliance support, and security policy development with an accent on operational security, regulatory frameworks, and cross-functional controls. Focus on managing vendor remediation, coordinating incident response and resilience exercises, and maturing security processes across cloud and hybrid environments.

Location: Remote, US

Salary: $120,000–$160,000 base salary per year

Company

hirify.global develops an adaptive cybersecurity platform that combines proprietary prevention engines and AI models to stop ransomware for mid-market and enterprise customers.

What you will do

  • Perform third-party risk assessments and track vendor remediation activities.
  • Coordinate security testing, vulnerability scans, penetration tests, and corrective action plans.
  • Collaborate with managed security service providers, engineering, operations, and internal stakeholders to monitor security events and implement security requirements.
  • Develop, maintain, and communicate information security policies, standards, procedures, and documentation.
  • Coordinate incident response planning, disaster recovery testing, and business continuity exercises.
  • Monitor and support technical and administrative security controls across cloud and hybrid environments.

Requirements

  • 5+ years of experience in information security, GRC, or IT risk management.
  • Strong understanding of cybersecurity concepts, controls, and risk frameworks.
  • Experience with third-party risk management, security testing, vulnerability management, regulatory compliance, and audit support.
  • Ability to assess and implement technical and administrative controls across cloud and hybrid environments.
  • Excellent communication, documentation, and cross-functional collaboration skills.
  • Experience with frameworks and regulations including SOC 2, ISO 27001, TX-RAMP, or FedRAMP.

Nice to have

  • Experience with Drata, Vanta, NIST 800-53, CIS Controls, DevSecOps, or secure software development practices.
  • Experience with Microsoft 365 or Google Workspace security configuration.
  • Exposure to HIPAA, GDPR, or CCPA environments.
  • Hands-on incident response or disaster recovery exercise experience.
  • CISSP, CISA, CISM, Security+, or similar certification.

Culture & Benefits

  • Remote-native, distributed global team.
  • Medical, dental, and vision coverage with premiums fully paid for employees and dependents.
  • Short- and long-term disability, life, AD&D, FSA, and 401(k) benefits.
  • Flexible PTO and parental leave.
  • Equity offerings.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →