Назад
Company hidden
2 дня назад

Information Security Operations Specialist

130 000 - 155 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Operations Specialist (SaaS/Security Compliance): Supporting risk assessments, internal controls, audit evidence, and security compliance for a SaaS platform processing financial-crime data with an accent on SOC 2, PCI, NIST, ISO 27001, and data privacy requirements. Focus on translating complex network and technical architecture into auditor-ready documentation, interviewing technical stakeholders, and maintaining policies and controls across a fast-paced Agile environment.

Location: Palo Alto, California, with a hybrid mix of working from home and in the office; regular in-person touchpoints are required. Must be legally authorized to work in the United States without employer sponsorship, now or in the future.

Salary: $130,000–$155,000 base salary per year.

Company

hirify.global is a SaaS and data science technology company that uses AI to help financial institutions and government agencies detect money laundering, fraud, criminal networks, and foreign influence.

What you will do

  • Support risk assessments for business and technical processes and systems.
  • Maintain and improve the internal control environment supporting technology risk management and regulatory compliance.
  • Create, review, and update technical security policies, procedures, and compliance documentation.
  • Interview Engineers and Data Scientists to produce auditor-ready responses to complex security compliance questionnaires.
  • Write technical narratives and annotate network architecture diagrams covering switching, routing, VLAN segmentation, and secure data transfer and storage.
  • Coordinate compliance milestones, evidence submissions, customer and vendor management, and collaboration with technical and business stakeholders.

Requirements

  • Bachelor’s degree in a technical field and 3+ years of experience in a security compliance role.
  • Professional audit or information security certification such as CISA, CISSP, CRISC, or CISM.
  • Strong technical writing, verbal communication, and stakeholder-mapping skills.
  • Experience assessing risks and controls for multi-tenant SaaS architectures, including SOC 2 or PCI controls and auditor evidence submission.
  • Experience with NIST frameworks, ISO 27001, data privacy compliance concepts including GDPR, CCPA, and CPRA, and formal SDLC and change control policies.
  • Must be legally authorized to work in the United States without employer sponsorship, now or at any time in the future.

Nice to have

  • Experience with JIRA and Confluence.
  • Familiarity with Drata or another security assurance platform.
  • Exposure to CMMC and FISMA.

Culture & Benefits

  • Hybrid work environment with flexible work arrangements and regular in-person collaboration.
  • Supportive, collaborative environment focused on learning and professional growth.
  • Flexible vacation and paid time off with an emphasis on work-life balance.
  • Company equity and an exceptional benefits package.
  • Employer-matched 401(k) plan.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →