Senior Security Compliance Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security Compliance Engineer: Ensuring the security of software and infrastructure by maintaining compliance with industry standards and regulations with an accent on PCI DSS, ISO/IEC 27001, SOC 2, NIST, and GDPR. Focus on performing security risk assessments, developing security policies, and supporting audits to protect customers.
Location: Remote
Company
is the world’s first RiskOps platform for financial risk management, safeguarding global commerce with a cloud-based risk management platform powered by machine learning and artificial intelligence.
What you will do
- Ensure compliance with core applicable standards and regulations (PCI DSS, ISO/IEC 27001 and 27701, SOC 2, NIST, GDPR) and participate in the audit processes.
- Support clients, vendors, and regulatory audits, assessments, and information security requests.
- Review, implement, and oversee the effectiveness of 's security framework.
- Perform security risk assessments and provide prioritized remediation recommendations.
- Develop, review, and maintain policies, processes, and standards to ensure compliance with internal and legal regulations and requirements.
Requirements
- Knowledge of compliance and regulatory frameworks (PCI DSS, ISO/IEC 27001, SOC 2, NIST, CIS, GDPR, etc.).
- Understanding of cloud security concepts (e.g.: Amazon Web Services (AWS) IAM, GCP or Azure security principles, etc.) and integrating security controls through DevOps and Infrastructure as a Service (IaaS) techniques.
- Excellent communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner.
Nice to have
- Knowledge of container orchestration systems such as Kubernetes is welcomed.
- Experience working with Generative AI (GenAI) tools is a plus.
Culture & Benefits
- Immersed in our brand with training, connections, and one-on-one time with your manager.
- Access to a ton of information to give you history, context, and all the knowledge you can handle about and the team.
- Start working on projects and collaborating on work currently being done.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →