Information Security Analyst II (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Information Security Analyst II (Cybersecurity): Supporting security compliance frameworks and audit initiatives with an accent on automation and scaling GRC workflows. Focus on building automated evidence collection methods from infrastructure and pipelines using Python, Go, and AI tools.
Location: Hybrid in New York, NY, USA. Candidates must be eligible for required authorizations from the US government to conform to US export control regulations.
Salary: $123,000 — $157,000 USD
Company
is a monitoring and security platform for cloud-scale applications.
What you will do
- Own and execute the full audit lifecycle from scoping and control mapping through evidence collection to final report delivery.
- Translate complex regulatory and customer standards into concrete requirements for Engineering, Legal, and Business teams.
- Utilize AI tools and scripting in Python and/or Go to accelerate evidence collection, control testing, and compliance workflow development.
- Design and build automated evidence collection methods from AWS infrastructure and pipelines.
- Manage expectations and serve as a key liaison between internal teams and internal/external auditors.
- Evaluate and adopt emerging GRC technologies to mature the compliance program.
Requirements
- 2-5 years of experience in risk management, security, compliance, or auditing with hands-on control experience.
- Experience managing security compliance for SaaS-based tech (AWS, GCP, Azure, etc.).
- Thorough understanding of security compliance frameworks such as FedRAMP, PCI-DSS, SOX, ISO 27001, or SOC.
- Proficiency in using terminal and CLI tools to query infrastructure and automate tasks.
- Proven ability to translate complex technical controls into language for both business and engineering audiences.
- Eligibility for US government authorizations to comply with US export control regulations.
Culture & Benefits
- Competitive compensation including new hire stock equity (RSUs) and employee stock purchase plan (ESPP).
- Comprehensive healthcare, dental, parental planning, and mental health benefits.
- 401(k) plan with company match.
- Hybrid workplace model designed for work-life harmony.
- Continuous professional development, product training, and an intradepartmental mentor/buddy program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →