Security Compliance Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Security Compliance Analyst (Cybersecurity): Managing the risk management program and overseeing internal and external audits for a leading AI solutions provider with an accent on GRC frameworks and regulatory compliance. Focus on building a comprehensive Governance, Risk and Compliance program and optimizing technology process controls in collaboration with engineering teams.
Location: San Francisco
Salary: $110,000 - $140,000
Company
is a leading provider of cloud-based AI solutions that empower organizations to understand, search, and generate content at scale.
What you will do
- Manage the company's risk management program and lead both internal and external audits.
- Implement and build a comprehensive ISMS and Governance, Risk and Compliance (GRC) program.
- Collaborate with Engineering and Product teams to improve change management and access management controls.
- Perform cybersecurity risk assessments to safeguard the business.
- Define and maintain privacy policies ensuring compliance with applicable laws and regulations.
- Oversee security and privacy training programs.
Requirements
- Bachelor's degree or equivalent professional experience.
- Minimum 4+ years of experience conducting risk-based assessments for information systems.
- Minimum 1+ years of experience running a comprehensive GRC program.
- Minimum 2+ years of experience leading ISO 27001 or SOC 1/2 audits.
- Strong knowledge of CCPA/CPRA and GDPR.
- Ability to communicate complex security concepts to both technical and non-technical audiences.
Culture & Benefits
- Opportunity to work at one of the fastest-growing AI startups in San Francisco.
- High-impact role where work directly influences the company's development.
- Steep learning curve in a competitive and ambitious environment.
- Competitive base salary and potential for stock options.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →