Назад
Company hidden
обновлено 4 дня назад

Sr. Security Compliance Analyst - PCI DSS & SOC 2 (East Coast)

119 078 - 174 648$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Security Compliance Analyst - PCI DSS & SOC 2 (East Coast) (PCI DSS, SOC 2, GRC): Leading continuous compliance monitoring, audit readiness, control testing, and remediation across cloud, on-premises, and hybrid environments with an accent on PCI DSS certification, SOC 2 control execution, and evidence-driven compliance operations. Focus on coordinating third-party audits, translating requirements into actionable controls, and driving closure of security and control deficiencies.

Location: Fully remote for U.S.-based candidates; U.S. citizenship required.

Salary: $119,078–$174,648 per year, plus eligibility for a discretionary annual incentive plan.

Company

hirify.global provides identity-centric security solutions and technologies for government agencies, enterprises, and financial institutions in more than 150 countries.

What you will do

  • Lead PCI DSS compliance activities, certification efforts, readiness assessments, and continuous monitoring across multiple environments.
  • Support the SOC 2 program through control design, testing, evidence collection, and control effectiveness measurement.
  • Prepare for and coordinate third-party audits, respond to auditor requests, and track remediation activities.
  • Translate security and compliance requirements into actionable controls for engineering and operations teams.
  • Partner with control owners, service providers, hosting partners, Security, Engineering, and Product teams to align shared controls.
  • Identify compliance risks and control deficiencies, maintain policies and evidence artifacts, and drive findings to closure.

Requirements

  • 5+ years of experience in security compliance, audit, or GRC, including administrative, technical, and physical controls.
  • Hands-on technical and audit experience with PCI DSS and SOC 2 compliance.
  • Experience with cloud environments, shared responsibility models, SaaS or cloud-native environments, and cross-functional infrastructure work.
  • Strong understanding of access control, change management, logging and alerting, vulnerability management, and related security domains.
  • Ability to work across multiple time zones with virtual global teams.
  • Must be a U.S. citizen and based in the United States.

Nice to have

  • Experience with PCI CP, FedRAMP, ISO 27001, or other compliance frameworks.
  • Experience with modern GRC platforms, control automation, and continuous compliance models.
  • Certifications such as CISSP, CISA, CISM, CRISC, PCI ISA, QSA, or PCIP.

Culture & Benefits

  • Remote and flexible work options with a collaborative, inclusive environment.
  • Career growth initiatives, learning opportunities, and education reimbursement.
  • Medical, vision, dental, life and disability insurance, mental health coaching, and virtual fitness programs.
  • 401(k) matching, paid personal time off, 12 paid holidays, and parental leave.
  • Focus on diversity, inclusion, respect, and global affinity groups.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →