IT Security, Risk & Compliance Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
IT Security, Risk & Compliance Analyst (Cybersecurity): Managing and improving internal enterprise security programs with an accent on GRC execution, internal controls, and endpoint security oversight. Focus on executing InfoSec controls, conducting vendor/client security evaluations, and triaging security events to strengthen organizational posture.
Location: Work From Home 100% or Hybrid/Onsite in Heredia, Costa Rica
Company
An American software development and technology advisory firm providing top-tier engineering talent for custom product development and staff augmentation.
What you will do
- Maintain and execute the periodic InfoSec controls calendar, monitoring patching, EDR status, and vulnerability scans.
- Coordinate with HR, IT, and Engineering teams to enforce security requirements and drive remediation.
- Develop and maintain IT security policies, standard operating procedures (SOPs), and user guidelines.
- Monitor, investigate, and triage security events at both endpoint and application levels.
- Perform security evaluations and risk questionnaires for third-party vendors and assist with client DDQs.
- Provide technical security advisory and organize security awareness training for end-users.
Requirements
- 3+ years of hands-on experience in Information Security, IT Audit, Technical Support, or GRC roles.
- English: Fluent (C1) written and spoken proficiency required for collaboration with international clients and teams.
- Familiarity with EDR platforms, MDM (e.g., Microsoft Intune), and patch management processes.
- Fundamental understanding of cloud ecosystems, SaaS tools, and baseline networking.
- Knowledge of major security frameworks such as SOC 2 and ISO 27001.
- Strong organizational skills and attention to detail for coordinating tasks across multiple departments.
Nice to have
- Experience implementing corporate security programs aligned with ISO 27001 or SOC 2.
- Certifications such as CompTIA Security+, Associate of ISC², or GIAC.
- Basic scripting skills in PowerShell, Python, or Bash for automation and evidence gathering.
Culture & Benefits
- Flexible work arrangement: 100% remote or office-based.
- Supportive and non-competitive team environment.
- Generous vacation schedule.
- Provision of a brand new laptop.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →