2 дня назад
Security Analyst III (SaaS)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Analyst III (SaaS): Executing GRC operations, third-party risk assessments, and compliance activities for corporate assets and web applications with an accent on vendor due diligence, customer trust, and security assurance. Focus on collecting SOC 2 and ISO 27001 audit evidence, identifying control gaps, improving security workflows, and coordinating risk management across Legal, Engineering, IT, Finance, and HR.
Location: Salt Lake City, Utah, United States; hybrid workplace with remote and office work depending on the needs of the role and team.
Company
develops visual collaboration and work acceleration products that help teams turn ideas into reality.
What you will do
- Conduct third-party vendor risk assessments and internal risk evaluations, documenting vulnerabilities and control gaps.
- Respond to vendor security questionnaires and support Sales and Customer Success with prospect security questions.
- Track and collect evidence for SOC 2 and ISO 27001 compliance audits and ensure compliance with applicable external regulations.
- Identify emerging threats and business risks, collaborating with senior security team members on practical solutions.
- Coordinate security awareness training and maintain security and compliance metrics for team dashboards.
- Partner with Legal, Engineering, IT, Finance, and HR to improve security controls, policies, and workflows.
Requirements
- Bachelor’s degree in information security assurance, business management, or a related field.
- 3+ years of experience with third-party risk management, GRC, customer due diligence, or related functions.
- Knowledge of security frameworks and principles such as NIST 800-53, ISO 27001, and SOC 2.
- Strong organizational skills, independence, and ability to manage deadlines with minimal daily oversight.
- Excellent verbal and written communication skills, including the ability to translate security concepts into clear documentation.
- Strong interpersonal skills and experience collaborating with technical and non-technical teams to resolve security risks.
Nice to have
- Experience in a modern SaaS or cloud-first technology company.
- Knowledge of risk management principles and practices.
- CRISC, CISSP, CISA, SSCP, CC, Security+, CySA+, or another relevant certification.
- Understanding of AWS, GCP, or Azure environments.
- Experience improving processes and automating GRC and Security Assurance workflows, including the use of AI tools.
Culture & Benefits
- Hybrid work combining remote and office work according to role and team needs.
- Values include teamwork, innovation, individual empowerment, initiative, ownership, and excellence.
- Inclusive workplace focused on respect and diverse perspectives.
- Security work supports rapid business and product adaptation through a risk and compliance mindset.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
InfoSec Analyst II, Trust (AI Governance)
96 000 - 160 000$
2 дня назад
Security Risk Analyst (AI)
3 дня назад
Security Engineer (AI Life Sciences)
6 часов назад
Cybersecurity Analyst, Security and AI Governance (AI)
100 000 - 120 000$
6 часов назад
Cybersecurity Analyst (Security and AI Governance)
100 000 - 120 000$
2 дня назад
Lead Security Analyst (AI Governance)
90 000 - 132 000$