1 день назад
Senior Security Compliance Specialist (ISO 27001)
90 000 - 110 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Compliance Specialist (ISO 27001/ISMS): Managing and maintaining LaBella’s ISO 27001 certification and Information Security Management System with an accent on risk management, audit coordination, control ownership, and compliance reporting. Focus on developing security policies, maintaining GRC evidence and workflows, coordinating corrective actions, and integrating incident response and business continuity activities into the ISMS.
Location: Hybrid position based at the Rochester, New York office, United States
Salary: $90,000–$110,000 per year
Company
provides professional services and supports information security, operations, and compliance programs across its organization.
What you will do
- Manage the ISO 27001 and Information Security Management System (ISMS) program in cooperation with Security Operations, IT, Operations, and business leadership.
- Maintain security policies, processes, procedures, ISO 27001 documentation, document control sites, risk registers, and risk treatment plans.
- Coordinate internal and external ISO audits, collect evidence through the GRC platform, and track corrective action plans.
- Establish the ISMS control ownership model, including control owners, performers, approvers, review frequency, evidence requirements, and escalation paths.
- Coordinate ISMS objectives, metrics, KPIs, KRIs, compliance calendars, management reviews, access reviews, supplier reviews, and certification milestones.
- Integrate incident response, business continuity, disaster recovery, crisis management, and physical and digital security activities into the ISMS.
Requirements
- At least seven years of experience in security compliance or audit program management.
- Bachelor’s degree in cybersecurity management, technology compliance, technology program management, auditing, or a related field; directly related experience may substitute.
- Strong understanding of IT infrastructure, networking, security, and software development.
- Strong communication, organization, confidentiality, teamwork, and relationship-building skills.
- Ability to explain and communicate complex technical and compliance information to technical and non-technical audiences.
Nice to have
- PMP, CISSP, auditor, or ISO document control certification.
Culture & Benefits
- Flexible work schedule within a hybrid workplace.
- Health and dental insurance, 401(k) plan with employer match, paid time off, and paid parental leave.
- Short- and long-term disability coverage, profit sharing, and wellness support.
- Fitness and tuition reimbursement, leadership development, and referral bonus programs.
- Team-building and community service events, with a focus on diversity, equity, and inclusion.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Plaid
2 часа назад
Security Analyst, Third-Party Ecosystem Risk Management
119 000 - 176 000$
5 дней назад
GRC/IT Compliance Analyst
108 000 - 130 000$
5 часов назад
Manager - Information Security Compliance (Cybersecurity)
135 800 - 183 800$
2 часа назад
Senior IT Compliance & Governance Specialist (Project Advisory) (Cybersecurity)
129 000 - 129 000$
10 часов назад
Security Manager
120 000 - 200 000$
2 дня назад
Technology Risk & Compliance Analyst (Cybersecurity)
85 000 - 105 000$