Назад
Company hidden
3 дня назад

ISO27001 Compliance Analyst (Cybersecurity)

147 000 - 232 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
ISO27001 Compliance Analyst (Cybersecurity): Maintaining continuous compliance with the ISO 27001:2022 framework by implementing, assessing, and auditing security practices and technical configurations with an accent on ISMS activities, risk management, and control effectiveness. Focus on developing control testing programs, leading internal audits and certification reviews, and resolving security and data issues across cloud and on-premise environments.

Location: Carlsbad, California; US citizenship required

Salary: $147,000–$232,000 annually. For specific locations in San Jose, the San Francisco Bay Area, and the New York City metropolitan area: $183,000–$274,000 annually.

Company

hirify.global delivers communication connectivity for consumers, businesses, governments, and militaries worldwide.

What you will do

  • Maintain continuous compliance with the ISO 27001:2022 framework and applicable security regulations and standards.
  • Facilitate ISO 27001 ISMS activities as a second line of defense and advise on company systems.
  • Develop, maintain, and automate security, risk, and compliance documentation, including exceptions and alternative controls.
  • Design and implement control-effectiveness testing programs for ISO 27001 compliance.
  • Lead security control ownership across ISO 27001 Annex A requirements and support engineering and IT changes.
  • Lead internal audits and coordinate external certification reviews, including finding assessment and follow-up.

Requirements

  • 8+ years of experience in risk and compliance and 8+ years working with ISO 27001:2022 auditing or control implementation.
  • ISMS Lead Auditor or Lead Implementer certification, or the ability to obtain certification after joining.
  • Experience preparing development teams for IT framework controls and managing several simultaneous efforts.
  • Deep knowledge of enterprise security laws, regulations, risk management, and governance controls.
  • Broad knowledge of infrastructure, networking, security, endpoint, cloud, and on-premise technologies.
  • Experience with a GRC tool and ability to travel up to 40%.

Nice to have

  • BA, BS, or equivalent experience in a related field.
  • Security and audit certifications such as CISA, CIA, CISM, CISSP, SANS, or CPA.
  • Experience with PCI DSS, NIST SP 800-171, CMMC, or IT SOX audits.
  • Project management experience and mature knowledge of applications, integrations, operations, and business processes.

Culture & Benefits

  • Inclusive and diverse work environment.
  • Medical, financial, and other benefits may be included depending on the position.
  • Additional cash or stock incentives may be available.
  • Benefits focus on holistic health and wellness.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →