20 часов назад
Security Compliance Analyst (Cybersecurity)
130 000 - 160 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Compliance Analyst (Cybersecurity): Building and owning an end-to-end security compliance program covering control catalogs, audit evidence, policies, GRC tooling, and third-party risk with an accent on SOC 2 Type II, ISO 27001, system scoping, and external audit readiness. Focus on translating frameworks into actionable engineering changes, automating evidence collection, defending scope decisions to assessors, and remediating audit findings in a high-growth manufacturing environment.
Location: Garden Grove, California, United States
Salary: $130,000–$160,000 USD annually
Company
is an American commercial electric vehicle company developing medium-duty electric vehicle and hybrid platforms.
What you will do
- Build and own the security compliance program, including the control catalog, implementation status, testing, evidence requirements, and framework crosswalks.
- Translate compliance requirements into actionable changes for engineering and business teams, then verify implementation and maintain corrective action plans.
- Manage recurring evidence collection and prepare for external audits and certification assessments, including readiness reviews, auditor walkthroughs, sample pulls, and remediation.
- Define and document system boundaries, scope decisions, control rationale, and audit outcomes in Jira or Confluence.
- Write and maintain security policies and procedures, administer Vanta integrations and mappings, and support security awareness and data-handling guidance.
- Conduct vendor and third-party security reviews and report compliance posture and audit readiness to security leadership.
Requirements
- 5+ years of experience in security compliance, GRC, or IT audit, including taking at least one framework from gap assessment through an external audit report or certification.
- Hands-on experience with SOC 2 Type II and/or ISO/IEC 27001, including certification audits with a fixed control catalog.
- Experience defining and defending system boundaries and scoping decisions to external assessors.
- Knowledge of NIST-based control catalogs, framework mappings, evidence chains, and controls for restricted or contractually protected data.
- Experience administering Vanta and working with Jira or Confluence.
- Bachelor’s degree in Information Systems, Cybersecurity, or a related field, or equivalent experience.
Nice to have
- CISA, CRISC, CompTIA Security+, or ISO 27001 Lead Auditor certification.
- Scripting ability in Python or JavaScript.
- Experience building compliance programs in a startup or high-growth environment.
Culture & Benefits
- Hands-on role in a fast-paced, high-growth manufacturing environment.
- Comprehensive health, dental, and vision coverage with 100% employee premiums covered.
- Early-stage stock options and retirement savings benefits, including 401(k), HSA, and FSA.
- Paid time off, parental leave, and an annual vacation bonus.
- Wellness, fertility, cell phone stipend, complimentary meals, and stocked kitchens.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
Sardine
2 дня назад
Security Compliance Lead (Fintech)
130 000 - 190 000$
5 дней назад
GRC Engineer (Cybersecurity)
200 000 - 250 000$
7 дней назад
Principal Security Governance, Risk & Compliance Analyst (AI Governance)
135 000 - 168 000$
5 часов назад
Regulatory & Security Compliance Analyst (Cybersecurity)
85 000 - 100 000$
3 дня назад
Risk Cyber Internal Audit Manager (Cybersecurity)
138 000 - 172 500$
16 часов назад
Senior GRC Analyst (SaaS)
183 000 - 205 000$