Назад
Company hidden
20 часов назад

Security Compliance Analyst (Cybersecurity)

130 000 - 160 000$
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Compliance Analyst (Cybersecurity): Building and owning an end-to-end security compliance program covering control catalogs, audit evidence, policies, GRC tooling, and third-party risk with an accent on SOC 2 Type II, ISO 27001, system scoping, and external audit readiness. Focus on translating frameworks into actionable engineering changes, automating evidence collection, defending scope decisions to assessors, and remediating audit findings in a high-growth manufacturing environment.

Location: Garden Grove, California, United States

Salary: $130,000–$160,000 USD annually

Company

hirify.global is an American commercial electric vehicle company developing medium-duty electric vehicle and hybrid platforms.

What you will do

  • Build and own the security compliance program, including the control catalog, implementation status, testing, evidence requirements, and framework crosswalks.
  • Translate compliance requirements into actionable changes for engineering and business teams, then verify implementation and maintain corrective action plans.
  • Manage recurring evidence collection and prepare for external audits and certification assessments, including readiness reviews, auditor walkthroughs, sample pulls, and remediation.
  • Define and document system boundaries, scope decisions, control rationale, and audit outcomes in Jira or Confluence.
  • Write and maintain security policies and procedures, administer Vanta integrations and mappings, and support security awareness and data-handling guidance.
  • Conduct vendor and third-party security reviews and report compliance posture and audit readiness to security leadership.

Requirements

  • 5+ years of experience in security compliance, GRC, or IT audit, including taking at least one framework from gap assessment through an external audit report or certification.
  • Hands-on experience with SOC 2 Type II and/or ISO/IEC 27001, including certification audits with a fixed control catalog.
  • Experience defining and defending system boundaries and scoping decisions to external assessors.
  • Knowledge of NIST-based control catalogs, framework mappings, evidence chains, and controls for restricted or contractually protected data.
  • Experience administering Vanta and working with Jira or Confluence.
  • Bachelor’s degree in Information Systems, Cybersecurity, or a related field, or equivalent experience.

Nice to have

  • CISA, CRISC, CompTIA Security+, or ISO 27001 Lead Auditor certification.
  • Scripting ability in Python or JavaScript.
  • Experience building compliance programs in a startup or high-growth environment.

Culture & Benefits

  • Hands-on role in a fast-paced, high-growth manufacturing environment.
  • Comprehensive health, dental, and vision coverage with 100% employee premiums covered.
  • Early-stage stock options and retirement savings benefits, including 401(k), HSA, and FSA.
  • Paid time off, parental leave, and an annual vacation bonus.
  • Wellness, fertility, cell phone stipend, complimentary meals, and stocked kitchens.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →