Назад
Company hidden
6 часов назад

Regulatory & Security Compliance Analyst (Cybersecurity)

85 000 - 100 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Regulatory & Security Compliance Analyst (Cybersecurity): Operating Takt's security, privacy, and compliance programs with an accent on Vanta administration, SOC 2 and ISO 27001, GDPR, and customer security reviews. Focus on coordinating audits, maintaining audit-ready controls and privacy records, managing remediation, and reporting risks to leadership and the Board.

Location: Reston, Virginia, United States; in-office four days per week with one flexible remote day

Salary: $85,000–$100,000 gross annual

Company

hirify.global is an AI-powered warehouse intelligence platform that unifies data from labor management systems, warehouse management systems, automation, robotics, and other operational systems to help retailers, 3PLs, and e-commerce companies optimize operations.

What you will do

  • Operate the compliance program in Vanta, including controls, evidence, policies, risks, vendors, personnel, testing, and remediation.
  • Manage continuous SOC 2 Type II activities and support ISO 27001 implementation and maintenance.
  • Coordinate audits, assessments, penetration tests, certifications, findings, and remediation with internal owners and external partners.
  • Serve as Data Protection Officer, maintaining GDPR, UK GDPR, records of processing, data inventories, agreements, privacy reviews, DPIAs, and data subject request processes.
  • Coordinate responses to customer security and privacy questionnaires, RFPs, due diligence requests, and trust documentation requests.
  • Present monthly compliance and privacy updates to leadership and escalate material issues to leadership or the Board when required.

Requirements

  • 2–4 years of experience in risk advisory, technology risk, IT audit, cybersecurity risk, compliance, or a related field.
  • Experience with controls, risk assessments, audit evidence, testing, or compliance frameworks.
  • Familiarity with SOC 2, ISO 27001, ITGCs, cybersecurity controls, or similar frameworks.
  • Strong analytical, written communication, organizational, and follow-up skills.
  • Ability to work directly with technical teams, business stakeholders, auditors, and customers.
  • Ability to work from the Reston office four days per week and independently perform DPO responsibilities with direct access to leadership and the Board.

Nice to have

  • Experience with SOC 2 or ISO 27001 audits, ITGC, technology risk, cybersecurity, or privacy assessments.
  • Familiarity with Vanta or another GRC platform.
  • Experience with customer security questionnaires or third-party risk assessments.
  • Exposure to GDPR or privacy compliance and experience with SaaS or cloud technology companies.
  • Familiarity with Google Cloud Platform, Kubernetes, or modern cloud infrastructure.

Culture & Benefits

  • Training, certifications, and development support in GDPR, CIPP/E, CIPM, ISO 27001, SOC 2, cloud security, and GRC.
  • Close collaboration with the CTO, engineering leadership, outside counsel, auditors, and external privacy advisors.
  • Opportunity to grow into hirify.global's internal security, privacy, and compliance subject-matter expert.
  • Independent DPO function with direct and unrestricted Board access when necessary.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →