6 часов назад
Regulatory & Security Compliance Analyst (Cybersecurity)
85 000 - 100 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Regulatory & Security Compliance Analyst (Cybersecurity): Operating Takt's security, privacy, and compliance programs with an accent on Vanta administration, SOC 2 and ISO 27001, GDPR, and customer security reviews. Focus on coordinating audits, maintaining audit-ready controls and privacy records, managing remediation, and reporting risks to leadership and the Board.
Location: Reston, Virginia, United States; in-office four days per week with one flexible remote day
Salary: $85,000–$100,000 gross annual
Company
is an AI-powered warehouse intelligence platform that unifies data from labor management systems, warehouse management systems, automation, robotics, and other operational systems to help retailers, 3PLs, and e-commerce companies optimize operations.
What you will do
- Operate the compliance program in Vanta, including controls, evidence, policies, risks, vendors, personnel, testing, and remediation.
- Manage continuous SOC 2 Type II activities and support ISO 27001 implementation and maintenance.
- Coordinate audits, assessments, penetration tests, certifications, findings, and remediation with internal owners and external partners.
- Serve as Data Protection Officer, maintaining GDPR, UK GDPR, records of processing, data inventories, agreements, privacy reviews, DPIAs, and data subject request processes.
- Coordinate responses to customer security and privacy questionnaires, RFPs, due diligence requests, and trust documentation requests.
- Present monthly compliance and privacy updates to leadership and escalate material issues to leadership or the Board when required.
Requirements
- 2–4 years of experience in risk advisory, technology risk, IT audit, cybersecurity risk, compliance, or a related field.
- Experience with controls, risk assessments, audit evidence, testing, or compliance frameworks.
- Familiarity with SOC 2, ISO 27001, ITGCs, cybersecurity controls, or similar frameworks.
- Strong analytical, written communication, organizational, and follow-up skills.
- Ability to work directly with technical teams, business stakeholders, auditors, and customers.
- Ability to work from the Reston office four days per week and independently perform DPO responsibilities with direct access to leadership and the Board.
Nice to have
- Experience with SOC 2 or ISO 27001 audits, ITGC, technology risk, cybersecurity, or privacy assessments.
- Familiarity with Vanta or another GRC platform.
- Experience with customer security questionnaires or third-party risk assessments.
- Exposure to GDPR or privacy compliance and experience with SaaS or cloud technology companies.
- Familiarity with Google Cloud Platform, Kubernetes, or modern cloud infrastructure.
Culture & Benefits
- Training, certifications, and development support in GDPR, CIPP/E, CIPM, ISO 27001, SOC 2, cloud security, and GRC.
- Close collaboration with the CTO, engineering leadership, outside counsel, auditors, and external privacy advisors.
- Opportunity to grow into 's internal security, privacy, and compliance subject-matter expert.
- Independent DPO function with direct and unrestricted Board access when necessary.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
21 час назад
Security Compliance Analyst (Cybersecurity)
130 000 - 160 000$
Sardine
2 дня назад
Security Compliance Lead (Fintech)
130 000 - 190 000$
21 час назад
Lead Security Analyst (AI Governance)
90 000 - 132 000$
TensorWave
3 дня назад
Governance, Risk & Compliance Manager (AI)
Decagon
7 дней назад
Governance, Risk, and Compliance Manager (AI Compliance)
190 000 - 275 000$
23 часа назад
Client Assurance & TPRM Manager - Assistant Vice President (Cybersecurity Risk)
100 000 - 140 000$