Responsibilities
- Coordinate and track SOX and ISO 27001 compliance activities, including control reviews, evidence collection, process documentation, and internal readiness assessments.
- Apply experience with security configuration and cloud service administration, including AWS and Azure.
- Organize and conduct thorough searches to determine how data security policies apply to client contracts.
- Serve as the primary contact for auditors and internal stakeholders during compliance reviews, ensuring clear and timely communication.
- Maintain and organize a central repository of compliance documentation, policies, and procedures with high clarity and accuracy.
- Review, triage, and analyze vulnerability findings from internal scans and external tools, prioritizing and categorizing based on risk and potential business impact.
- Collaborate with IT and application owners to coordinate remediation efforts, follow up on open vulnerabilities, and ensure timely resolution.
- Assist in developing security policies, procedures, and user guidance aligned with industry best practices.
- Generate concise and meaningful reports and dashboards for internal leadership and auditors.
- Track exceptions, manage control gaps, and help drive risk mitigation strategies.
- Contribute to security awareness and training efforts by preparing clear documentation and guidance materials.
Requirements
- 3+ years of experience in information security, IT compliance, or related roles.
- Demonstrated experience supporting or managing SOX, ISO 27001, or similar compliance activities.
- Familiarity with vulnerability management tools.
- Outstanding written communication skills, especially in drafting audit responses, procedures, and internal documentation.
- Meticulous attention to detail with a strong ability to manage and organize complex, deadline-driven tasks.
- Comfortable working independently in a remote or distributed team environment.
- Bachelor's Degree in Computer Science, MIS, or a related field.
Nice to Have
- Certifications such as CISA, ISO 27001 Implementation, CISSP, or Security+.
- Experience working with compliance frameworks such as NIST, GDPR, or SOC 2.
- Prior experience in a multinational or regulated environment.
- Familiarity with project tracking tools such as JIRA, Confluence, or SharePoint.
Work Arrangement
Remote (Worldwide)
Other
- This is a global role requiring frequent flexibility for meetings with US-based colleagues.
- Role may include occasional after-hours or before-hours support during incidents or critical remediation windows.