Your Role
You will be a key member of our Security & IT Compliance Team that is responsible for maintaining the security and integrity of all company data. You will ensure that the organization’s information, technology systems, processes, and practices comply with relevant laws, regulations, and industry standards.
Your Responsibilities
- Develop and implement IT compliance policies and procedures based on both regulatory requirements and industry best practices.
- Assist with risk assessments to identify potential compliance gaps and/or vulnerabilities within our current IT systems and processes.
- Work closely with the company’s Risk Officer, CIO, and CISO to perform audits and assessments to monitor compliance with internal policies and external regulators.
- Raise awareness about compliance requirements and best practices through training company employees.
- Manage third-party vendors and service providers to ensure they comply with strict IT compliance requirements.
- Develop and implement procedures for responding to IT compliance breaches or incidents, including investigating and reporting on such incidents.
- Respond to due diligence requests from internal and external customers.
- Ensure compliance with company policies and controls.
Required Experience, Skills, and Qualifications
- Bachelor’s degree
- 3-5 years of progressive experience
- Knowledge of relevant regulations and standards
- Knowledge of conducting audits and assessments to evaluate compliance
- Knowledge of network routing and IP protocol, secure application coding, firewall rule management, AV/Spyware tools, data leakage protection concepts and tools, and AWS and Azure cloud-based solutions
- Verbal and written communication skills to present and articulate compliance requirements to stakeholders at all levels of the organization, both technical and nontechnical audiences
- Analytical and problem-solving skills
- Ability to develop and implement policies and procedures
- Project management skills, including planning, organizing, and coordinating necessary activities
- Computer security incident response skills
- Understanding of vulnerability and penetration testing concepts
- Ability to assess and mitigate risks, including identifying vulnerabilities and implementing necessary controls
- Ability to collaborate effectively with cross-functional teams to get buy-in for compliance initiatives across the company
- Ability to obtain a CISSP (Certified Information Systems Security Professional)
- Ability to obtain a CISA (Certified Information Systems Auditor)
- Ability to multitask within tight deadlines; self-directed and results/goal oriented
- Excellent attention to detail