Information Security and Compliance Specialist

Remote Full-time
Work collaboratively with internal Idera technology stakeholders regarding technology controls reviews and assessments. The scope of these activities will include participating with any related teams on a consultativebasis. ● Design, test, and document controls related to compliance with AICPA Trust Principles (SOC2) and ISO 27001 and 27701 requirements;● Gather audit evidence from company stakeholders to provide to assessors, coordinate scheduling of meetings between assessors and company stakeholders for audits;● Plan and execute internal and external audits to assess and evaluate potential technology risks and controls issues;● Curate audit findings into management reports and provide recommendations to stakeholders regarding remediation or mitigation of identified risks;● Work collaboratively to drive Idera’s risk management program which includes the identification, assessment, tracking and reporting of technology risks and status;● Execute continuous audit testing program and refine controls to support Testing automation;● Coordinate pentest scheduling with DevOps team and third-party or internal penetration testing team, vulnerability scans with Product Management and DevOps, and remediation of any findings with applicableteams;● Assist with risk assessments of third-party vendors;● Any other infosec-related compliance tasks identified.Experience Required:Experience with SOC 2 Type 2 and ISO 27001 and 27701 audits (mustHave or obtain at the time of hire - ISO 27001 internal auditor certification), performing internal audits (user access reviews, risk assessments; evaluating findings of penetration tests and vulnerability scans). Apply tot his job
Apply Now →

Similar Jobs

Senior Business Risk & Controls Advisor-Tech/Cyber (Remote)

Remote Full-time

GRC / Cyber Security Specialist

Remote Full-time

Cybersecurity Assessment / Authorization Specialist NIST RMF / Federal Compliance

Remote Full-time

Experienced GRC Professional for Cyber Protection – Third Party Risk Management & Compliance Specialist at blithequark

Remote Full-time

Technology Compliance Specialist

Remote Full-time

Experienced Cybersecurity Governance, Risk, and Compliance Specialist - Remote Data Entry and Risk Management Professional for blithequark

Remote Full-time

Information Assurance Compliance Specialist II (RMF Specialist)

Remote Full-time

Urgently Hiring: Secretary - ICT (Security & Audit Control)

Remote Full-time

Senior Federal Cybersecurity & Compliance Consultant

Remote Full-time

IT Auditor

Remote Full-time

FCRM Investigations and Reporting Analyst I (Hybrid)

Remote Full-time

905 - Principal Biostatistician - Medical Affairs, Oncology, Immunology, CV (Remote, US)

Remote Full-time

Mobile Game Developer Needed for Cute 2D Tapping Game (BooTap) – iOS & Android

Remote Full-time

Front-End Engineer / Angular / Music / Remote / Toronto

Remote Full-time

Early Career Trial Attorney, $10k Sign-on Bonus (Remote - California)

Remote Full-time

Vice President, Marketing

Remote Full-time

Sales Engineer, Film & Rigid Packaging - Remote in Midwest

Remote Full-time

Senior iOS Engineer - Music job at Spotify in New York, NY

Remote Full-time

Enterprise Data Architect, Lead @ Pinnacle

Remote Full-time

Experienced Data Analytics Engineer for Apple Services – Big Data, Cloud, and Artificial Intelligence Expertise Required

Remote Full-time
← Back to Home