Information Security and Compliance Analyst
- Coordinate and track SOX and ISO 27001 compliance efforts, including control reviews, evidence collection, process documentation, and internal readiness assessments
- Experience with security configuration and knowledge of cloud service administration including AWS and Azure
- Organize and conduct comprehensive searches to determine the applicability of data security policies to client contracts
- Serve as the point of contact for auditors and internal stakeholders during compliance reviews, ensuring clear and timely communication
- Maintain and organize a central repository of compliance documentation, policies, and procedures with a high standard of clarity and accuracy
- Review, triage, and analyze vulnerability findings from internal scans and external tools; prioritize and categorize based on risk and potential business impact.
- Work closely with IT and application owners to coordinate remediation efforts, follow up on open vulnerabilities, and ensure timely resolution
- Assist in developing security policies, procedures, and user guidance aligned with industry best practices
- Generate concise and meaningful reports and dashboards for internal leadership and auditors
- Track exceptions, manage control gaps, and help drive risk mitigation strategies
- Contribute to security awareness and training efforts by preparing clear documentation and guidance materials
- 3+ years of experience in information security, IT compliance, or related roles
- Demonstrated experience supporting or managing SOX, ISO 27001 or similar compliance activities
- Familiarity with vulnerability management tools
- Outstanding written communication skills, especially in drafting audit responses, procedures, and internal documentation
- Meticulous attention to detail, with a strong ability to manage and organize complex deadline-driven tasks
- Comfortable working independently in a remote or distributed team environment.
- Certifications such as CISA, ISO 27001 Implementation, CISSP, or Security+
- Experience working with compliance frameworks such as NIST, GDPR, or SOC 2
- Prior experience in a multinational or regulated environment.
- Familiarity with project tracking tools (e.g. JIRA, Confluence, SharePoint).
- This is a global role requiring frequent flexibility for meetings with US-based colleagues.
- Role may include occasional after-hours (or before-hours) support during incidents or critical remediation windows.
Work Environment and Expectations
- This is a global role requiring frequent flexibility for meetings with US-based colleagues
- Role may include occasional after-hours (or before-hours) support during incidents or critical remediation windows