Information Security and Compliance Manager
You will prepare for and operate information-security certifications, manage security and privacy regulations, and deliver employee awareness training. You will handle privacy-protection work, review relevant domestic and international laws, and monitor security equipment and solutions while coordinating follow-up actions.
Responsibilities
- Prepare for and operate ISMS-P, ISO 27001, and SOC 2 Type II certifications
- Create, revise, and manage information-security and privacy regulations and guidelines
- Deliver information-security and privacy training
- Perform privacy-protection work, including privacy policies, letters of consent, privacy impact assessments, and vendor management
- Review and respond to domestic and international information-security and privacy laws
- Monitor security equipment and solutions and take follow-up actions
Requirements
- Four to eight years of information-security and privacy experience
- Experience performing privacy-protection work
- Practical experience with information-security management systems, privacy protection, or security compliance
- Experience responding to internal or external audits, certification assessments, or customer security reviews
- Experience automating privacy-protection work
- Experience reviewing and responding to GDPR or APPI
- Experience operating firewalls, WAF, IPS, DLP, or NAC solutions
- Cloud or SaaS security experience