Governance & Compliance Security Analyst at EdgeUno improving information security and ISO 27001 compliance. Collaborating with teams to maintain an effective Information Security Management System.
Responsibilities
Maintain and update the Information Security Management System (ISMS) in line with ISO/IEC 27001
Coordinate periodic risk assessments, Statement of Applicability (SoA) updates, and treatment plans
Support internal and external audits (preparation, evidence collection, tracking of nonconformities and corrective actions)
Develop, review, and maintain information security policies, standards, and procedures
Monitor and support compliance with applicable laws, regulations, and contractual security requirements (telecom, data protection, client demands)
Support third party risk management process: security assessments of vendors, service providers, and partners
Keep ISMS and governance documentation well organized and current
Produce reports and dashboards on compliance status, audit results, and ISMS performance for management
Contribute to security awareness initiatives around policies, acceptable use, and data protection
Act as a point of contact for questions related to policies, compliance, and third party security requirements
Work closely with IT, Security Operations, Legal, HR, Procurement, and business units to ensure controls are understood and applied
Requirements
Bachelor’s degree in Information Security, Systems Engineering, Law, Business, or related field (or equivalent experience)
2–5+ years of experience in information security, GRC (Governance, Risk & Compliance)
Good understanding of ISO/IEC 27001 and related standards
Experience with security policies, procedures, and audit processes
Familiarity with basic risk management concepts and methods
Ability to review and interpret contracts, SLAs, and security clauses (desirable)
Strong documentation, organization, and reporting skills
Ability to work collaboratively with technical and non-technical teams
Attention to detail, structured thinking, and a proactive mindset
Nice to Have: Experience in telecom, ISP, hosting, or cloud environments
Knowledge of data protection regulations (e.g., local privacy laws, GDPR exposure)
Certifications such as ISO 27001 Lead Implementer/Auditor, CISA, or similar.
Benefits
Competitive compensation aligned with senior technical roles in the region
Opportunity to influence software quality standards across the organization
Strong engineering culture focused on ownership, automation, and continuous improvement
Information Security Analyst evaluating cybersecurity and third - party risk for clients in regulated industries. Utilizing VRM and Cybersecurity Compliance platforms to ensure rigorous security standards.
Acquisition Security Analyst at GDIT ensuring technology safety and securing advanced programs. Collaborating on program protection methodologies and conducting lifecycle analysis for critical information.
Operational Safety Analyst supporting safety management and process improvements at Gol Linhas Aéreas. Engaging in compliance and risk management with a diverse team.
Governance & Compliance Security Analyst maintaining and improving information security governance and ISO 27001 compliance for EdgeUno's digital infrastructure in Latin America.
Cybersecurity Analyst designing, implementing, and maintaining security controls across EdgeUno’s network and platforms in Latin America. Requires collaboration with various technical teams and security technology expertise.
Cybersecurity Analyst at EdgeUno responsible for designing and implementing security controls across platforms. Collaborates with teams to ensure secure architecture for ISP and cloud services.
Cyber Security Analyst supporting design, security, and operation of a Kubernetes - based system for Maricopa County. Collaborating with IT teams and vendors to ensure security and compliance.
Senior Security Analyst leading the handling of escalated security incidents at Landis+Gyr. Mentoring analysts and collaborating on security threats mitigation in a hybrid environment.
Cyber Security Analyst investigating cyber security incidents and enhancing response processes for a sustainable energy company. Supporting global stakeholders with security tools and functions.
Information Security Analyst at Hitss conducting penetration tests and security assessments across IT infrastructures. Collaborating with teams to report and mitigate vulnerabilities.