Governance & Compliance Security Analyst managing information security governance, ISO 27001 compliance, and third-party risk management for EdgeUno. Collaborating with cross-functional teams to ensure effective ISMS alignment across regulatory requirements.
Responsibilities
Maintain and update the Information Security Management System (ISMS) in line with ISO/IEC 27001.
Coordinate periodic risk assessments, Statement of Applicability (SoA) updates, and treatment plans.
Support internal and external audits (preparation, evidence collection, tracking of nonconformities and corrective actions).
Develop, review, and maintain information security policies, standards, and procedures.
Coordinate periodic reviews and approvals with management and relevant stakeholders.
Ensure documentation is aligned with ISO 27001, regulatory requirements, and business needs.
Monitor and support compliance with applicable laws, regulations, and contractual security requirements (telecom, data protection, client demands).
Prepare and maintain evidence repositories for certifications, audits, and customer due diligence.
Support responses to security questionnaires, RFPs, and client audits.
Support the third party risk management process: security assessments of vendors, service providers, and partners.
Review certifications and security documentation from third parties (e.g., ISO 27001, SOC 2).
Track identified risks and remediation actions for critical third parties and maintain an up to date third party inventory.
Keep ISMS and governance documentation well organized and current.
Produce reports and dashboards on compliance status, audit results, and ISMS performance for management.
Help define and track security KPIs/KRIs related to governance and compliance.
Contribute to security awareness initiatives, especially around policies, acceptable use, and data protection.
Act as a point of contact for questions related to policies, compliance, and third party security requirements.
Work closely with IT, Security Operations, Legal, HR, Procurement, and business units to ensure controls are understood and applied.
Requirements
Bachelor’s degree in Information Security, Systems Engineering, Law, Business, or related field (or equivalent experience).
2–5+ years of experience in information security, GRC (Governance, Risk & Compliance).
Good understanding of ISO/IEC 27001 and related standards.
Experience with security policies, procedures, and audit processes.
Familiarity with basic risk management concepts and methods.
Ability to review and interpret contracts, SLAs, and security clauses (desirable).
Strong documentation, organization, and reporting skills.
Ability to work collaboratively with technical and nontechnical teams.
Attention to detail, structured thinking, and a proactive mindset.
Nice to Have: Experience in telecom, ISP, hosting, or cloud environments.
Knowledge of data protection regulations (e.g., local privacy laws, GDPR exposure).
Certifications such as ISO 27001 Lead Implementer/Auditor, CISA, or similar.
Benefits
Competitive compensation aligned with senior technical roles in the region
Opportunity to influence software quality standards across the organization
Strong engineering culture focused on ownership, automation, and continuous improvement
Cyber Threat Intelligence Analyst supporting IT Security team in identifying and mitigating cyber threats. Ensuring network security and protecting company secrets in high - tech environment.
Risk Analyst supporting cyber risk management activities for PokerStars and other brands. Ensuring accurate risk documentation, reporting, and stakeholder engagement in Cluj - Napoca, Romania.
Cyber Security Analyst responsible for governance, risk management, and compliance projects for clients and internally at Cyberlogic. Engaging with clients on project - based work while developing policies and standards.
Analista de segurança de informação supporting the maintenance of data privacy and protection programs at Minsait. Involves audit support, training, and compliance with legislation.
IT Security Analyst assisting in managing technology environments ensuring security compliance. Supporting Brasilseg's platforms with adherence to best practices in software and hardware.
Senior Cybersecurity Analyst applying RMF concepts to enhance cybersecurity for defense program. Conducting risk assessments and developing reports, based in Colorado Springs, CO.
Junior Information Security Analyst assisting federal clients at OCT Consulting with NIST security assessments and risk analyses. Responsible for executing hands - on security control assessments and recommending process improvements.
Journeyman Information Security Analyst providing expertise to federal clients in Security Controls Assessments and Risk Analyses. Responsibilities include technical assessments and recommendations for security improvements.
Information Security Analyst supporting security practices at Silimed, the leading silicone implant manufacturer in Latin America. Ensuring compliance and resilience in critical OT & IT environments.
Security Analyst defending enterprise systems against cyber threats. Supporting threat intelligence and incident response activities in a global biotechnology organization.