InfoSec Risk & Compliance Analyst supporting Governance, Risk & Compliance at Reward Gateway. Ensuring ISO compliance and supporting information security operations in a growing company.
Responsibilities
Support our control framework covering ISO 27001, SOC2 Type II, PCI DSS, Cyber Essentials Plus and (in the future) ISO 9001
Ensure ISO readiness/compliance by conducting/supporting periodic internal audits and participating in hosting ISO registrar audits
Assist with analysis, documentation and remediation actions for detected audit observations
Verify implementation and effectiveness of the corrective/preventative actions
Support the Head of GRC and process owners in developing, documenting, reviewing, and communicating company processes and procedures to incorporate best practices in Quality Management and Information Security Management
Maintain the compliance automation platform for achieving streamlined compliance activities
Support the Director of Information Security and Risk Owners with the risk management process
Requirements
At least 1+ year of experience working in Information Security Compliance/Internal Audit
Experience with at least one compliance framework (e.g., ISO 27001, ISO 9001, ISO 22301, SOC 2 Type II, PCI DSS).
Understanding of information security concepts and technology
Previous exposure to cloud technologies and cloud security will be beneficial
Experience in Document Management (incl. Good Documentation Practices) and procedure review
Excellent English communication skills
Comfortable with working across multiple projects, geographical locations, and assignments at once
Have a risk-based approach to problem-solving
Benefits
A 30-minute online interview with the Senior Talent Partner
First stage online interview with the Head of Governance Risk & Compliance
Final stage interview with the Director of Information Security and the Head of Governance Risk & Compliance
Be comfortable. Be you. At Reward Gateway, we want all of our employees to feel comfortable bringing their passion, creativity and individuality to work. We value all cultures, backgrounds and experiences, as we truly believe that diversity drives innovation. Express yourself, join our community and help us Make the World a Better Place to Work.
Security Officer responsible for maintaining safety and security at Hilton in Harrisburg, PA. Conducting patrols, responding to emergencies, and supervising housekeeping staff.
Information Security Engineer managing incident detection and response for Safe - Guard Products. Involves vulnerability management, data protection, and security engineering activities.
Work Student, Product Security at TeamViewer supporting security initiatives for product safety. Opportunity to gain hands - on experience in an international environment with a focus on cybersecurity.
Cyber Security Detection Engineer focusing on threat detection capabilities and security telemetry within complex environments. Collaborating across Security Operations, Cloud Engineering, and Compliance disciplines.
Security Specialist managing mainframe security operations at PNC. Collaborating with teams on compliance and security risks while mentoring junior analysts.
Security Assurance Specialist coordinating security assessments within cybersecurity risk management at Vanguard. Ensuring effective risk and vulnerability management across applications and infrastructures.
Summer Intern supporting CIO PMO and Security teams at Sprinklr. Gaining hands - on experience in technology and security areas while assisting key initiatives.
Sicherheitsingenieur managing safety and integrated management systems for CRONIMET. Supporting the development of safety practices and conducting audits on various health and safety topics.
Senior Cloud Security Engineer securing public cloud platforms and services in the financial industry. Collaborating with teams to enhance security posture and ensure compliance in cloud environments.
Cybersecurity Metrics and Reporting Lead overseeing development of security metrics and dashboards. Collaborating with teams to improve cybersecurity program effectiveness and compliance tracking.