InfoSec Risk & Compliance Analyst supporting Governance, Risk & Compliance at Reward Gateway. Ensuring ISO compliance and supporting information security operations in a growing company.
Responsibilities
Support our control framework covering ISO 27001, SOC2 Type II, PCI DSS, Cyber Essentials Plus and (in the future) ISO 9001
Ensure ISO readiness/compliance by conducting/supporting periodic internal audits and participating in hosting ISO registrar audits
Assist with analysis, documentation and remediation actions for detected audit observations
Verify implementation and effectiveness of the corrective/preventative actions
Support the Head of GRC and process owners in developing, documenting, reviewing, and communicating company processes and procedures to incorporate best practices in Quality Management and Information Security Management
Maintain the compliance automation platform for achieving streamlined compliance activities
Support the Director of Information Security and Risk Owners with the risk management process
Requirements
At least 1+ year of experience working in Information Security Compliance/Internal Audit
Experience with at least one compliance framework (e.g., ISO 27001, ISO 9001, ISO 22301, SOC 2 Type II, PCI DSS).
Understanding of information security concepts and technology
Previous exposure to cloud technologies and cloud security will be beneficial
Experience in Document Management (incl. Good Documentation Practices) and procedure review
Excellent English communication skills
Comfortable with working across multiple projects, geographical locations, and assignments at once
Have a risk-based approach to problem-solving
Benefits
A 30-minute online interview with the Senior Talent Partner
First stage online interview with the Head of Governance Risk & Compliance
Final stage interview with the Director of Information Security and the Head of Governance Risk & Compliance
Be comfortable. Be you. At Reward Gateway, we want all of our employees to feel comfortable bringing their passion, creativity and individuality to work. We value all cultures, backgrounds and experiences, as we truly believe that diversity drives innovation. Express yourself, join our community and help us Make the World a Better Place to Work.
Teamlead for IT Perimeter Security Engineering at Axians Switzerland, leading a security team and managing client consultations. Engaging in technical engineering of security solutions while fostering team development.
Product Security Engineer working on security measures for identity verification systems. Driving vulnerability responses and enhancing security in product development cycles.
Senior Product Security Engineer at Persona focusing on security infrastructure and AI tooling. Drive vulnerability lifecycle and collaborate with engineering teams on secure feature development.
Senior Software Engineer developing IAM systems for identity verification at Persona. Engaging in security - focused engineering to ensure user identity safety and compliance.
Software Engineer developing and building IAM systems at Persona, focused on identity verification infrastructure. Collaborating across teams to ensure secure practices in deploying AI tooling.
Teamleiter:in IT Perimeter Security Engineering at Axians Switzerland leading a Cyber Security team. Guiding practical engineering and technical project management for client services in a multi - site environment.
Security Officer maintaining safety and compliance at WarHorse Casino. Responsible for incident reporting and guest relations in a dynamic gaming environment.
Technical leader in security architecture for Riachuelo, overseeing security solutions and team activities. Seeking to enhance security measures while fostering teamwork.
Cyber Security Specialist for Riachuelo's Red Team overseeing offensive security projects. Leading cyber threat intelligence and collaborating with internal teams on security improvements.
Senior Security Engineer at PagBank ensuring secure network and application exposure strategies. Leading technical initiatives in firewalls, WAF/CDN, and advanced troubleshooting.