Job Closed
This listing is no longer active.
Speed. Security. Reliability.
Security Policy & Compliance Analyst
Location
Idaho + 3 moreAll locations: Idaho | Montana | Oregon | Washington
Posted
179 days ago
Salary
$80.8K - $103.1K / year
Seniority
Mid Level
Job Description
Security Policy & Compliance Analyst
Ziply Fiber
• Administer the policy lifecycle, including drafting, coordinating reviews, publishing, and updating security policies. • Collaborate with Legal, IT, and Security to ensure policies align with business and regulatory requirements. • Maintain centralized documentation for audits, assessments, and regulatory reviews. • Assist in preparing and organizing policy and evidence documentation for internal and third-party audits. • Monitor regulatory developments and assist in aligning internal practices accordingly. • Assist in monitoring organizational adherence to internal policies and procedures. • Track and report on compliance and policy enforcement metrics. • Arranges, conducts and monitors compliance testing, audits, and investigations. • Provides ongoing monitoring of compliance information systems and processes. • Informs supervisor of any compliance violations. • Reviews internal systems, controls, and processes and identifies ways to resolve regulatory gaps and deficiencies. • Assists with the implementation of new and updated compliance systems, standards, processes, procedures, and policies. • Ensures compliance with all local, state, and federal laws and regulations as well as company policies, procedures and internal controls. • Support compliance initiatives across departments by providing guidance and training. • Generates analyses and reports containing results of compliance testing to management. • Develops, maintains, and delivers compliance training content and programs. • Performs other duties as required to support the business and evolving organization.
Job Requirements
- Bachelor of Science (BS) in Computer Science, Information Technology, Risk Management, Legal Studies, Business, or a related field.
- Minimum of two (2) years in a policy, audit, or compliance analyst role.
- Strong understanding of risk frameworks such as:
- o National Institute of Standards and Technology Cybersecurity Framework (NIST CSF).
- o NIST Special Publication 800-171.
- o International Organization for Standardization ISO 27001.
- o Service Organization Control 2 (SOC 2).
- o Sarbanes-Oxley Act (SOX).
- Direct experience managing regulatory requirements such as:
- o Payment Card Industry Data Security Standard (PCI-DSS).
- o NIST guidelines.
- Experience contributing to cross-functional compliance projects or initiatives.
- Familiarity with Governance, Risk, and Compliance (GRC) platforms or compliance tracking systems.
- Familiarity with legal hold processes, third-party risk management, and incident response documentation.
- Familiarity with business continuity and incident response concepts and procedures.
Benefits
- Medical
- Dental
- Vision
- 401k
- Flexible spending account
- Paid sick leave and paid time off
- Parental leave
- Quarterly performance bonus
- Training
- Career growth and education reimbursement programs
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Director of Business Development, Cybersecurity
FTI - Frontier Technology Inc.Right Data. Best Decisions. | Technology and deep data expertise to drive the best defense and intelligence decisions.
• Build, manage, and grow a high-value pipeline of cyber-related opportunities, leveraging relationships, market insights, and understanding of mission priorities across the DoD. • Drive the identification, shaping, and capture of new business opportunities in support of DoD Cyber Security. • Collaborate with operational, technical, and functional leaders across FTI to align internal capabilities with external customer demands, bringing forward differentiated and competitive solutions. • Assist in guiding potential customers by demonstrating technology solutions, architectures, capabilities, and potential acquisition paths for early-stage opportunities, working with internal technical and program management teams to develop responses for requests for information (RFI), market surveys, white papers, presentations, briefings, and major event demonstrations. • Support bid/no bid decisions, proposal strategy development, resource planning, and overall capture execution. • Maintain a clear understanding of customer funding profiles, acquisition strategies, and emerging requirements to proactively position FTI. • Contribute to internal growth planning efforts including strategic planning and market analysis relevant to the cyber domain. • Help foster a culture of growth, accountability, and high performance within the BD team. • Develop and deliver reports and briefs as required.
• Lead and manage the GRC and Security Engineering teams, including strategy, objectives, staffing, coaching, and performance management. • Own governance, risk, and compliance programs. Maintain ISO 27001 and related controls. Drive audit readiness for HIPAA and other frameworks. Coordinate policy lifecycle management and control testing. • Run vendor assessment and qualification program. Oversee third party risk management, due diligence, contractual security requirements, and continuous monitoring. • Provide AI related security assessments and guidance. Establish acceptable use guardrails for AI, assess model and data risks, and advise on controls for AI enabled solutions. • Oversee security architecture for cloud environments and enterprise platforms. Partner with engineering on secure design for AWS, Azure, identity, network, and data protection. • Direct security engineering operations. Manage EDR and threat detection with CrowdStrike, SIEM operations, CSPM posture management, vulnerability management, and SOAR automation. • Lead incident response readiness and execution. Run tabletop exercises, coordinate investigations, and deliver root cause and lessons learned. • Own and manage security budgets, multiyear planning, vendor contracts, and cost optimization while meeting control objectives. • Report program status and risk posture to executives and the board. Define and track KPIs and KRIs. Communicate clearly with technical and non technical stakeholders. • Establish and enforce secure software development practices and SDLC controls with engineering leadership. • Maintain a current security roadmap and maturity plan aligned to business priorities. • Oversee metrics, dashboards, and reporting for program performance and risk reduction. • Coordinate with Legal, Privacy, and Compliance on regulatory obligations and customer security assessments. • Champion security awareness training and culture, sponsor targeted training for engineering and high risk roles. • Evaluate, select, and manage strategic security vendors and platforms, drive successful implementations and integrations. • Represent security in customer meetings and due diligence, provide credible technical and compliance answers.
Data Center Security Manager
RYZ LabsRYZ Labs is a startup studio built in 2021 by three lifelong entrepreneurs. The founders of RYZ have worked at some of the world's largest tech companies and some of the most iconic consumer brands. They have lived and worked in Argentina for many years and have decades of experience in Latam. Passion for the early phases of company creation Attracting the brightest talents to build industry-defining companies in a post-pandemic world Remote and distributed teams throughout the US and Latam Use of cutting-edge technologies in cloud computing Aim to provide diverse product solutions for different industries Plans to build a large number of startups in the upcoming years Our Values and What to Expect Customer First Mentality - every decision we make should be made through the lens of the customer. Bias for Action - urgency is critical, expect that the timeline to get something done is accelerated. Ownership - step up if you see an opportunity to help, even if not your core responsibility. Humility and Respect - be willing to learn, be vulnerable, and treat everyone who interacts with RYZ with respect. Frugality - being frugal and cost-conscious helps us do more with less. Deliver Impact - get things done most efficiently. Raise our Standards - always be looking to improve our processes, our team, and our expectations. The status quo is not good enough and never should be.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description RYZ Labs is hiring for a Data Center Security Manager to develop and enforce physical security policies, protect facilities from threats, and lead access control, surveillance, and incident response. On-call rotation required. - Develop and maintain security policies, SOPs, and incident response plans. - Manage access control, badging, visitor management, and key/lock programs. - Oversee CCTV/VMS, alarms/IDS, and monitoring; ensure timely response and reporting. - Lead incident handling and investigations; perform RCA and corrective actions. - Conduct risk assessments, audits, and drills; track metrics and compliance. - Manage guard force and security vendors; coordinate with DC ops, EHS, and legal. - Plan lifecycle upgrades and maintenance for security systems and infrastructure. Qualifications - Bachelor’s in Security, Criminal Justice, or related field, or equivalent experience. - 5+ years in physical security for data centers or critical facilities. - Hands-on with PACS (e.g., Lenel/Genetec), VMS, alarms/IDS; basic integration with IT/SIEM a plus. - Knowledge of security and compliance frameworks (ISO 27001, SOC 2, NIST, TIA-942, PCI). - Experience with incident response, investigations, audits, and vendor management. - Certifications preferred: CPP, PSP (ASIS), or equivalent. Company Description RYZ Labs is a startup studio built in 2021 by two lifelong entrepreneurs. The founders of RYZ have worked at some of the world's largest tech companies and some of the most iconic consumer brands. They have lived and worked in Argentina for many years and have decades of experience in Latam. What brought them together is the passion for the early phases of company creation and the idea of attracting the brightest talents in order to build industry-defining companies in a post-pandemic world. - Our teams are remote and distributed throughout the US and Latam. - They use the latest cutting-edge technologies in cloud computing to create applications that are scalable and resilient. - We aim to provide diverse product solutions for different industries, planning to build a large number of startups in the upcoming years. - At RYZ, you will find yourself working with autonomy and efficiency, owning every step of your development. - We provide an environment of opportunities, learning, growth, expansion, and challenging projects. - You will deepen your experience while sharing and learning from a team of great professionals and specialists. - Customer First Mentality - every decision we make should be made through the lens of the customer. - Bias for Action - urgency is critical, expect that the timeline to get something done is accelerated. - Ownership - step up if you see an opportunity to help, even if not your core responsibility. - Humility and Respect - be willing to learn, be vulnerable, and treat everyone who interacts with RYZ with respect. - Frugality - being frugal and cost-conscious helps us do more with less. - Deliver Impact - get things done in the most efficient way. - Raise our Standards - always be looking to improve our processes, our team, and our expectations.
Senior Security Engineer
NextGen Federal SystemsNextGen Federal Systems is an innovative technology and professional services provider specializing in advanced software solutions and comprehensive mission and business support services. We work in close collaboration with our Customers to truly understand their business and mission goals. Our approach is to design, build, implement, and manage solutions that measurably improve our client’s organizational performance. We have established and foster a corporate culture where we: Treat employees with fairness and respect regardless of their position, tenure, race, or sexual identity. Communicate the importance of our mission and our employees’ contributions to it, ensuring they understand how their job role contributes to the greater good. Openly promote and communicate our ideas for change and adaptability. Strive to achieve results as an organization. Hold employees accountable to their commitments and provide incentives that encourage positive and productive behaviors. Value the talents and contributions of our employees as the key factor for our success. Create an environment where people can engage at all levels. Encourage people to take risks and allow them to make mistakes.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are seeking an experienced Senior Security Engineer to remotely support our federal customer located in Clarksburg, WV. This role requires at least a Secret Security Clearance, and the primary work location is remote. Responsibilities include: - Performs security audits, risk analysis, application-level vulnerability testing, and security code reviews. - Develops and implements technical solutions to help mitigate security vulnerabilities. - Conducts research to identify new attack vectors. - Supports mainframe with scanning and other security focused operational support responsibilities. Qualifications - Bachelor’s Degree with 8 years of work experience. - Active Tier 3 Secret clearance. - 5+ years of experience performing security audits, risk analysis, application-level vulnerability testing, and security code reviews. - 5+ years of experience developing and implementing technical solutions to help mitigate security vulnerabilities. - Experience working within the Agile Methodology. - Experience in a cloud native architecture. - Experience working in a Kafka infrastructure. - Experience with container security in AWS. - Building and maintaining secure CI/CD Pipelines. - Strong understanding of federal security requirements. - Strong written and verbal communication skills. Company Description NextGen Federal Systems is an innovative technology and professional services provider specializing in advanced software solutions and comprehensive mission and business support services. We work in close collaboration with our Customers to truly understand their business and mission goals. Our approach is to design, build, implement, and manage solutions that measurably improve our client’s organizational performance. We have established and foster a corporate culture where we: - Treat employees with fairness and respect regardless of their position, tenure, race, or sexual identity. - Communicate the importance of our mission and our employees’ contributions to it, ensuring they understand how their job role contributes to the greater good. - Openly promote and communicate our ideas for change and adaptability. - Strive to achieve results as an organization. - Hold employees accountable to their commitments and provide incentives that encourage positive and productive behaviors. - Value the talents and contributions of our employees as the key factor for our success. - Create an environment where people can engage at all levels. - Encourage people to take risks and allow them to make mistakes.



