Better. Sooner. Together.
Security Compliance Manager
Location
United States
Posted
32 days ago
Salary
$110K - $140K / year
Seniority
Senior
Job Description
Security Compliance Manager
OneStudyTeam
• Lead security certification & audit readiness (ISO 27001 / SOC 2). • Operate the ISMS controls program. • Evidence management & auditor response. • Risk management program execution. • Metrics, reporting, and stakeholder enablement. • Manage periodic reviews and updates of security policies and procedures. • Partner with an outsourced/internal audit function to validate control performance. • Support cross-functional education and adoption of security requirements.
Job Requirements
- Experience leading a successful ISO 27001 or SOC 2 certification effort.
- 5+ years in a dedicated information security role in a regulated environment (e.g., HIPAA, GLBA, PCI).
- Security certification such as CISA, CISM, CISSP (or similar).
- Demonstrated ability to lead ISO 27001 and/or SOC 2 certification efforts and ongoing maintenance activities.
- Strong competency in gap analysis and risk assessment methodologies;
- Working knowledge of security policy, procedure, and enforcement across key domains: access control, data classification, change management, asset management, BCDR, incident response, vulnerability management, secure SDLC, source control, endpoint protection.
- Ability to translate security/compliance requirements into actionable work for Engineering/IT/Operations.
- Strong written and verbal communication—able to interface with all levels of the organization and produce high-quality audit-ready documentation.
- Technical foundation sufficient to understand high-level concepts related to public cloud (AWS/GCP/Azure), Agile SDLC, CI/CD, VPNs, and modern web applications.
Benefits
- Health insurance
- Professional development opportunities
- Flexible work arrangements
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Data Security Engineer
CAQHCAQH delivers technology-enabled solutions, operating rules and research to the healthcare industry.
• Partner with data owners and the Data team to identify and inventory critical data assets across the enterprise. • Implement automated and programmatic classification of sensitive data using tools such as Wiz, Microsoft Purview, Varonis and other data security solutions. • Develop and maintain data protection policies aligned with regulatory standards (e.g., HITRUST, HIPAA). • Apply and tune DLP policies across email, cloud, USB, printing, and endpoint channels. • Build dashboards, alerts, and metrics for real-time monitoring of data protection events. • Implement and manage data rights enforcement mechanisms to ensure appropriate access and usage of sensitive data. • Contribute to the deployment and tuning of DSPM tools such as Wiz, Zscaler, Varonis, Imperva and others to enhance visibility and control. • Collaborate with infrastructure teams to ensure backup and recovery strategies align with data protection objectives and support immutable backups. • Integrate DLP and DSPM tools with SIEM for incident response, ticketing, and compliance reporting. • Work closely with CAQH teams to align protection strategies with business operations. Provide training and documentation to business units on data protection best practices.
• Analizar los requerimientos del negocio para diseñar arquitecturas, patrones y soluciones que mitiguen riesgos en los proyectos de transformación • Construir matrices de controles personalizadas según el contexto tecnológico (Nube, Aplicación, APIs, Microservicios) • Verificar la correcta implementación de los controles en todas las capas del software mediante la ejecución de escaneos de línea base y la validación de evidencias técnicas • Realizar el seguimiento, priorización y recomendaciones técnicas para el cierre de vulnerabilidades identificadas durante el ciclo de desarrollo de aplicaciones • Actuar como referente frente a las células de transformación, detallando activos críticos, amenazas y riesgos asociados a la arquitectura • Coordinar la respuesta a requerimientos de auditorías internas/externas y evaluaciones de riesgo • Elaborar informes sobre el estado de seguridad de las iniciativas y comunicar desviaciones de manera oportuna a las partes interesadas
• Collaborate with the Corporate Cyber Security team to define and advance the access identity management and MFA products • Act as a senior technical advisor on IAM architecture, access patterns, and authentication/authorization strategies • Contribute to threat modeling, security reviews, and incident response support as it relates to IAM systems • Design, develop, and maintain full-stack applications and services that enable security capabilities • Configure, customize and maintain authentication services including SSO, MFA, federation, privileged access, cloud security (AWS) and IBM ISVG / Access Management components • Monitor, troubleshoot, and resolve IAM-related incidents and performance issues • Integrate services with enterprise applications, identity providers, and authentication services • Translate business requirements into secure, scalable, and maintainable solutions • Present technical solutions to both technical and non-technical stakeholders • Own and maintain GitLab CI/CD pipelines • Automate deployment and operational tasks using scripting (Python, Bash) • Mentor junior developers, participate in Code Reviews and support team-wide best practices
OT Security Architect
meteocontrolIndependent developer of holistic energy & asset management solutions in the renewable energy industry since 1998.
• Support multiple customer projects at various project stages • Design and develop security architectures for renewable energy power plants • Specify security requirements and support compliance with international/regional security standards and regulations (e.g., IEC 62443, NIS 2) • Perform threat and risk analyses and define countermeasures at system level • Advise technical departments on secure system integration • Support customer projects from concept through implementation • Evaluate and select security technologies and solutions




