About Role
We're looking for a Security Compliance & Audit Specialist to join the FSD Security Team.
In this role, you will drive security compliance, audit readiness, and governance initiatives across the organization. You will partner with technology, product, cloud, infrastructure, and security teams to ensure alignment with internal policies, regulatory requirements, and industry security frameworks. You will lead and support security audits, manage risk assessments, develop compliance documentation, create executive reporting, and leverage modern tools including AI-powered solutions to improve compliance visibility, reporting, and operational efficiency.
Key Responsibilities
- Lead and support internal, external, customer, and regulatory security audits.
- Drive compliance initiatives aligned with NIST CSF, NIST 800-53, SOC 2, ISO 27001, CIS Controls, and other applicable standards.
- Conduct risk assessments, control reviews, compliance gap analyses, and remediation tracking.
- Partner with engineering, cloud, infrastructure, and business teams to ensure effective implementation of security controls.
- Manage audit findings, risks, exceptions, and corrective action plans through closure.
- Develop and maintain security policies, standards, procedures, and compliance documentation.
- Coordinate audit evidence collection, control testing, and auditor engagements.
- Create executive presentations, dashboards, KPIs, compliance reports, and security metrics for leadership visibility.
- Support customer security assessments, due diligence reviews, third-party risk evaluations, and regulatory requests.
- Leverage AI and automation tools to improve audit readiness, reporting, compliance monitoring, and operational efficiency.
- Communicate security risks, audit outcomes, and compliance status effectively to technical and business stakeholders.
- Drive continuous improvement of governance, compliance, and security maturity programs.
Required Qualifications
- 5+ years of experience in Information Security, Compliance, Audit, Risk Management, or GRC.
- Strong knowledge of NIST, SOC 2, ISO 27001, CIS Controls, security governance frameworks, and regulatory compliance requirements.
- Experience supporting or leading internal and external security audits.
- Experience performing risk assessments, control evaluations, remediation management, and compliance reporting.
- Good understanding of security domains including: Access Management Vulnerability Management Incident Response Security Monitoring Data Protection Third-Party Risk Management
- Working knowledge of AWS and Azure security controls, governance, and compliance requirements.
- Experience creating executive-level presentations, dashboards, KPIs, and compliance reporting.
- Excellent verbal and written communication skills with the ability to influence and collaborate across technical and nontechnical stakeholders.
- Strong stakeholder management skills, including the ability to facilitate discussions, negotiate remediation plans, and manage competing priorities across teams.
- Demonstrated experience presenting audit results, compliance metrics, and risk assessments to leadership audiences
Preferred Qualifications
- Experience supporting customer audits, security questionnaires, due diligence reviews, and working within large enterprise environments.
- Professional certifications such as CISSP, CISA, CRISC, CISM, Security+ or ISO 27001 Lead Auditor.
- Experience with GRC platforms such as Archer or vulnerability tool platforms for report generations.
- Experience using AI-powered tools (MSCopilot, Claude Enterprise, ChatGPT, PowerBI, security analytics platforms, etc.) to improve productivity, reporting, workflow automation, and compliance insights