Information Security Compliance Analyst
The Information Security Compliance Analyst will be responsible for monitoring, managing and closing existing compliance issues while also ensuring that internal systems are compliant with security standards, both internal and global like: ISO 27001, NIST, COBIT or TISAX. In carrying out these functions, the analyst’s responsibilities include the identification, evaluation and interpretation of regulatory, statutory and member security requirements, control deficiencies and information security risks.
Essential Duties & Responsibilities
- Design, coordinate and execute audit process e.g., TISAX or ISO, monitoring and procedures to assess and measure company information security risks and compliance with its security policies and procedures.
- Monitor advancements in information privacy laws and global frameworks e.g., TISAX, ISO, NIST or COBIT to ensure organizational adaptation and compliance.
- Develop, recommend, and establish controls and processes as necessary to protect client's information assets against unauthorized or accidental modification, destruction, or disclosure.
- Creating and coordinating proper reporting channels for compliance issues. Developing compliance communications with client’s Business Units. Coordinating required compliance training for employees.
- Provide consulting and technical support services to owners, custodians, and users in defining and deploying cost-effective security controls and protections.
- Document, maintain, and obtain ongoing support for all aspects of the ISMS program.
- Monitor the effectiveness of strategies, activities, measures, and controls designed to protect clients' information assets.
- Serve as internal and external point of contact for information security matters regarding information security topics.
- Participate in the Information Security policies lifecycle process, necessary to ensure the security of information and information resources against unauthorized or accidental modification, destruction, or disclosure.
- Coordinate the review of the data security requirements, specifications of the third-party risk assessment (TPRM).
Required Skills
- Desirable 2 + years of relevant Information Security experience in any organization with background covering design, risk, compliance, governance, data protection, Identity and assess management, Network security, application security and/or cloud.
- Excellent communication, organization time management and problem-solving skills
- Exceptional track record of building relationships with stakeholders
- Strong multi-tasking skills with the ability to manage multiple projects
- Ability to function as a Team Player and maintain a good working relationship, yet think and act independently with professionalism, discretion and confidentiality
- Excellent communication, organization time management and problem-solving skills
- Availability to travel depending on business needs – Germany, Sweden, Romania, Czechia.
Required Experience
- Bachelor’s degree in Computer Science, Information Security and Risk Management, Information Systems etc.
- CISSP, CISM or ITIL, certifications are preferred
- Experience in implementing and managing information security programs or projects, including KRI creation and maintenance