Information Security Analyst

Scale Up Recruiting Partners

San Juan (PR)

On-site

USD 90,000 - 130,000

Full time

9 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Scale Up Recruiting Partners is seeking an Information Security Analyst contractor to own the vendor security questionnaire process end-to-end across multiple client accounts.

You will monitor security requests from U.S.-based startups, coordinate with technical stakeholders, and ensure questionnaires are completed accurately and on time using SIG, CAIQ, or custom formats.

Qualifications

  • 2–4 years in vendor security questionnaires or GRC/compliance roles.

Responsibilities

  • Monitor client Slack channels and respond to vendor security questionnaire requests.

Skills

Vendor security questionnaires
GRC/compliance
SOC 2 knowledge
ISO 27001 knowledge
Security frameworks
Written communication
Professional English
organization

Education

CompTIA Security+
ISC2 Certified in Cybersecurity (CC)

Tools

Jira
Linear
OneTrust
Whistic
SecurityScorecard
Conveyor
SafeBase
Vanta

Job description

Hey! We're Scale Up, and our client is looking to hire a Information Security Analyst.

Type of Employment: Contractor (Long-term)

Work Modality: 100% Remote

Work Schedule: Full-time

Time Zone: U.S. Pacific Time (PST) with overlap during business hours

Location: LATAM

About Our Client

Our client is a fast-growing U.S.-based cybersecurity and compliance consulting firm that partners with technology startups to strengthen their security posture and achieve compliance with frameworks such as SOC 2, ISO 27001, HIPAA, and more.

They act as an extension of their clients' security teams, providing GRC consulting, audit readiness, vendor risk management, and virtual CISO services. As the company continues to grow, they are expanding their team with professionals who enjoy working across multiple clients in a fast-paced consulting environment.

About The Role

You’ll own the vendor security questionnaire process from end to end across multiple client accounts.

You’ll work closely with U.S.-based startups, monitoring incoming security requests, coordinating with technical stakeholders, and completing security questionnaires accurately and on time. This role requires a solid understanding of security frameworks, strong organizational skills, and the ability to communicate clearly with both technical and non-technical stakeholders.

This is an excellent opportunity for someone with experience in GRC, security compliance, or vendor risk who enjoys supporting multiple clients and playing a key role in helping companies close enterprise deals.

Key Responsibilities
  • Monitor client Slack channels and respond promptly to incoming security questionnaire requests.
  • Create and manage tickets in Jira, Linear, or other ticketing systems to track requests through completion.
  • Complete vendor security questionnaires (SIG, CAIQ, custom questionnaires) through spreadsheets and security platforms such as OneTrust, Whistic, SecurityScorecard, and similar tools.
  • Develop a deep understanding of each client's security posture, policies, controls, and technical environment.
  • Maintain and continuously improve client answer libraries and knowledge bases.
  • Coordinate with security consultants, engineers, and subject matter experts whenever technical clarification is needed.
  • Escalate recurring gaps or missing controls that impact questionnaire responses.
  • Ensure all questionnaires are completed accurately and within customer deadlines.
Requirements
  • 2-4 years of experience completing vendor security questionnaires, working in GRC/compliance, or in a security-related client-facing role.
  • Hands-on experience completing SIG, CAIQ, or custom vendor security questionnaires.
  • Working knowledge of SOC 2 and ISO 27001.
  • Understanding of common security concepts, including:
    • Single Sign-On (SSO)
    • Multi-Factor Authentication (MFA)
    • Endpoint Management
    • Encryption (at rest & in transit)
    • Cloud infrastructure fundamentals
    • Backup & Disaster Recovery
    • Vendor Risk Management
  • Strong organizational skills with the ability to manage multiple requests simultaneously.
  • Excellent judgment regarding when to answer independently and when to involve technical SMEs.
  • Excellent written communication skills.
  • Professional English (written and spoken).
Nice to Have
  • Experience handling a high volume of vendor security questionnaires.
  • Experience with:
    • Conveyor
    • SafeBase
    • Vanta
    • Whistic
    • Trust Center platforms
  • Experience maintaining questionnaire knowledge bases.
  • Experience working alongside Sales or Revenue teams supporting enterprise deals.
  • Certifications such as:
    • CompTIA Security+
    • ISC2 Certified in Cybersecurity (CC)
    • Similar cybersecurity certifications
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Information Security Analyst: GRC & Vendor Risk
Remote Information Security Analyst: GRC & Vendor Risk

Scale Up Recruiting Partners • San Juan (PR)

On-site
USD 90,000 - 130,000
Information Security Client and Vendor Risk Manager
Information Security Client and Vendor Risk Manager

KamisPro • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Security Compliance Analyst
Security Compliance Analyst

Managed IT & Security Provider • Alexandria (VA)

On-site
USD 75,000 - 100,000
401(k)
401(k) matching
Bonus based on performance
+3
Vendor Cybersecurity Auditor #2945
Vendor Cybersecurity Auditor #2945

Genius Road, LLC • Austin (TX)

On-site
USD 85,000 - 115,000
Opportunities for professional growth
Collaborative work environment
High visibility within the team
Security Compliance Analyst
Security Compliance Analyst

Sur • United States

On-site
USD 22,000 - 33,000
Supply Chain Analyst (Vendor & Supply Chain Risk)
Supply Chain Analyst (Vendor & Supply Chain Risk)

Crux Security • Austin (TX)

Hybrid
USD 90,000 - 130,000
Remote Senior Cybersecurity & Compliance Consultant (HIPAA, NIST & SOC 2)
Remote Senior Cybersecurity & Compliance Consultant (HIPAA, NIST & SOC 2)

Thehelloteam • New York (NY)

Hybrid
USD 100,000 - 130,000
Long-term growth opportunities
Flexible remote work environment
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Security Engineer (Vendor and Network Security)
Security Engineer (Vendor and Network Security)

PTR Global • Sunnyvale (CA)

Hybrid
USD 61,992 - 75,768