Security Compliance Specialist

Military, Veterans and Diverse Job Seekers

San Jose (CA)

On-site

USD 110,000 - 160,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Military, Veterans and Diverse Job Seekers is seeking a Security Compliance Specialist to advance our information security program. You will maintain governance, risk management, and compliance for ISO 27001 while enhancing the security framework, controls, and audit readiness.

The role requires coordinating audits (ISO27001, ISO9001, SOX) and managing vendor risk with cross-functional teams.

Qualifications

  • 5+ years in information security risk and governance.
  • Bachelor's degree in risk management or information security or related discipline.
  • Strong knowledge of security principles and risk management.
  • Experience with ISO27001 and NIST-800.
  • Excellent verbal and written communication skills to document, communicate findings, and interact with business customers.

Responsibilities

  • Maintain strong governance, risk, and compliance processes for ISO 27001.
  • Continuously improve the security framework, methodology, standards, and internal controls.
  • Govern NCR process and ensure corrective actions are completed.
  • Establish and monitor performance metrics, trending reports, and KPIs.
  • Create and maintain internal governing documents for ISO27001 auditing procedures and internal controls.
  • Assess information security risks, threats, vulnerabilities, and impact.
  • Serve as the main contact for audits such as ISO27001, ISO9001, SOX, policy, and data privacy.
  • Create, manage, and document SOPs and guidelines.
  • Develop security awareness training content and deliver to employees.
  • Manage third-party, supply chain, and cloud vendor risk reduction programs.
  • Perform security risk assessments and identify mitigations for new projects.

Skills

Risk management
Governance
Information security
ISO27001
NIST-800
Auditing
Documentation
Security awareness
Vendor risk management
Project management

Education

Bachelor's degree in risk management
Bachelor's degree in information security
Related discipline

Job description

About the job Security Compliance Specialist

Responsibilities:

  • Support the maintenance of strong governance, risk, and the compliance process for ISO 27001.
  • Continuously improve the security framework, methodology, standards, and system of internal controls.
  • Govern the NCR process and ensure corrective actions are completed.
  • Establish and monitor performance metrics, trending reports, and KPI.
  • Create and maintain internal governing documents for compliance with ISO 27001 various auditing procedures and internal security controls.
  • Regularly examine the organization's information security risks, analyzing threats, vulnerabilities, and impact.
  • Serve as the main point of contact for all compliance audits such as ISO27001, ISO9001, SOX, security policy, and data privacy as needed.
  • Create, manage, and document standard operating procedures and best practice guidelines.
  • Develop security awareness training content, campaigns; deliver training to employees.
  • Manage third-party, supply chain, and cloud vendor risk reduction and mitigation programs.
  • Perform security risk assessment and identify risk mitigations for new projects, programs, etc.
  • Act as the project manager for security projects to track deliverables, and identify risks.
  • Responsible for daily security monitoring, detections, and investigations.
  • Support the team with other areas of security and governance as needed.

Requirements:

  • Preferred 5+ years in Information Security risk and governance experience.
  • Bachelors degree in risk management, information security, or related discipline.
  • Strong knowledge of security principles and risk management
  • Experience with ISO27001 and NIST-800 are a must
  • Excellent verbal and written communication skills to document, communicate findings, and interact with business customers.

Preferred Requirements:

  • CISSP or CISA Security Certification a plus
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ISO 27001 Compliance & Risk Specialist
ISO 27001 Compliance & Risk Specialist

Military, Veterans and Diverse Job Seekers • San Jose (CA)

On-site
USD 110,000 - 160,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Information Security Officer (ISO)
Information Security Officer (ISO)

Gainwell Furniture Co. • Grand Rapids (MI)

Remote
USD 120,000 - 150,000
Flexible vacation policy
401(k) employer match
Comprehensive health benefits
+3
Infosec or GRC Leader
Infosec or GRC Leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 95,000 - 130,000
ISMS Compliance Manager
ISMS Compliance Manager

Hexagon Mining • Tucson (AZ)

On-site
USD 90,000 - 120,000
GRC Security compliance leader
GRC Security compliance leader

Avantdigitalnow • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Information Security Engineer
Senior Information Security Engineer

Grayson Search Partners • Nashville (TN)

On-site
USD 120,000 - 150,000
ServiceNow Administrator / Developer
ServiceNow Administrator / Developer

Cynosure IT Innovations LLC • Chicago (IL)

On-site
USD 120,000 - 160,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus
Senior Manager of Information Security
Senior Manager of Information Security

Plume • United States

On-site
USD 180,000 - 240,000