Lyft2 дня назад
Senior Security Assurance Analyst
Зарплата не указана
New York
Обязанности
- 01Own and lead ISO 27001 compliance program end-to-end
- 02Drive execution across multi-program compliance portfolio (SOC 2, PCI DSS, HIPAA, NIST CSF, UK Cyber Essentials, Spain ENS, EU regulations)
- 03Serve as primary liaison to external auditors and certification bodies
- 04Own Security Risk Management Framework
- 05Lead development and maintenance of information security policies and procedures
- 06Build cross-functional relationships with Engineering, Legal, Privacy, Sales
- 07Support review of security provisions in customer contracts
- 08Drive evidence collection and continuous control testing using workflow tools
- 09Partner with Engineering to design automated evidence collection and monitoring
- 10Leverage AI tools to automate compliance processes
- 11Own responses to customer security questionnaires and manage external trust center
Требования
- 015+ years of experience in security governance, risk, and compliance (GRC), IT audit, or related security assurance role
- 025+ years of hands-on experience with ISO 27001 and PCI DSS
- 03In-depth knowledge of regulatory compliance including SOC 2, HIPAA, NIST CSF
- 04Experience managing multi-program compliance portfolio spanning global requirements
- 05Experience managing, reviewing, and drafting InfoSec policies and procedures
- 06Strong technical background with ability to communicate effectively with engineering teams
- 07Excellent cross-functional communication and leadership skills
- 08Ability to manage large workload and competing priorities
- 09Strong written and verbal communication skills