Lyft2 дня назад

Senior Security Assurance Analyst

Зарплата не указана
New York

Обязанности

  • 01Own and lead ISO 27001 compliance program end-to-end
  • 02Drive execution across multi-program compliance portfolio (SOC 2, PCI DSS, HIPAA, NIST CSF, UK Cyber Essentials, Spain ENS, EU regulations)
  • 03Serve as primary liaison to external auditors and certification bodies
  • 04Own Security Risk Management Framework
  • 05Lead development and maintenance of information security policies and procedures
  • 06Build cross-functional relationships with Engineering, Legal, Privacy, Sales
  • 07Support review of security provisions in customer contracts
  • 08Drive evidence collection and continuous control testing using workflow tools
  • 09Partner with Engineering to design automated evidence collection and monitoring
  • 10Leverage AI tools to automate compliance processes
  • 11Own responses to customer security questionnaires and manage external trust center

Требования

  • 015+ years of experience in security governance, risk, and compliance (GRC), IT audit, or related security assurance role
  • 025+ years of hands-on experience with ISO 27001 and PCI DSS
  • 03In-depth knowledge of regulatory compliance including SOC 2, HIPAA, NIST CSF
  • 04Experience managing multi-program compliance portfolio spanning global requirements
  • 05Experience managing, reviewing, and drafting InfoSec policies and procedures
  • 06Strong technical background with ability to communicate effectively with engineering teams
  • 07Excellent cross-functional communication and leadership skills
  • 08Ability to manage large workload and competing priorities
  • 09Strong written and verbal communication skills