Security Compliance Analyst
hace 1 día
Reporting to the Security Compliance Manager, the Security Compliance Analyst is a key member of the Security, Governance and Compliance team. This position is focused on PCI and SOC1/SOC2 compliance, working across multiple business units and markets globally to ensure and deliver upon our annual compliance assessments and improve our security compliance posture overall. The Security Compliance Analyst will work closely with Information Security leadership and management team members to build and maintain a strong security compliance practice, while ensuring ongoing delivery on our compliance obligations. _
- The role requires attention to detail, technical expertise, and control testing experience with strong people skills. Must have the ability to build trusted relationships and influence decisions around security risk and compliance management. _
**What you’ll do**:
- Support management of the PCI and SOC compliance process from end to end including pre-assessments, contracting, planning, scheduling, walkthroughs, testing, evidence collection, reporting, and remediation.
- Conduct multiple annual compliance reports and enterprise-level security assessments on Equifax systems globally (e.g. PCI-DSS, FISMA, FedRAMP, NIST, etc).
- Perform compliance scope advisement for both on-premises and cloud environments to determine applicable security compliance requirements for an environment.
- Support evidence collection with regards to various security compliance frameworks including SOC, PCI-DSS, FISMA, FedRAMP, NIST, etc.
- Collaborate with multiple departments and cross functional teams
- Assist with analysis of security control mapping and compliance efficiency improvements.
- Assist in maturing security compliance via automation or other tools
- Provide reporting and trending information of identified risks to compliance timelines
- Organize, publish, and maintain audit evidence and related documents in such a way that information is easily accessible
- Assist Global Security Compliance team in other tasks as required
- Perform compliance scope advisement for both on-premises and cloud environments to determine applicable security compliance requirements for an environment.
- Monitor and communicate program measures of success, plans, status, issues and risks in a timely manner to team members, stakeholders and senior level management.
- Identify industry best practices and recommend program updates or changes as needed to ensure program success.
- Proactively advise management and staff about potential security or compliance risks that may have a material impact on the business.
- Report to management and senior leadership on KPI's and KRI's for compliance programs (NIST, PCI-DSS, FISMA, FedRAMP, NYDFS500, SOC1/2 and ISO 27001).
- Perform program risk management and identify and assist BU/Applications teams with appropriate remediation guidance for identified compliance gaps.
**What experience you need**:
- Security Certifications such as CISSP, CCSP, CISA, CISM, QSA/ISA, CompTIA, etc.
- 3-5 years experience in **PCI or SOC1/2 audits **or directly related audit experience
- 3-5 years of experience performing assessments of information security programs including detailed control testing demonstrating thorough understanding of information security practices and methodologies, and public cloud environments (GCP, AWS, and Azure) and familiarity with security best practices
- 3-5 years experience testing and reviewing controls related to IT concepts, cloud services (IaaS, PaaS, SaaS), networking concepts (routers, firewalls, cloud networking rules), security tools (SIEM, IDS/IPS, FIM, A/V), virtualization, and tokenization
**What could set you apart**:
- Bachelor’s Degree in Cybersecurity, Information Systems, Information Security, Information Technology, or comparable major strongly preferred
- Consulting experience (Big 4) much preferred
- Familiarity with project management, Wiz, ServiceNow preferred
- Excellent organizational, time management, customer service and problem-solving skills
LI-DU1
LI-Hybrid
-
Security Compliance Analyst
hace 1 semana
San José, Costa Rica Equifax A tiempo completoEquifax is where you can power yours possibly. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you. Equifax is a dynamic organization committed to maintaining the highest standards of compliance and data security. We are actively seeking an ISO...
-
Security Compliance Analyst
hace 5 días
San José, Costa Rica Equifax A tiempo completoEquifax is where you can power yours possibly.If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you.Equifax is a dynamic organization committed to maintaining the highest standards of compliance and data security.We are actively seeking an ISO...
-
Security Risk Analyst
hace 1 semana
San José, Costa Rica Splunk OLD (Read Only) A tiempo completoSplunk is the leader in big data and machine learning analytics, with a significant presence in the cybersecurity market. Join us as we pursue our disruptive vision to make machine data accessible, usable, and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best experience for our...
-
Security Compliance Audit
hace 2 días
San José, Costa Rica DXC Technology A tiempo completoBecome familiar with SOC audit and security compliance requirements to effectively communicate DXC security standards and SOC audit requirements (e.g., SSAE 18, ISAE 3000, ISAE 3402) as needed to help DXC teams achieve successful audit outcomes. - Understand in-country regulatory requirements with regards to sharing of data internal and external to DXC. -...
-
Security Governance Analyst
hace 5 días
San José, Costa Rica Splunk A tiempo completo**About SPLUNK**:Splunk is the leader in big data and machine learning analytics, with a significant presence in the cybersecurity market.Join us as we pursue our disruptive vision to make machine data accessible, usable, and valuable to everyone.We are a company filled with people who are passionate about our product and seek to deliver the best experience...
-
Security and Compliance Officer
hace 3 días
San José, Costa Rica DXC Technology A tiempo completoRole Responsibilities_ - 2. ASO and ACO will act as trusted advisors to DXC delivery personnel to ensure the ongoing effectiveness of service delivery. Review and optimize security delivery processes to ensure the appropriateness of ongoing service delivery._ - 3. Organize security review meetings between DXC and Customer following an agreed schedule;...
-
Security Compliance Analyst
hace 5 días
San José, Costa Rica Equifax A tiempo completoEquifax is where you can power your possible.If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you.**What you'll do**- Working knowledge in relation to public cloud fundamentals, concepts and services and be able to analyze adherence to industry...
-
Security Analyst
hace 4 días
San José, Costa Rica Catalina Marketing A tiempo completo**Why Catalina?** Catalina delivers omni-channel solutions to our customers with a long-standing history of rich data assets, but our _greatest _asset is our people.Our guiding principles set the stage for winning in the markets we serve, and our potential is powerful.When you join the Catalina team, you will be part of an inclusive environment that embraces...
-
Compliance Security Specialist
hace 5 días
San José, San José, Costa Rica Experian A tiempo completoExperian, a leading global information services company, unlocks data power to create opportunities for consumers, businesses, and society. As one of the 100 Best Companies to work for, FORTUNE has named us, and we've been recognized as Great Place To Work (GPTW) certified for three years.We're redefining customer credit lifecycle management with...
-
Security Analyst
hace 5 días
San José, Costa Rica Smartsheet A tiempo completoCyber Security is an integral part of Smartsheet's corporate culture.At Smartsheet, we believe that it is the responsibility of each and every employee to safeguard information, protect it from unauthorized access, and ensure regulatory compliance.Cyber Security has a significant effect on privacy, consumer trust, external reputation, and it is a priority on...
-
Senior Security Operations Analyst
hace 5 días
San José, Costa Rica Cloudpay A tiempo completoAs a security analyst you will form part of a team which is led by a security operations lead you will be the first point of defense for the company's security operations Centre as a fast growing company we face growing threats every day the role of the analyst will be important as they will be the first in dealing with incoming security alerts of...
-
Senior Security Operations Analyst
hace 5 días
San José, Costa Rica Cloudpay A tiempo completoAs a security analyst you will form part of a team which is led by a security operations lead you will be the first point of defence for the company's security operations Centre as a fast growing company we face growing threats every day the role of the analyst will be important as they will be the first in dealing with incoming security alerts of...
-
Sap Security Analyst
hace 5 días
San José, Costa Rica Emerson A tiempo completoThe SAP Security Analyst will be responsible to learn the security designs in all the Emerson Automation Solutions SAP Systems and execute improvement and design standardization that results in a lower support complexity.This position may interface with Internal & External audit teams and is responsible for execution and submission of audit requests as...
-
Security Analyst
hace 5 días
San José, Costa Rica Smartsheet A tiempo completoCyber Security is an integral part of Smartsheet's corporate culture.At Smartsheet, we believe that it is the responsibility of each and every employee to safeguard information, protect it from unauthorized access, and ensure regulatory compliance.Cyber Security has a significant effect on privacy, consumer trust, external reputation, and it is a priority on...
-
Risk Compliance Security Specialist
hace 5 días
San José, San José, Costa Rica Equifax A tiempo completoAbout UsAt Equifax, we empower individuals to achieve their full potential by fostering a culture of innovation and collaboration.We are seeking a skilled Risk Compliance Security Specialist to join our team. This role will be responsible for supporting security governance and compliance activities globally and ensuring the success of business by working...
-
Security Deviations Analyst Entry
hace 5 días
San José, Costa Rica Equifax A tiempo completoEquifax is where you can power your possible.If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you.The position is an active member of the Security Governance and Compliance team responsible for supporting security governance and compliance...
-
Governance Risk
hace 5 días
San José, Costa Rica Mondelez International A tiempo completo**Are You Ready to Make It Happen at Mondelez International?****Join our Mission to Lead the Future of Snacking.Make It Uniquely Yours.**You work with the information security team as a competent and experienced information security and compliance specialist.**How you will contribute****What you will bring**A desire to drive your future and accelerate your...
-
Security Compliance Reviewer
hace 5 días
San José, Costa Rica Equifax A tiempo completo**What you'll do**- Manages and complete security questionnaires, evidence or RFP's audits.- Evaluates and audits customer, organization and supplier systems to credential, review, assess and determine systems, information and data vulnerabilities.- Conducts ongoing security and risk assessments, audits to compliance with credentials and evaluates...
-
Security & Compliance Technical Specialist
hace 5 días
San José, Costa Rica Microsoft Corporation A tiempo completoThe Technology Solutions team consists of highly capable pre-sales individuals that drive Microsoft wins on the latest cloud and modern development technologies.Digital Technical Specialist's main goal is to win the technical decision of customers to purchase, implement and use our online services and solutions.You will work in a team, enabling the customers...
-
Technical Security and Compliance Specialist
hace 5 días
San José, San José, Costa Rica Microsoft A tiempo completoAt Microsoft, we strive to create a secure and connected customer experience. Our Customer Service & Support (CSS) organization is responsible for building trust and confidence with our customers through seamless support experiences.The Security, Compliance, Identity and Management (SCIM) team was created to further enable our commitment to security strategy...