Security Compliance Analyst

hace 2 semanas


San José, Costa Rica Equifax A tiempo completo

Reporting to the Security Compliance Manager, the Security Compliance Analyst is a key member of the Security, Governance and Compliance team. This position is focused on PCI and SOC1/SOC2 compliance, working across multiple business units and markets globally to ensure and deliver upon our annual compliance assessments and improve our security compliance posture overall. The Security Compliance Analyst will work closely with Information Security leadership and management team members to build and maintain a strong security compliance practice, while ensuring ongoing delivery on our compliance obligations. _
- The role requires attention to detail, technical expertise, and control testing experience with strong people skills. Must have the ability to build trusted relationships and influence decisions around security risk and compliance management. _

**What you’ll do**:

- Support management of the PCI and SOC compliance process from end to end including pre-assessments, contracting, planning, scheduling, walkthroughs, testing, evidence collection, reporting, and remediation.
- Conduct multiple annual compliance reports and enterprise-level security assessments on Equifax systems globally (e.g. PCI-DSS, FISMA, FedRAMP, NIST, etc).
- Perform compliance scope advisement for both on-premises and cloud environments to determine applicable security compliance requirements for an environment.
- Support evidence collection with regards to various security compliance frameworks including SOC, PCI-DSS, FISMA, FedRAMP, NIST, etc.
- Collaborate with multiple departments and cross functional teams
- Assist with analysis of security control mapping and compliance efficiency improvements.
- Assist in maturing security compliance via automation or other tools
- Provide reporting and trending information of identified risks to compliance timelines
- Organize, publish, and maintain audit evidence and related documents in such a way that information is easily accessible
- Assist Global Security Compliance team in other tasks as required
- Perform compliance scope advisement for both on-premises and cloud environments to determine applicable security compliance requirements for an environment.
- Monitor and communicate program measures of success, plans, status, issues and risks in a timely manner to team members, stakeholders and senior level management.
- Identify industry best practices and recommend program updates or changes as needed to ensure program success.
- Proactively advise management and staff about potential security or compliance risks that may have a material impact on the business.
- Report to management and senior leadership on KPI's and KRI's for compliance programs (NIST, PCI-DSS, FISMA, FedRAMP, NYDFS500, SOC1/2 and ISO 27001).
- Perform program risk management and identify and assist BU/Applications teams with appropriate remediation guidance for identified compliance gaps.

**What experience you need**:

- Security Certifications such as CISSP, CCSP, CISA, CISM, QSA/ISA, CompTIA, etc.
- 3-5 years experience in **PCI or SOC1/2 audits **or directly related audit experience
- 3-5 years of experience performing assessments of information security programs including detailed control testing demonstrating thorough understanding of information security practices and methodologies, and public cloud environments (GCP, AWS, and Azure) and familiarity with security best practices
- 3-5 years experience testing and reviewing controls related to IT concepts, cloud services (IaaS, PaaS, SaaS), networking concepts (routers, firewalls, cloud networking rules), security tools (SIEM, IDS/IPS, FIM, A/V), virtualization, and tokenization

**What could set you apart**:

- Bachelor’s Degree in Cybersecurity, Information Systems, Information Security, Information Technology, or comparable major strongly preferred
- Consulting experience (Big 4) much preferred
- Familiarity with project management, Wiz, ServiceNow preferred
- Excellent organizational, time management, customer service and problem-solving skills

LI-DU1
LI-Hybrid



  • San José, San José, Costa Rica Splunk Old (Read Only) A tiempo completo

    About SplunkSplunk Old (Read Only) is a company dedicated to making machine data accessible, usable, and valuable to everyone. We strive to deliver the best possible experience for our customers while pursuing a disruptive new vision.We are committed to the success of our customers and believe that building trust through our products and services is...


  • San José, Costa Rica Equifax A tiempo completo

    Equifax is where you can power yours possibly. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you. Equifax is a dynamic organization committed to maintaining the highest standards of compliance and data security. We are actively seeking an ISO...

  • Security Risk Analyst

    hace 4 semanas


    San José, Costa Rica Catalina Marketing A tiempo completo

    **Why Catalina?** Catalina delivers omni-channel solutions to our customers with a long-standing history of rich data assets, but our _greatest _asset is our people. Our guiding principles set the stage for winning in the markets we serve, and our potential is powerful. When you join the Catalina team, you will be part of an inclusive environment that...

  • Security Risk Analyst

    hace 12 horas


    San José, Costa Rica Catalina Marketing A tiempo completo

    **Why Catalina?** Catalina delivers omni-channel solutions to our customers with a long-standing history of rich data assets, but our _greatest _asset is our people. Our guiding principles set the stage for winning in the markets we serve, and our potential is powerful. When you join the Catalina team, you will be part of an inclusive environment that...


  • San José, San José, Costa Rica Bacardi A tiempo completo

    Company OverviewAbout UsBacardi is a leading spirits company with a rich history of innovation and commitment to quality. We are dedicated to delivering exceptional customer experiences and building strong relationships with our partners.Job DescriptionKey ResponsibilitiesAssist in the management of Bacardi's compliance programs relating to third-party risk...

  • Security Compliance Audit

    hace 2 semanas


    San José, Costa Rica DXC Technology A tiempo completo

    Become familiar with SOC audit and security compliance requirements to effectively communicate DXC security standards and SOC audit requirements (e.g., SSAE 18, ISAE 3000, ISAE 3402) as needed to help DXC teams achieve successful audit outcomes. - Understand in-country regulatory requirements with regards to sharing of data internal and external to DXC. -...


  • San José, Costa Rica Splunk A tiempo completo

    **About SPLUNK**: Splunk is the leader in big data and machine learning analytics, with a significant presence in the cybersecurity market. Join us as we pursue our disruptive vision to make machine data accessible, usable, and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best...

  • Security Risk Analyst

    hace 3 semanas


    San José, Costa Rica Splunk OLD (Read Only) A tiempo completo

    Splunk is the leader in big data and machine learning analytics, with a significant presence in the cybersecurity market. Join us as we pursue our disruptive vision to make machine data accessible, usable, and valuable to everyone. We are a company filled with people who are passionate about our product and seek to deliver the best experience for our...


  • San José, Costa Rica DXC Technology A tiempo completo

    Role Responsibilities_ - 2. ASO and ACO will act as trusted advisors to DXC delivery personnel to ensure the ongoing effectiveness of service delivery. Review and optimize security delivery processes to ensure the appropriateness of ongoing service delivery._ - 3. Organize security review meetings between DXC and Customer following an agreed schedule;...


  • San José, Costa Rica Equifax A tiempo completo

    Equifax is where you can power your possible. If you want to achieve your true potential, chart new paths, develop new skills, collaborate with bright minds, and make a meaningful impact, we want to hear from you. **What you’ll do** - Working knowledge in relation to public cloud fundamentals, concepts and services and be able to analyze adherence to...

  • Security Analyst

    hace 3 semanas


    San José, San José, Costa Rica Catalina Marketing A tiempo completo

    **Why Catalina?** Catalina delivers omni-channel solutions to our customers with a long-standing history of rich data assets, but our _greatest _asset is our people.Our guiding principles set the stage for winning in the markets we serve, and our potential is powerful.When you join the Catalina team, you will be part of an inclusive environment that embraces...


  • San Francisco, Heredia, Costa Rica Equifax A tiempo completo

    **About the Role:**We are seeking a seasoned Security Compliance Officer to join our team at Equifax. As a key member of our security team, you will be responsible for ensuring that IT solutions are designed, built, deployed, and maintained in compliance with our security policies and standards.You will collaborate with Security, IT, and Business partners in...

  • SAP Security Analyst

    hace 4 semanas


    San José, Costa Rica Emerson A tiempo completo

    The SAP Security Analyst will be responsible to learn the security designs in all the Emerson Automation Solutions SAP Systems and execute improvement and design standardization that results in a lower support complexity. This position may interface with Internal & External audit teams and is responsible for execution and submission of audit requests as...


  • San José, San José, Costa Rica Equifax A tiempo completo

    **What you'll do**- Manages and complete security questionnaires, evidence or RFP's audits.- Evaluates and audits customer, organization and supplier systems to credential, review, assess and determine systems, information and data vulnerabilities.- Conducts ongoing security and risk assessments, audits to compliance with credentials and evaluates...

  • Security Analyst

    hace 4 semanas


    San José, Costa Rica Smartsheet A tiempo completo

    Cyber Security is an integral part of Smartsheet's corporate culture. At Smartsheet, we believe that it is the responsibility of each and every employee to safeguard information, protect it from unauthorized access, and ensure regulatory compliance. Cyber Security has a significant effect on privacy, consumer trust, external reputation, and it is a priority...


  • San José, Costa Rica cloudpay A tiempo completo

    As a security analyst you will form part of a team which is led by a security operations lead you will be the first point of defense for the company’s security operations Centre as a fast growing company we face growing threats every day the role of the analyst will be important as they will be the first in dealing with incoming security alerts of threats....


  • San José, Costa Rica Equifax A tiempo completo

    The Security Compliance Reviewer manages the security credentialing process for organization. Evaluates and audits customer, organization and supplier systems to credential, review, assess and determine systems, information and data vulnerabilities. Conducts ongoing security and risk assessments, audits to comply with credentials and evaluate vulnerabilities...


  • San José, Costa Rica Equifax A tiempo completo

    The Security Compliance Reviewer manages the security credentialing process for organization. Evaluates and audits customer, organization and supplier systems to credential, review, assess and determine systems, information and data vulnerabilities. Conducts ongoing security and risk assessments, audits to comply with credentials and evaluate vulnerabilities...


  • San José, San José, Costa Rica Bacardi A tiempo completo

    Role OverviewThe Tech Compliance Analyst role plays a critical part in implementing and managing information security compliance and privacy objectives at Bacardi. This position will be responsible for assisting in the management of Bacardi's compliance programs relating to third-party risk management, security awareness training, audit support, policy...


  • San Francisco, Heredia, Costa Rica Citi A tiempo completo

    As a Unix Risk & Control Senior Analyst, you will contribute to the delivery of critical technical foundation for Citi's operations through the infrastructure that runs business and general user computing services. You will work closely with Unix System Administrator teams and Risk Management teams to maintain an effective control environment and minimize...