Security Compliance Analyst

New
M
MasabiSecurity compliance
This role is only available to candidates based in Colombia in a fully remote model.Full-Time
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Required Skills
Risk Management

Requirements

  • Have hands-on experience in information security, IT compliance, internal control, audit, or a similar field.
  • Have a working understanding of access control, risk management, and data protection.
  • Be curious about technology and interested in how systems, cloud services, and SaaS tools fit together.
  • Write clearly and structure information effectively for documentation, registers, and questionnaire answers.
  • Be organized enough to manage recurring tasks and multiple deadlines.
  • Take ownership of work and ask questions when requirements are unclear.
  • Third-Party Risk Management or vendor security assessment experience is a plus.
  • Knowledge of ISO 27001, SOC 2, PCI DSS, GDPR, or NIST is a plus.
  • Experience supporting RFPs, tenders, or customer security questionnaires is a plus.
  • Experience with compliance automation or GRC platforms is a plus.
  • Interest in automation, scripting, low-code tools such as n8n or Make, or using AI to improve workflows is a plus.
  • Experience with Jira or Confluence is a plus.

Responsibilities

  • Own assigned security control processes from planning and execution through evidence gathering and findings follow-up.
  • Perform manual and tool-based security controls and help address gaps in control coverage or consistency.
  • Carry out regular reviews, including user access reviews, and record results and actions.
  • Run the Third-Party Risk Management process by assessing suppliers, reviewing their security posture, tracking risks, and scheduling reassessments.
  • Maintain accurate and current supplier, risk, asset, and data processing registers.
  • Analyze security and privacy requirements in bids and tenders and help prepare responses.
  • Respond to customer security questionnaires and information requests.
  • Prepare evidence and documentation to support audits and certifications, including ISO 27001, SOC 2, PCI DSS, and Cyber Essentials.
  • Identify opportunities to automate or improve control processes, including with AI tools.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now