Security Compliance Analyst
New
M
MasabiSecurity compliance
This role is only available to candidates based in Colombia in a fully remote model.Full-Time
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Required Skills
- Risk Management
Requirements
- Have hands-on experience in information security, IT compliance, internal control, audit, or a similar field.
- Have a working understanding of access control, risk management, and data protection.
- Be curious about technology and interested in how systems, cloud services, and SaaS tools fit together.
- Write clearly and structure information effectively for documentation, registers, and questionnaire answers.
- Be organized enough to manage recurring tasks and multiple deadlines.
- Take ownership of work and ask questions when requirements are unclear.
- Third-Party Risk Management or vendor security assessment experience is a plus.
- Knowledge of ISO 27001, SOC 2, PCI DSS, GDPR, or NIST is a plus.
- Experience supporting RFPs, tenders, or customer security questionnaires is a plus.
- Experience with compliance automation or GRC platforms is a plus.
- Interest in automation, scripting, low-code tools such as n8n or Make, or using AI to improve workflows is a plus.
- Experience with Jira or Confluence is a plus.
Responsibilities
- Own assigned security control processes from planning and execution through evidence gathering and findings follow-up.
- Perform manual and tool-based security controls and help address gaps in control coverage or consistency.
- Carry out regular reviews, including user access reviews, and record results and actions.
- Run the Third-Party Risk Management process by assessing suppliers, reviewing their security posture, tracking risks, and scheduling reassessments.
- Maintain accurate and current supplier, risk, asset, and data processing registers.
- Analyze security and privacy requirements in bids and tenders and help prepare responses.
- Respond to customer security questionnaires and information requests.
- Prepare evidence and documentation to support audits and certifications, including ISO 27001, SOC 2, PCI DSS, and Cyber Essentials.
- Identify opportunities to automate or improve control processes, including with AI tools.
View Full Description & ApplyYou'll be redirected to the employer's site