Security Compliance Analyst
Filevine · Information Technology
- Location: Salt Lake City (United States of America)
- Work arrangement: hybrid
- Employment type: Full Time
- Seniority: senior
- Posted:
Job description
Position:
Security Compliance Analyst
Company:
Filevine
Location:
United States, Salt Lake City, Utah
Employment type:
Full-time
Work Arrangement:
On-site
Short Summary:
Filevine is looking for a High Security Compliance Analyst to join our Information Security team to ensure that our platform, applications, and infrastructure are compliant and secured at the highest levels thus protecting and enhancing customer trust.
Responsibilities:
- Manage CJIS obligations, including monthly and yearly audits, clearances for employees, and associated CJIS efforts
- Assist with Federal and international government security audits (e.g. FedRAMP, StateRAMP, Canadian government compliance obligations)
- Strategize and outline goals and objectives of the GRC (IT Audit and Risk management) programs
- Assist with security efforts to meet HIPAA, SOC 2 Type I & II, and other compliance requirements
- Work directly with Information Security, Legal, HR, Compliance and Development teams to ensure secure IT and IS best practices are fully adopted at Filevine
- Help train employees on auditing secure coding techniques to mitigate the need for break-fix/out-of-band patching
- Review audit, compliance and risk assessment issues that arise and manage them to resolution
- Provide audit frameworks and risk assessment methodologies contemplating new software solutions to help mitigate security vulnerabilities and other business risks
- Maintain documented Policy and Procedure libraries for compliance purposes
- Complete Third-party vendor risk management and security questionnaires for Filevine
- Provide annual Internal audit and risk assessment functions
- Facilitate and lead annual penetration testing and auditing efforts
- Develop a familiarity with new auditing and risk assessment tools and techniques
Requirement:
- Bachelor's Degree or equivalent in Computer Science, Computer Engineering, Information Technology, or related field
- 4+ years of experience in IT Auditing, Compliance Analyst and/or direct experience related to risk assessment methodologies
- Proven work experience as IT Audit & Risk Assessor with a passion for details and security
- Familiarity with auditing and assessing the OWASP Top 10
- Experience with managing risks, fraud, and security threats
- Knowledge of web related technologies and of network/web related protocols
- Experience assessing, testing, or auditing technical IT and security controls
- Working knowledge of and demonstrated experience with ISO 27701, ISO 27018, ISO 27001
- Experience with FedRAMP is preferred, as well as SOC II Type I & II, HIPAA Security Rule, CJIS, GDPR, CCPA/CPRA and other compliance frameworks
- Demonstrated knowledge of assessing development methodologies (Agile, Waterfall)
- Excellent oral and written communication skills with the ability to communicate security concepts to a technical and non-technical audience including senior management
Benefits:
- A dynamic, rapidly growing company, focused on helping organizations thrive
- Medical, Dental, & Vision Insurance (for full-time employees)
- Competitive & Fair Pay
- Maternity & paternity leave (for full-time employees)
- Short & long-term disability
- Opportunity to learn from a dedicated leadership team
- Top-of-the-line company swag
Security Compliance Analyst
Company:
Filevine
Location:
United States, Salt Lake City, Utah
Employment type:
Full-time
Work Arrangement:
On-site
Short Summary:
Filevine is looking for a High Security Compliance Analyst to join our Information Security team to ensure that our platform, applications, and infrastructure are compliant and secured at the highest levels thus protecting and enhancing customer trust.
Responsibilities:
- Manage CJIS obligations, including monthly and yearly audits, clearances for employees, and associated CJIS efforts
- Assist with Federal and international government security audits (e.g. FedRAMP, StateRAMP, Canadian government compliance obligations)
- Strategize and outline goals and objectives of the GRC (IT Audit and Risk management) programs
- Assist with security efforts to meet HIPAA, SOC 2 Type I & II, and other compliance requirements
- Work directly with Information Security, Legal, HR, Compliance and Development teams to ensure secure IT and IS best practices are fully adopted at Filevine
- Help train employees on auditing secure coding techniques to mitigate the need for break-fix/out-of-band patching
- Review audit, compliance and risk assessment issues that arise and manage them to resolution
- Provide audit frameworks and risk assessment methodologies contemplating new software solutions to help mitigate security vulnerabilities and other business risks
- Maintain documented Policy and Procedure libraries for compliance purposes
- Complete Third-party vendor risk management and security questionnaires for Filevine
- Provide annual Internal audit and risk assessment functions
- Facilitate and lead annual penetration testing and auditing efforts
- Develop a familiarity with new auditing and risk assessment tools and techniques
Requirement:
- Bachelor's Degree or equivalent in Computer Science, Computer Engineering, Information Technology, or related field
- 4+ years of experience in IT Auditing, Compliance Analyst and/or direct experience related to risk assessment methodologies
- Proven work experience as IT Audit & Risk Assessor with a passion for details and security
- Familiarity with auditing and assessing the OWASP Top 10
- Experience with managing risks, fraud, and security threats
- Knowledge of web related technologies and of network/web related protocols
- Experience assessing, testing, or auditing technical IT and security controls
- Working knowledge of and demonstrated experience with ISO 27701, ISO 27018, ISO 27001
- Experience with FedRAMP is preferred, as well as SOC II Type I & II, HIPAA Security Rule, CJIS, GDPR, CCPA/CPRA and other compliance frameworks
- Demonstrated knowledge of assessing development methodologies (Agile, Waterfall)
- Excellent oral and written communication skills with the ability to communicate security concepts to a technical and non-technical audience including senior management
Benefits:
- A dynamic, rapidly growing company, focused on helping organizations thrive
- Medical, Dental, & Vision Insurance (for full-time employees)
- Competitive & Fair Pay
- Maternity & paternity leave (for full-time employees)
- Short & long-term disability
- Opportunity to learn from a dedicated leadership team
- Top-of-the-line company swag
Skills
- owasp
Languages
EN
Apply
Open this job in our interactive board to apply, save it, or sign up for matched alerts on similar roles.
View & apply