This role provides information security and compliance assistance through controls analysis, risk assessments, and policy development. The analyst manages security due diligence questionnaires and supports internal and external audit activities.
Overview
Under the general supervision of the Director, ISMS, this position provides information security and compliance assistance through operations and controls analysis, policy and procedure development, risk assessments, and development/execution of remediation efforts.
Responsibilities
- Provide quality internal and external customer service surrounding the Company values.
- Serve customers with the highest degree of courtesy and professionalism.
- Monitor the Compliance mailbox, handling client requests, updates, and coordination with other departments within the company for information on the organization’s information security management systems and quality management systems.
- Prepare written responses to routine security and compliance inquiries by preparing, and modifying documents including correspondence, reports, drafts, memos, and emails.
- Handle customers’ security due diligence questionnaires.
- Review, track and distribution the Company’s compliance report to customers.
- Assist the Sales organization with Requests for Proposals on security and compliance-related information.
- Coordinate with Information Security on policy development.
- Support both internal and external audit activities including records collection, and coordinating with other departments to collate all relevant information.
- Accuracy, detail orientation, and analytical skills needed.
- High degree of confidentiality.
- Other duties as assigned.
Qualifications
- Fundamental understanding of information security best practices.
- Fundamental understanding of information security audit frameworks including AICPA SOC 1 and SOC 2, NIST standards, PCI-DSS, HIPAA and ISO 27001, ISO 27701 and ISO 22301.
- Excellent verbal, written, and interpersonal skills
- Ability to adapt to shifting priorities, demands, and timelines through analytical and problem-solving capabilities
- Ability to collaborate with multidisciplinary teams
- Ability to work independently as well as in a team environment including multi-level staff and external partners
- Proficiency in using MS Office Suite and Windows-based computer applications
- Adequate professional experience and knowledge to perform Job Responsibilities
- Ability to work on multiple projects simultaneously
- Ability to operate in a fast-moving, team-oriented, collaborative environment with tight deadlines
- 5C/6C Public trust clearance will be required
Preferred Experience
- A minimum of five (5) to eight (8) years of experience in an information technology position.
- Associate degree in business or related field, Certified Information Systems Auditor (CISA) preferred or other security or compliance certification.
- Technical writing and SOP development a plus
Pay TransparencyTierPoint is committed to practices that promote pay equity and transparency. We provide a compensation range for roles that may be hired in locations with pay transparency law requirements. It’s important to note the pay range may be narrower than displayed, as various factors are used to determine the offered compensation package including skill set, level of experience, geographic locations, and other relevant factors- i.e. budgetary requirements.Pay Range $60,000.00 - $97,778.29
#LI-EW1
#LI-Remote