
Information Security Compliance Analyst
Posted 6 hours ago

Posted 6 hours ago
This is a fully remote position, open to applicants in Minnesota.
β’ Assist in the administration, documentation, monitoring, and ongoing enhancement of information security compliance, governance, and risk management initiatives.
β’ Coordinate compliance efforts in line with NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, and other relevant standards.
β’ Maintain policies, standards, procedures, control matrices, ownership records, audit artifacts, evidence repositories, and compliance documentation.
β’ Engage in internal and external audits, assessments, and compliance evaluations.
β’ Assess the design and effectiveness of security controls; assist in control testing, reviews, findings, corrective actions, and remediation until closure.
β’ Monitor POA&Ms, corrective action strategies, security exceptions, compensating controls, and risk acceptance documentation.
β’ Aid in risk assessments, control gap analyses, risk register management, mitigation tracking, and the development of policies.
β’ Support vendor risk management, third-party security evaluations, and risk monitoring activities.
β’ Validate and gather evidence for security controls in AWS and Microsoft Azure environments.
β’ Collaborate with teams across Information Security, IT, Engineering, Product, Legal, Privacy, and other departments.
β’ Organize compliance projects, track milestones, deliverables, status updates, and assigned tasks.
β’ Investigate trends in cybersecurity, privacy, compliance, regulatory, and cloud security, providing recommendations for enhancements.
β’ Assist with security awareness programs, customer security questionnaires, due diligence requests, and ongoing monitoring.
β’ Travel for orientation, industry or company events, or onsite meetings as necessary.
β’ Carry out additional responsibilities as needed.
β’ Bachelor's degree in Information Security, Cybersecurity, Information Technology, Information Systems, Risk Management, Business, or a related field, or an equivalent combination of education and relevant experience.
β’ Demonstrated professional experience in information security, cybersecurity, compliance, audit, governance, risk management, information technology, or a related domain.
β’ Familiarity with NIST 800-53, FedRAMP, GovRAMP, HIPAA, SOC 2, ISO 27001, or similar frameworks.
β’ Capability to evaluate security controls and support cloud compliance requirements within AWS and Microsoft Azure environments.
β’ Experience in compliance assessments, control testing, audit preparation, risk evaluations, gap analyses, continuous monitoring, or related GRC initiatives.
β’ Prior experience with GRC platforms, compliance management tools, vendor risk management, or third-party security assessments is preferred.
β’ Strong organizational, project management, analytical, investigative, research, problem-solving, and documentation skills.
β’ Proficient in coordinating cross-functional initiatives, influencing stakeholders, driving accountability, and managing remediation efforts.
β’ Excellent verbal, written, interpersonal, and stakeholder communication abilities.
β’ Experience in coordinating audits, compliance assessments, remediation actions, or governance initiatives across various stakeholders.
β’ Industry certifications such as Security+, SSCP, CGRC, CISA, CRISC, CCSK, AWS Security Specialty, Azure Security Engineer Associate, or similar credentials are preferred.
β’ Ability to handle proprietary and confidential information with discretion.
β’ Willingness to travel as needed, up to 10% of the time.
β’ Strong work ethic, integrity, collaboration, and team-oriented mindset.
β’ Annual base salary ranging from $80,000 to $100,000 USD.
β’ Bonus opportunities.
β’ Comprehensive benefits package.
β’ Additional perks.
β’ Contributions to community initiatives.
β’ Fully remote work arrangement.
β’ Equal opportunity workplace.
β’ Workplace accommodations available for applicants with disabilities.
Satellite Office
Stefanini LATAM
Cox Enterprises
NuHarbor Security
Get handpicked remote jobs straight to your inbox weekly.