
InfoSec Analyst
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Assist with global Security Trust operations encompassing customer trust, third-party risk, and security assurance workflows.
• Address customer security questionnaires, vendor assessments, due diligence inquiries, and requests for security documentation.
• Ensure that responses intended for customers are precise, evidence-based, consistent with approved messaging, and in alignment with Security, Legal, Privacy, Product, and Compliance standards.
• Convert technical information regarding security, privacy, compliance, and products into clear, accurate, and audience-appropriate responses.
• Review SOC 1 and SOC 2 reports, ISO 27001 certifications, PCI DSS attestations, HIPAA security documentation, penetration testing reports, risk assessments, policies, procedures, and security questionnaires.
• Assess security risks, document findings, and propose remediation or risk treatment strategies.
• Maintain and enhance Trust Center materials, standard responses, knowledge articles, playbooks, documentation, evidence repositories, and AI-enabled knowledge bases.
• Collaborate cross-functionally with Sales, Customer Success, Procurement, Legal, Privacy, Engineering, Product Security, Security Operations, Governance, Risk, Compliance, and business stakeholders.
• Monitor the status of security reviews, remediation activities, evidence requests, operational metrics, and workflow performance.
• Facilitate audit readiness by organizing evidence and keeping accurate security documentation.
• Identify opportunities for automation and self-service to decrease turnaround times and scale Security Trust operations on a global level.
• Utilize approved AI tools for completing questionnaires, vendor assessments, evidence collection, document generation, content maintenance, and security analysis.
• Create reusable prompts, workflows, and knowledge assets.
• Validate the accuracy, completeness, consistency, and handling of sensitive information in AI-generated outputs.
• Evaluate and enhance AI-assisted workflows while ensuring human oversight is maintained.
• Promote the adoption of AI-enabled processes and take part in continuous improvement initiatives.
• Bachelor's degree or equivalent experience required.
• 2 to 5 years of experience in Information Security, Security Assurance, Customer Trust, Third Party Risk Management, Governance, Risk, and Compliance, or a related field.
• Familiarity with reviewing or responding to security questionnaires, due diligence requests, or vendor assessments.
• Knowledge of SOC 2, ISO 27001, NIST CSF, NIST SP 800-53, PCI DSS, and HIPAA Security Rule.
• Strong written, verbal, analytical, and organizational abilities.
• A demonstrated curiosity and enthusiasm for leveraging AI and automation to enhance security operations.
• This position requires access to software/technology subject to U.S. export controls; any offer is contingent upon the ability to comply with U.S. export controls.
• Bonus or commission eligibility.
• Medical benefits.
• Retirement benefits.
• Financial benefits.
• Wellness benefits.
• Time off.
• Employee discounts.
• Fair, equitable, and transparent compensation.
• Diverse, equitable, and inclusive workplace.
AbbVie
Gartner
Marsh McLennan
ŌURA
Get handpicked remote jobs straight to your inbox weekly.