
Senior Information Security Specialist
Posted 9 hours ago

Posted 9 hours ago
This is a fully remote position, open to applicants in United States.
• Conduct and uphold third-party risk evaluations while monitoring vendor remediation efforts.
• Aid in the coordination and analysis of both internal and external security assessments, including vulnerability scans and penetration tests.
• Create, monitor, and follow up on action plans to address identified security weaknesses or audit results.
• Work together with managed security service providers and internal teams to oversee and manage security incidents and escalations.
• Collaborate with engineering and operations teams to guarantee the application of security and compliance requirements throughout the organization.
• Assist in the creation, maintenance, and dissemination of information security policies, standards, and procedures.
• Organize security incident response preparation, disaster recovery testing, and business continuity drills.
• Monitor and support the enforcement of technical and administrative security measures across the organization.
• Stay informed about advancing security and privacy regulations and frameworks, including SOC 2, ISO 27001, TX-RAMP, and FedRAMP.
• Over 5 years of experience in information security, Governance, Risk, and Compliance (GRC), or IT risk management.
• Strong grasp of cybersecurity principles, controls, and risk frameworks.
• Proven experience with third-party risk management processes and tools.
• Demonstrated ability to coordinate security assessments and manage vulnerabilities.
• Outstanding communication, documentation, and cross-departmental collaboration abilities.
• Capability to evaluate and implement technical and administrative controls in cloud and hybrid settings.
• Experience with regulatory compliance and audit support in dynamic environments.
• Hands-on involvement in incident response or disaster recovery drills is an advantage.
• Familiarity with compliance platforms such as Drata or Vanta is a plus.
• Knowledge of NIST 800-53 or CIS Controls is advantageous.
• Awareness of secure software development practices or DevSecOps principles is beneficial.
• Background in auditing or assisting with third-party security assessments is a plus.
• Experience with security configurations in Microsoft 365 and/or Google Workspace is beneficial.
• Exposure to regulatory environments such as HIPAA, GDPR, or CCPA is a plus.
• Certifications like CISSP, CISA, CISM, Security+, or equivalent are advantageous.
• Comprehensive healthcare coverage (medical, dental, and vision) with premiums fully paid for employees and their dependents.
• Short and long-term disability coverage, as well as basic life and AD&D insurance plans.
• Options for medical and dependent care Flexible Spending Accounts (FSAs).
• A 401k plan featuring a generous employer contribution.
• Flexible paid time off (PTO) policy.
• Parental leave.
• Generous equity offerings.
• Eligible positions may partake in bonus or commission plans.
• Additional discretionary bonuses/incentives and equity may be accessible.
MRO
AgelessRx
Xcelerate Solutions
OnePay
Get handpicked remote jobs straight to your inbox weekly.