Bachelor's degree in Information Security, Computer Science, or a related field., 2-4 years of experience in cybersecurity with a focus on compliance management., Proficiency in Asana for project management and Slack for communication., Strong understanding of SOC 2 Type I and II, and ISO 27001 standards..
Key responsibilities:
Provide technical support for cybersecurity tools and ensure timely issue resolution.
Assist clients with audit readiness, evidence collection, and control testing.
Create and maintain security policies and compliance documentation.
Collaborate with the cybersecurity team to implement security measures and respond to client inquiries.
Report This Job
Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
We impact global start-ups and organizations to ignite their sense of mission and purpose while impacting the lives of underserved communities around the world.
Our co-evolving partners seek to disrupt their industry and serve as a vehicle for change. We provide outsourcing services in the form of Talent Solutions, Managed Solutions, and Workspace Solutions helping our partners drive towards ever-greater purpose and meaning.
Our values are what ultimately drive Booth and Partners. We do our best to make sure that our shared values are deeply ingrained in how we work. We understand how values are inextricably connected to all areas of our business, and we focus on ways to be intentional. These values manifest not only in how we relate to each other but how we thrive and exist in the world.
As a Compliance Support Specialist at Eden Data, you will play a critical role in helping our clients achieve and maintain compliance with SOC 2 Type II, ISO 27001, and other framework standards.
You will maintain clear client communications via Slack and email, oversee clients' Drata instances to ensure all compliance requirements are met, and create and manage project plans in Asana as needed. You will collaborate closely with the internal cybersecurity team to implement security controls, conduct risk assessments, maintain security documentation, and continuously enhance compliance initiatives to protect sensitive information. You will also be answering client questions daily via Slack and email.
Responsibilities:
Technical Support
Provide technical support for cybersecurity tools and technologies, ensuring operational effectiveness and timely issue resolution.
Maintain security awareness training documentation for internal and client-facing audiences to promote cybersecurity best practices.
Support clients' audit readiness by assisting with evidence collection, control testing, and remediation tracking.
Assist clients with the setup and maintenance of GRC (Governance, Risk, and Compliance) tools, particularly Drata, including data migration, vendor module configuration, user management, and policy updates.
Security Documentation
Create, maintain, and update security policies, procedures, and compliance documentation to align with industry standards.
Develop and maintain trackers for client purposes according to their internal policy requirements.
Assist clients in completing Self-Assessment Questionnaires (SAQs), leveraging existing onboarding information, historical SAQs, and data housed within GRC platforms.
Conduct periodic user access reviews across clients' systems and applications.
Assist in preparing reports and documenting response actions.
Collaboration
Partner with cybersecurity team members and cross-functional departments to implement and sustain security measures.
Research and respond to clients' ad-hoc security inquiries, providing clear and actionable findings.
Leverage internal tools to optimize workflows and drive efficiency in daily operations.
Exercise Self-Direction
Regularly assess and enhance client security postures, leveraging GRC platform features for control management, task assignment, and audit readiness activities.
Operates autonomously, taking ownership of work and executing tasks ahead of deadlines with minimal oversight
Requirements
Education: Bachelor's degree in Information Security, Computer Science, or a related field.
Relevant certifications SEC+, CISA, or equivalent may be required.
(CISSP, CISM, CRISC) are a plus.
Experience: Minimum of 2-4 years of experience in cybersecurity, with a focus on compliance management and project management.
Technical Skills: Proficiency in using Asana (or equivalent) for project management and Slack for effective communication.
Familiarity with Drata or similar compliance management tools is highly desirable.
Compliance Knowledge: Strong understanding of SOC 2 Type I and II, and ISO 27001 standards, controls, and assessment methodologies.
Experience with other compliance frameworks (e.g., HIPAA, GDPR, NIST) is nice to have.
Analytical Thinking: Ability to analyze and identify security risks, providing practical recommendations for mitigating those risks.
Communication Skills: Excellent verbal and written communication skills in English, with the ability to convey technical concepts to both technical and non-technical stakeholders effectively.
Collaboration: Proven ability to work collaboratively in a team environment, interacting with clients, internal teams, and third-party auditors or assessors (as needed).
This role would not need to take external calls with clients (via Zoom etc.) but does need to be externally facing via Slack and email correspondence.
Ability to work independently, remotely, with assigned tasks and deadlines, with minimal oversight.
Attention to Detail: Meticulous and thorough approach to work, ensuring accuracy in documentation, reporting, and compliance activities.
Adaptability: Ability to thrive in a fast-paced and rapidly changing environment, managing multiple projects simultaneously and meeting deadlines.
Benefits
✔Competitive salary
✔ Prepaid medicine
✔ Life insurance
✔ Birthday day off.
✔ Indefinite-term labor contract, with all legal benefits.
Required profile
Experience
Spoken language(s):
English
Check out the description to know which languages are mandatory.