Senior Security Compliance Specialist
AppDirect Ver todas las vacantes
- Buenos Aires
- Permanente
- Tiempo completo
- Provide overall oversight for continued compliance and ongoing certifications (e.g. SOC 1 and 2, PCI DSS, ISO 27001, NIST CSF, GDPR, HIPAA, ISO 42001, NIST AI RMF, etc.).
- Collaborate with internal staff to ensure that appropriate controls are implemented, operating properly, in accordance with the corporate policies.
- Conduct audit readiness assessments and coordinate with internal and external functions and audit resources.
- Serve as the primary point of contact during external audits, including coordinating evidence requests, facilitating auditor walkthroughs, and managing audit timelines to closure.
- Improve and maintain the Privacy practice at AppDirect.
- Develop and implement in collaboration with Engineering and architects mechanisms to automate the generation of evidence.
- Support security and compliance due diligence and integration activities for M&A transactions.
- Oversee customers questionnaires by liaising with internal staff and delivering expected results
- Develop and maintain organization information security policies based on applicable standards, information security requirements, business requirements and legal requirements.
- Communicate compliance requirements and risk posture to technical and non-technical stakeholders, including executive leadership.
- Expertise in US certifications, such as GovRAMP or FedRAMP, is considered a strong asset.
- Demonstrated ability to use AI-assisted workflows to improve efficiency in compliance operation
- Facilitate discussions and reach decisions that can have a good balance between security and usability.
- A degree or comparable experience (~5+ years) in Information Security or a related field.
- Prior experience in IT compliance and Audit support (SOC2, ISO 27001 and PCI-DSS).
- Prior experience with risk management and GRC Tools.
- Good experience with Privacy frameworks and what needs to be implemented to meet customer/internal needs.
- Successful in cross-functional team collaboration to drive early security adoption
- Good understanding of networking, cloud computing, operating systems concepts.
- Experience on cloud adoption strategies including design and implementation of security controls and compliance monitoring.
- Experience with project management (planning, organizing, and managing resources to successfully achieve audits).
- Strong verbal, written and presentations skills with the ability to find innovative solutions to complex problems (compliance vs risk vs security vs usability).
- Nice to have, any Information Security Certification (CISA, CDPSE, ISO implementer , Security+, CISSP).
- Demonstrated technical experience in development, networking, IT support, system administrations, etc.