What are the responsibilities and job description for the Security Compliance Engineer position at Rain Instant Pay?
As a Security Compliance Engineer you will be challenged to conduct the organization on the path to complying with industry certifications such as SOC 2, ISO 27001, PCI DSS. You need to be a communicative person, who interacts with multidisciplinary teams, someone technical, with a background in security, risk and compliance. You are a person who has knowledge of standards and certifications, that will engaged with the squads to collect evidence and will participate in meetings with external consultants that will help you make the company compliant.
Key Responsibilities
Conduct projects to obtain certifications such as SOC 2, ISO 27001, PCI DSS;
Conduct internal compliance projects with business partners and third parties;
Interact with multiple teams and engage the company as a whole to collect necessary evidence;
Propose security improvements, listing priorities and assisting teams involved or acting directly in the implementation of the necessary controls;
Provide internal Information Security consultancy on projects;
Acting in initiatives such as risk management, vendor and third-party assessment, etc;
Skills
Skills for conducting projects on Data Privacy, Data Protection and liaison with Legal on Privacy matters;
Knowledge of international standards and certifications in information security auditing;
Audit and regulations – PCI DSS, ISO 27001, ISO27701, GDPR, SOC 2;
Desirable to have any of the certifications such as ISO 27001 Lead Auditor, CISA, CRISC, among others;
Identification, establishment and sustainment of risk governance and risk management projects;
Risk assessments – custom risk assessments for sectorial regulators;
Risk surveys based on various security frameworks, gap analysis;
Ongoing consulting services;
Experience
3 years of experience in GRC (Governance, Risk and Compliance) projects;
3 years of experience as a Consultant, Auditor or similar role;
3 years of experience conducting projects for some international certifications;
Experience in auditing, consulting and risk management;
Experience working in information security related position, with experience in governance, risk and compliance;