Compliance Security Analyst
About the Team
AppDirect is the leading cloud service marketplace company dedicated to revolutionizing the way businesses run. We offer a cloud service marketplace and management platform that enables companies to distribute digital services. The global network of AppDirect-powered marketplaces allows businesses to find, buy, and manage the best applications the cloud has to offer.
With our award-winning platform, service providers can launch a state-of-the-art online application store within a matter of weeks, while developers can integrate once and make their software available across multiple marketplaces worldwide. Our products offer more advanced features and tools than any other competitive solution, putting AppDirect at the forefront of the rapidly evolving market for cloud services delivery.
We’re looking for talented yet humble individuals who are smart, passionate, and want to drive disruption in the Information security industry. If you thrive in a fast-paced, collaborative workplace, AppDirect provides an environment where you will be challenged and inspired every day. If you relish the freedom to bring creative, thoughtful solutions to the table that reflect your experience and personality, there's no limit to what you can accomplish here.
What you'll do and how you'll make an impact
You will be a member of the Compliance team (part of the Infosec team) as a compliance analyst. You will join the team responsible, mainly, for continuous compliance monitoring, risk management, vendor management and maintaining our ISO 27001,PCI-DSS and SOC2/SOC1 certification.
You have both soft skills and technical potential and you think that the security team must be an ally and a facilitator for the company and all its members. Below is what we expect from you:
Provide overall oversight for continued compliance and ongoing certifications (e.g. SOC 1 and 2, PCI DSS, ISO 27001, NIST CSF, GDPR, etc.).
Collaborate with internal staff to ensure that appropriate controls are implemented, operating properly, in accordance with the corporate policies.
Conduct audit readiness assessments and coordinate with internal and external functions and audit resources.
Improve and maintain the Privacy practice at AppDirect.
Develop and implement in collaboration with Engineering and architects mechanisms to automate the generation of evidence.
Assess and improve the maturity of the risk governance process and oversee and lead risk assessments.
Oversee customers questionnaires by liaising with internal staff and delivering expected results
Develop and maintain organization information security policies based on applicable standards, information security requirements, business requirements and legal requirements.
Improve and operationalize the Vendor management process at AppDirect.
Facilitate discussions and reach decisions that can have a good balance between security and usability.
What we’re looking for
A degree or comparable experience (~3+ years) in Information Security or a related field.
Prior experience in IT compliance and Audit support (SOC2, ISO 27001 and PCI-DSS).
Prior experience with risk management and GRC Tools.
Good experience with Privacy frameworks and what needs to be implemented to meet customer/internal needs.
Successful in cross-functional team collaboration to drive early security adoption
Good understanding of networking, cloud computing, operating systems concepts.
Well organized and able to work with clear deadlines.
Experience with project management (planning, organizing, and managing resources to successfully achieve audits).
Strong verbal, written and presentations skills with the ability to find innovative solutions to complex problems (compliance vs risk vs security vs usability).
Be able to think Business first!
Nice to have
Any Information Security Certification (CISA, CDPSE, ISO implementer , Security+, CISSP).
Demonstrated technical experience in developpement, networking, IT support, system administrations, etc.
At AppDirect, we believe that innovation thrives in an environment that houses diversity of excellence, experience and thought. We respect each AppDirector as their own fingerprint; unique with no one alike. We foster an environment of inclusion without regard to race, religion, age, sexual orientation, or gender identity enabling AppDirectors to embrace their uniqueness to do their best work. As such, we strongly encourage applications from Indigenous peoples, racialized people, people with disabilities, people from gender and sexually diverse communities, and/or people with intersectional identities.