Security Compliance Analyst
Core
Build and own the security compliance program end-to-end, including control sets, evidence management, policies, and tooling for a commercial EV company.
Role type
Security Compliance Analyst (GRC)
Builds
SOC 2 Type II and ISO/IEC 27001 compliance programs
Domain
Cybersecurity / GRC / EV Manufacturing
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
SOC 2 Type II, ISO/IEC 27001, NIST control catalogs, GRC platform administration, evidence chain management, system boundary definition, corrective action planning, vendor risk assessment
Preferred skills
CISA, CRISC, CompTIA Security+, ISO 27001 Lead Auditor, Python, JavaScript
Technologies
Vanta, Jira, Confluence
Responsibilities
Own the control catalog and implement controls; run evidence collection and build automations; prepare for and support external audits; write and maintain policy and procedure sets; administer GRC platform Vanta; run vendor and third-party security reviews; report compliance posture to leadership
Seniority
Mid-Senior, hands-on IC