Information Security Assurance analyst
Core
Support IT and InfoSec by performing governance, risk, and compliance activities, including managing customer security questionnaires, conducting security reviews of contracts, and engaging with customers on security posture.
Role type
Information Security GRC Analyst
Builds
Customer security assurance artifacts, contract security terms, and internal compliance evidence repositories
Domain
Information Security / GRC / Customer Trust
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security compliance frameworks (SOC 2, ISO 27001, NIST, CIS, PCI DSS, HIPAA, GDPR), security fundamentals (access control, encryption, vulnerability management, secure SDLC, incident response), contract security review, cross-functional collaboration, high-volume request management
Preferred skills
CISA or CISM certification, SaaS/cloud security assurance experience, security contract negotiation
Technologies
SOC 2, ISO 27001, NIST, CIS, PCI DSS, HIPAA, GDPR
Responsibilities
Complete end-to-end customer security questionnaires and RFP security sections, present security controls to customers and prospects, review contracts and security addendums for risk areas, improve team efficiency through standardization and playbook refinement
Seniority
Mid-level, hands-on IC