Security Compliance Analyst
Core
Own security control processes end-to-end, manage third-party risk, and support audits/certifications for a global mobile ticketing platform. (via careerplan.io/jobs/e4b5d5bf-f448-4058-9521-d516509ad5db-security-compliance-analyst-at-masabi)
Role type
Security Compliance Analyst
Builds
Security controls, risk registers, and audit evidence for Justride fare collection platform
Domain
Public transport technology / Information Security Compliance
Required skills
Information security fundamentals, IT compliance, internal control, audit, risk management, data protection, process ownership, documentation, stakeholder communication
Preferred skills
Third-party risk management (TPRM), ISO 27001/SOC 2/PCI DSS/GDPR/NIST frameworks, RFP/tender support, compliance automation, GRC platforms, scripting/low-code tools, Jira/Confluence
Technologies
ISO 27001, SOC 2, PCI DSS, GDPR, NIST, Jira, Confluence, n8n, Make
Responsibilities
Plan and execute assigned security controls and gather evidence; Perform manual and tool-based security reviews; Manage Third-Party Risk Management (TPRM) assessments; Maintain security and privacy registers; Analyze security requirements in bids and tenders; Respond to customer security questionnaires; Support audits and certifications (ISO 27001, SOC 2, PCI DSS, Cyber Essentials); Identify automation opportunities for control processes
Seniority
Individual Contributor, mid-level