Security Assurance Specialist
About the Role
You will help implement key security requirements across the business and build and maintain security control frameworks. You will test and validate security controls, conduct third-party risk reviews, and document and manage remediation efforts. You will enable audit readiness by coordinating evidence collection, working with auditors, and improving control automation and continuous monitoring. You will collaborate directly with engineering, security, legal, procurement, finance, and product teams to embed compliance into daily workflows.
Requirements
- Minimum 5+ years of experience in Security Assurance, Security GRC, or related compliance/security function
- Proven expertise in security risk assessments, security controls testing, and automation
- Strong knowledge of industry standards and regulatory frameworks such as ISO 27001, SOC 2, and NIST
- Experience implementing, monitoring, and automating security controls aligned with recognized frameworks
- Skilled in assessing, tracking, and reporting on control deficiencies and driving timely remediation
- Solid understanding of technology environments including applications, infrastructure, and SaaS
- Ability to translate compliance requirements into technical control implementations and automated processes
- Proficiency in documenting processes, procedures, and system requirements
- Comfortable collaborating directly with engineers to embed compliance and assurance into workflows
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
- Detail-oriented with ability to manage multiple priorities under deadlines
- Industry certifications such as CISSP, CISA, or ISO 27001 Lead Implementer are a strong plus
Responsibilities
- Lead compliance programs and audits
- Manage end-to-end compliance initiatives such as SOC 2 and ISO 27001
- Serve as primary liaison with external and internal auditors and stakeholders
- Drive timely collection, validation, and submission of audit evidence
- Assess manual controls and implement automated compliance controls with engineering and security
- Build and maintain continuous monitoring dashboards
- Integrate compliance checks into internal systems and tooling
- Provide guidance to control owners and business units to ensure ownership and audit readiness
- Benchmark and improve the compliance program against industry best practices
- Identify opportunities to reduce manual effort and increase scalability of compliance activities
- Stay current with regulatory changes and emerging compliance automation solutions
Benefits
- Remote work
