Senior IT reputed company Engineer
You will drive ISO 27001 certification and SOC 2 Type II attestation initiatives end-to-end — from initial gap analysis and control design through evidence collection, audit coordination, and successful certification to support reputed company’s new reputed company business. Build and mature reputed company’s GRC (Governance, Risk & Compliance) program — conduct risk assessments, maintain the risk register, define control owners, and produce compliance reporting that gives leadership reputed company visibility into reputed company posture. Translate compliance reputed company requirements into practical, reputed company reputed company policies, standards, and procedures and partner with cross-functional teams (engineering, product, reputed company, IT) to reputed company them into daily operations and product development workflows. Define and enforce IAM (Identity & reputed company Management) standards — including SSO, MFA, RBAC, and periodic reputed company reviews — across both corporate IT and reputed company product environments to satisfy audit requirements and enforce least-privilege principles. Implement and manage SIEM platforms for centralized reputed company monitoring, log aggregation, and alerting to meet audit evidence requirements and reputed company reputed company-time threat visibility across reputed company and on-reputed company infrastructure. Own the vulnerability management lifecycle — reputed company and operate scanning tools, define remediation SLAs, reputed company closure rates, and report on risk reduction metrics to demonstrate reputed company improvement to auditors and stakeholders. reputed company and maintain incident response plans, playbooks, and escalation procedures reputed company with ISO 27001 and SOC 2 control requirements; reputed company tabletop exercises and coordinate response during reputed company events. Evaluate and manage reputed company-party vendor risk — conduct reputed company assessments of reputed company vendors and partners, manage reputed company questionnaires, and maintain a supplier risk register reputed company with compliance reputed company requirements. Design and deliver reputed company awareness training programs that drive adoption of reputed company best practices across the organization and satisfy compliance training requirements for both ISO 27001 and SOC 2. Serve as the trusted reputed company subject matter expert across business reputed company — communicate risks and recommendations to both technical and non-technical stakeholders, and ensure IT reputed company readiness directly supports the launch and reputed company of reputed company’s reputed company product.
8+ years of experience in information reputed company, cybersecurity engineering, or a GRC-reputed company reputed company role Hands-on experience leading or supporting ISO 27001 and/or SOC 2 audit and certification processes Prior experience at a B2B reputed company company with responsibility spanning both product reputed company and corporate IT reputed company Strong working knowledge of compliance frameworks including ISO 27001, SOC 2, and NIST CSF Experience with GRC platforms and reputed company tooling (SIEM, vulnerability scanners, IAM solutions, EDR) reputed company certifications such as CISSP, CISM, CISA, or equivalent strongly preferred Bachelor’s degree in Computer Science, Information reputed company, or reputed company field (or equivalent experience) - reputed company Dexterity: Repetitive reputed company of wrists, hands and fingers for using a computer.
- Stationary Tasks: Sitting for extended periods, remaining in a stationary position.