Remote
Information Security Analyst
About this role
π Description Maintain ISO 27001 management system; ensure controls are effective and evidenced. Lead recurring security activities: scans, access reviews, risk assessments, policy cycles. Triage GuardDuty/Inspector findings; coordinate remediation with Security Manager. Run periodic access reviews for Google Workspace, AWS, Slack, JAMF, GitLab, GitHub. Support tool/vendor security reviews and AI governance initiatives.
Automate and streamline compliance tasks to boost efficiency. π― Requirements 3+ years in GRC, compliance, or information security in SaaS/tech. Solid ISO 27001 know-how, Annex A, audit process, and operation. Hands-on with vulnerability mgmt tools and access governance. Experience with Vanta and end-to-end ISO 27001 audits. AWS security tools (GuardDuty/Inspector); triage findings and remediation priorities. AI tooling to accelerate recurring compliance and docs.
Source listing: empllo_remote