About this role
DESCRIPTION OF ESSENTIAL DUTIES:
• Adhere to, evaluate, and assist in the development of security policies, standards, and procedures; recommend updates to align with legal, regulatory, and business requirements.
• Perform security and compliance assessments to evaluate adherence to internal policies, standards, and applicable regulatory frameworks.
• Assist in identifying control gaps, document findings, and support management and stakeholders in remediation activities.
• Track compliance status, risks, exceptions, and remediation activities, ensuring appropriate documentation and evidence is maintained.
• Assist in internal and external risk assessments, including identifying, analyzing, and documenting security and compliance risks.
• Maintain working knowledge of relevant security and privacy frameworks and regulations (e.g., NIST, CIS, ISO, NAIC, PCI, SOX, HIPAA, or similar, as applicable).
• Assist in delivering guidance and awareness materials to internal teams based on established policies and direction.
• Monitor changes in regulatory requirements, industry standards, and emerging risks, and provide updates to management for review and direction.
• Prepare compliance metrics, status reports, and risk summaries for management review.
• Document activities, assessments, issues, and remediation tracking within designated systems or tools.
• Complete task and project work as assigned.
• Escalates issues, risks, and exceptions to management for review and decision-making.
OTHER RESPONSIBILITIES/REQUIREMENTS:
• Develop and maintain positive working relationships with internal and third-party vendors as needed.
• Provide management and team members with clear, accurate, and timely information regarding compliance posture, risks, and issues.
• Continually improve the security program by identifying gaps in documentation, processes, or controls, and recommending enhancements.
• Demonstrate strong communication and interpersonal skills with the ability to interact effectively with both technical and non‑technical stakeholders.
• Support team members by sharing knowledge of security and compliance practices.
• Ability to follow sound business ethics when executing job responsibilities.
• Demonstrate a commitment to continuous learning and professional development.
• Be a self-motivated individual with the ability to complete assigned tasks and priorities within established timelines, escalating issues or competing demands to management as needed.
QUALIFICATION, EDUCATION AND EXPERIENCE REQUIREMENTS:
• Bachelor's degree in Information Technology, Information Security, Risk Management, Business, or a related field, or an equivalent combination of education, training, and experience.
• Background or experience in information security, compliance, governance, risk management, audit, IT operations, or a related discipline is desired.
• Familiarity with developing, maintaining, reviewing, or assessing security policies, standards, and procedures.
• Exposure to security or compliance assessments, risk evaluations, audit support activities, or control testing is beneficial.
• General understanding of IT systems, security controls, and enterprise technology environments.
• Experience working with, interpreting, or mapping controls to recognized frameworks such as NIST CSF, NIST SP 800‑53, CIS Controls, ISO/IEC 27001, or similar.
• Knowledge of regulatory, legal, or contractual security and compliance expectations in regulated or complex environments.
• Security-related professional certifications (e.g., Security+, CISSP, CISA, CISM, CRISC, or similar) are a plus.
• Strong organizational, analytical, and documentation skills with attention to detail.
• Ability to interpret requirements and translate them into clear, practical, and business-aligned guidance.
• Strong written and verbal communication skills, with the ability to engage effectively with both technical and non‑technical stakeholders.
• Demonstrates curiosity and willingness to learn, with interest in understanding the “what,” “why,” and “how” behind security controls and compliance requirements.
• Self-motivated, adaptable, and comfortable working in an evolving security and compliance program.
SUPERVISORY RESPONSIBILITIES:
None
PHYSICAL DEMANDS/WORK ENVIRONMENT:
None
The above statements reflect the general details necessary to describe the principle functions of the occupation described and shall not be construed as a detailed description of all the work requirements that may be inherent in the occupation.