- Perform and maintain third-party risk assessments and track vendor remediation activities.
- Support coordination and analysis of internal and external security testing, including vulnerability scans and penetration tests.
- Develop, track, and follow up on corrective action plans for identified security gaps or audit findings.
- Collaborate with managed security service providers and internal stakeholders to monitor and manage security events and escalations.
- Partner with engineering and operations teams to ensure implementation of security and compliance requirements across the organization.
- Assist in developing, maintaining, and communicating information security policies, standards, and procedures.
- Coordinate security incident response planning, disaster recovery testing, and business continuity exercises.
- Monitor and support enforcement of technical and administrative security controls across the enterprise.
- Stay current with evolving security and privacy regulations and frameworks, including SOC 2, ISO 27001, TX-RAMP, and FedRAMP.
Requirements
- 5+ years of experience in information security, GRC, or IT risk management.
- Strong understanding of cybersecurity concepts, controls, and risk frameworks.
- Demonstrated experience with third-party risk management processes and tooling.
- Proven ability to coordinate security testing and vulnerability management efforts.
- Excellent communication, documentation, and cross-functional collaboration skills.
- Ability to assess and implement technical and administrative controls across cloud and hybrid environments.
- Experience with regulatory compliance and audit support in fast-paced environments.
- Hands‑on participation in incident response or disaster recovery exercises is a plus.
- Experience with compliance platforms such as Drata or Vanta is a bonus.
- Knowledge of NIST 800‑53 or CIS Controls is a bonus.
- Familiarity with secure software development practices or DevSecOps principles is a bonus.
- Background in auditing or supporting third‑party security assessments is a bonus.
- Experience with Microsoft 365 and/or Google Workspace security configuration is a bonus.
- Exposure to HIPAA, GDPR, or CCPA regulatory environments is a bonus.
- CISSP, CISA, CISM, Security+, or similar certifications are a plus.
Core Competencies
Demonstrates expertise in information security, risk management, and compliance, with a strong focus on third‑party risk assessments and security controls. Proficient in coordinating security testing, incident response, and regulatory compliance across diverse environments.
Highest‑signal resume keywords
- Information Security Management
- Third-Party Risk Management
- Vulnerability Management
- Regulatory Compliance
- Incident Response Coordination
ATS Optimization Keywords
Hard Skills
- Cybersecurity Concepts
- Risk Frameworks
- Technical Controls Implementation
- Security Testing Coordination
- Disaster Recovery Planning
- Audit Support
- Secure Software Development Practices
- Cloud Security Configuration
- Vulnerability Scanning
- Penetration Testing
Soft Skills
- Excellent Communication
- Documentation Skills
- Cross‑Functional Collaboration
Certifications & Qualifications
- CISSP
- CISA
- CISM
- Security+
Industry Keywords
- SOC 2
- ISO 27001
- TX-RAMP
- FedRAMP
- NIST 800-53
- CIS Controls
- HIPAA
- GDPR
- CCPA
Tools & Technologies
- Compliance Platforms
- Microsoft 365 Security
- Google Workspace Security
- Drata
- Vanta
#J-18808-Ljbffr
Senior Information Security Specialist Arbeitgeber: Jobtailor
Als Front Office Supervisor in unserem dynamischen Team bieten wir Ihnen die Möglichkeit, in einem unterstützenden und freundlichen Arbeitsumfeld zu wachsen. Wir legen großen Wert auf die berufliche Entwicklung unserer Mitarbeiter und bieten regelmäßige Schulungen sowie die Chance, Verantwortung zu übernehmen. Unsere Lage ermöglicht es Ihnen, Teil einer lebendigen Gemeinschaft zu sein, während Sie gleichzeitig die Standards unseres Franchise-Partners einhalten und unseren Gästen einen unvergesslichen Aufenthalt bieten.