Security Compliance Specialist (Security Compliance & Common Flow Team)
Semrush
Hi there!
We are Semrush, a global IT company developing our own product—a platform for digital marketers. New stars are born here, so don’t miss your chance.
This is our Security Compliance Specialist role for those who strive to implement functional processes and drive them to full completion.Tasks in the roleEnsure that Semrush complies with security standards such as PCI DSS and SOC 2 with main focus on SOC 2 attestationDevelop, review, and update security policies, procedures, and guidelines to maintain compliance with regulatory and industry standardsIncident Response: Assist in the development and execution of the incident response process, ensuring timely and effective handling of security incidentsTraining and Awareness: Conduct security training programs for employees to ensure that everyone is aware of the organization’s security policies and practicesEnsure that third-party vendors meet the organization’s security standards and compliance requirementsAssist in responding to customer inquiries regarding security compliance and provide clear, accurate information about our security practices and standardsWork closely with security, legal, and business units to identify security risks and implement appropriate controlsWho we are looking forExperience: 3+ years of experience in security compliance, information security, or a related fieldCertifications: Certifications such as CISSP, CISM, CISA, or similar are highly desirableStrong knowledge of security frameworks (e.g., SOC 2, PCI DSS 4. 0, ISO 27001, NIST CSF) and industry best practicesExperience in conducting SOC 2 audits or participation in similar auditsExperience in managing compliance for cloud environments (e.g., AWS, Azure, Google Cloud)Excellent understanding of the risk-based approach, as well as understanding of the basic principles of risk identification and assessmentFamiliarity with GDPR, CCPA, and other data privacy regulationsExcellent communication skills with the ability to translate technical requirements to non-technical stakeholdersFluent in written and spoken English, with excellent communication skills in a professional contextNot required, but a plusStrong analytical and problem-solving skillsDetail-oriented with strong organizational skillsYou share our common values: Trust, as we prefer to speak up and be our true selves; Sense of Ownership, as it’s not worth wasting time on something you don’t believe in; and enthusiasm for Constant Change, as we are always looking to make things better.A bit about the teamYou can get to know the team better at one of the interviews, but some brief information about future colleagues will be useful now.
Security Compliance & Common Flow team will focus on security compliance questions (PCI DSS, Security audits) and general security issues.
Barcelona
Wed, 25 Sep 2024 04:59:39 GMT
To help us track our recruitment effort, please indicate in your email/cover letter where (vacanciesineu.com) you saw this job posting.
Job title: Full-Stack Developer – European Commission Company: Edda International Job description WHO WE AREEdda…
Location: Gava (8850) - Basque Country, Spain Salary: Competitive Type: Permanent Main Industry: Search Science…
Location: Rotherham (S65) - South Yorkshire, North East, United Kingdom Salary: £17 - £17.5 per…
Location: Istanbul - Turkey Salary: Negotiable Type: Permanent Main Industry: Search Science Jobs Other Industries…
Location: Søborg - Denmark Salary: Competitive Type: Permanent Main Industry: Search Finance, Banking & Insurance…
Job title: Director Research and Knowledge Exchange/Director Centre for National Park and Protected Areas Company:…