3-6 years of experience in information security, IT risk, or GRC with hands-on implementation or audit involvement.
Proficient knowledge of NIST CSF 2.0 and its functions, categories, and tiers or the ability to learn quickly.
Experience securing cloud and SaaS environments (AWS, Azure, GCP) and understanding configurations.
Strong project management skills with experience coordinating multi-workstream projects.
Excellent technical writing skills for clear and concise documentation of policies and procedures.
Ability to collaborate with non-security stakeholders and communicate security requirements effectively.
Self-motivated with the ability to show progress independently, especially in the initial weeks.
Bilingual in English and Spanish.
Responsibilities
Implement and audit information security frameworks to ensure compliance.
Develop and maintain security policies and procedures aligned with industry standards.
Manage security assessments and coordinate with various stakeholders for completion.
Oversee security controls in cloud and SaaS environments to ensure effectiveness.
Prepare clear status reports and documentation for both technical and non-technical audiences.
Translate security controls into actionable tasks for engineering and administrative teams.
Benefits
Flexible working hours with remote work options.
Opportunities for professional development and training.
Access to cutting-edge security tools and technologies.
Supportive work culture promoting diversity and inclusion.
Health and wellness programs, including mental health resources.
Full Job Description
Qualifications:
3-6 years in information security, IT risk, or GRC, including at least one framework implementation or audit program you personally worked on (NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, or similar).
Working knowledge of NIST CSF 2.0 - the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Implementation Tiers, and Organizational Profiles - or demonstrated ability to get fluent in a comparable framework quickly.
Hands-on experience securing cloud and SaaS environments (AWS, Azure, or GCP, plus core SaaS platforms such as identity providers, productivity suites, and endpoint tooling). You should be able to read a configuration, not just ask someone about it.
Demonstrated project management capability: you have kept a multi-workstream effort with distributed owners on schedule, using whatever tooling was at hand.
Strong technical writing. Policies, procedures, and status reports that are clear, concise, and hold up to outside scrutiny.
Comfort working with non-security stakeholders - engineers, IT admins, executives - and translating control requirements into work they can actually schedule.
Able to work independently with limited supervision and produce visible progress in the first two weeks.
Bilingual English and Spanish communication capabilities
Preferred Qualifications
Security certification such as CISSP, CISA, CRISC, CISM, Security+, or a cloud security credential (AWS Security Specialty, Azure SC-100, CCSK, CCSP).
PMP, CAPM, or equivalent formal project management training.
Experience responding to enterprise customer security reviews and vendor due-diligence questionnaires.
Familiarity with GRC or compliance-tracking tooling, and with scripting or automation for evidence collection.
Background in media, content identification, or another data-intensive technology sector.