Berkeley Research Group (BRG)

Intelligence that works.

Security Engineer – Compliance

Security EngineerSecurity EngineerFull TimeRemoteTeam 1,001-5,000H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

28 days ago

Salary

$125K - $170K / year

Bachelor Degree5 yrs expEnglishAWSAzureCloudFirewalls

Job Description

• Own, manage, and support the application of key compliance frameworks (SOC 1 and 2, ISO 27001, CSA STAR, NIST CSF, etc). • Develop, control, and maintain applicable organizational policies, procedures, best practices, and guides associated with key compliance requirements and in support of annual audits. • Assist in the development and implementation of an internal audit program designed to measure the effectiveness of organizational processes and procedures, assess organizational adherence to those processes and procedures, identify opportunities for organizational and systemic process improvement, and alert the organization about emerging risks to the comprehensive compliance program. • Support the Risk Management Program making risk-based decisions an integrated part of the cultural landscape, including: risk identification, risk mitigation, risk monitoring, risk reporting, and documentation of risk realization and/or retirement. • Work closely with the Security Operations (SecOps) team to ensure security functions meet operational compliance requirements and will meet/exceed independent annual audit standards. • Ensure technical, operational, and administrative controls are fully operable and meet standards necessary for SOC 1 and 2 audits. • Support Quarterly Access Reviews (QARs) as part of the larger User Access Request process.

Job Requirements

  • 5+ years of proven work experience as a System or Information Security Engineer, Compliance Engineer, or Risk Engineer
  • Detailed technical knowledge of compliance frameworks and their application across systems and organizations
  • Thorough understanding of the latest security principles, techniques, and protocols
  • Problem solving skills and ability to work under pressure
  • Experience with compliance frameworks (e.g., SOC 1 and 2, ISO 27001, CSA STAR, NIST CSF)
  • Familiarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and network/web related protocols
  • Experience with cloud services (Microsoft 365, SharePoint Online, Microsoft Azure, and Amazon Web Services)
  • Operational understanding of security systems, including firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, and content.
  • Strong risk background including risk identification, adjudication, and mitigation development experience

Benefits

  • Health technology solutions
  • Flexible working environment
  • Opportunities for personal growth
  • Collaborative team culture

Related Categories

Related Job Pages

More Security Engineer Jobs

Security GRC Analyst

Monarch Money

A financial coach in your pocket. Get personalized advice on how to best grow your money.

Security Engineer28 days ago
Full TimeRemoteTeam 1-10Since 2016H1B No Sponsor

Security GRC Analyst managing compliance programs at fintech company

AWSCloud
United States
$85K - $180K / year

Executive Technology and Security Specialist

Onebrief

Software for rapid military planning: make planning fast enough for today's environment

Security Engineer28 days ago
Full TimeRemoteTeam 1-10H1B No Sponsor

Executive Technology & Security Specialist supporting executive teams at Onebrief.

CloudCyber SecurityJamfMacOS
United States
$150K - $170K / year
ContractRemoteTeam 51-200H1B No Sponsor

Are you ready to join an innovative team that pushes the boundaries of creativity and delivers top-notch results? At Aardvark Studios, we thrive in a multitude of creative landscapes. Simply calling us a “Creative Fabrication Company” or an “Experienti...

United States
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

Senior Consultant in security training and consulting at Vizient

United States
$88.9K - $155.5K / year