Compliance Automation Engineer
Ohio - Columbus
Applications have closed
Veeva Systems
Veeva Systems Inc. is a leader in cloud-based software for the global life sciences industry. Committed to innovation, product excellence, and customer success, Veeva has more than 1,100 customers, ranging from the world's largest...We are the first public company to become a Public Benefit Corporation. As a PBC, we are committed to making the industries we serve more productive, and we are committed to creating high-quality employment opportunities.
Veeva is a Work Anywhere company which means that you can choose to work in the environment that works best for you - on any given day. Whether you choose to work remotely from home or work in an office - it’s up to you.
Veeva was recently named the #1 Best Place to Work in Central Ohio by Columbus Business First.
The Role
Veeva’s Security Compliance and Audit team is seeking a Compliance Automation Engineer to improve the efficiency and accuracy of its compliance operations. As an automation engineer, you will be part of team that helps Veeva ensure ongoing compliance with relevant information security regulations and standards. You will improve the overall effectiveness of compliance operations by automating steps in the evidence collection and review process, building dashboards, and building workflow support tools.
You will enhance the effectiveness of Veeva’s security compliance operations by automating key processes that support third party, customer, and internal audits. These audits include ISO 27000, SOC 2, and HIPAA. You will also assist in constructing reports and dashboards that provide insight into the current compliance and risk status of the company.
The Compliance Automation Engineer is expected to possess strong technical and interpersonal skills. The person in this position will work with teams throughout Veeva to identify automation opportunities and implement them. The Engineer is expected to show good judgement in designing secure solutions, prioritizing work, and selecting technologies. A strong customer focus and a team-first attitude are essential to success in this role.
What You'll Do
- Identify opportunities to leverage automation for collecting, reviewing and organizing evidence in support of security audits of Veeva products. The end goal is to reduce the manual effort required to collect, review and organize evidence while at the same time improving the reliability of the evidence collection processes
- Develop and enhance processes to maintain awareness of the current state of risk and compliance. This includes building dashboards and reports to show the current status of evidence collection for each audit, health of select security controls, and current information security risk posture of the company
- Design, build, document, and maintain tools to support compliance operations as described above. This includes utilizing APIs, SDKs, and other technologies to integrate with various components of Veeva infrastructure as needed. Tools are expected to be reliable, secure, maintainable, and well documented
- Follow established security team practices for building, testing, maintaining and documenting tools
Requirements
- BS in Computer Science or related field, or equivalent work experience
- 2+ years of work experience as an application developer or application security engineer
- Programming experience with one or more: Python, JAVA, Java Script, PowerShell, Bash scripting
- Experience with cloud service providers, preferably AWS and its various services
- Experience with Linux, Windows Server, and database technologies such as MySQL, Amazon RDS
- Well versed in application design
Nice to Have
- Knowledge of ISO 27001, SOC 2, HIPAA, GDPR
- Experience with the audit process – gap analysis, evidence collection, evidence presentation, management of auditors
- Understanding of network security, authentication protocols, cryptography, and application security
- Knowledge of security concepts such as web application firewalls, IDS/IPS, vulnerability management
- Security, risk, or compliance certification such as CISSP, CISA, CRISC, CIPP
Veeva’s headquarters is located in the San Francisco Bay Area with offices in more than 15 countries around the world.
Veeva is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity or expression, religion, national origin or ancestry, age, disability, marital status, pregnancy, protected veteran status, protected genetic information, political affiliation, or any other characteristics protected by local laws, regulations, or ordinances. If you need assistance or accommodation due to a disability or special need when applying for a role or in our recruitment process, please contact us at talent_accommodations@veeva.com.
Tags: APIs Application security Audits Automation AWS Bash CIPP CISA CISSP Cloud Compliance Computer Science CRISC Cryptography Firewalls GDPR HIPAA IDS IPS ISO 27000 ISO 27001 Java Linux MySQL Network security PowerShell Python Scripting SOC SOC 2 Vulnerability management Windows
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Ethical hacker / Pentester H/F jobs
- Open Staff Security Engineer jobs
- Open Information Security Specialist jobs
- Open Cyber Security Architect jobs
- Open Manager Pentest H/F jobs
- Open Senior Cyber Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cyber Security Specialist jobs
- Open Principal Security Engineer jobs
- Open Product Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Cybersecurity Analyst jobs
- Open IT Security Analyst jobs
- Open Consultant infrastructure sécurité H/F jobs
- Open Consultant SOC / CERT H/F jobs
- Open Cybersecurity Consultant jobs
- Open Chief Information Security Officer jobs
- Open Senior Information Security Engineer jobs
- Open Security Specialist jobs
- Open Cybersecurity Specialist jobs
- Open Senior Penetration Tester jobs
- Open Security Researcher jobs
- Open Sr. Security Engineer jobs
- Open Senior Security Architect jobs
- Open Security Operations Analyst jobs
- Open CISM-related jobs
- Open ISO 27001-related jobs
- Open Network security-related jobs
- Open Application security-related jobs
- Open Windows-related jobs
- Open Agile-related jobs
- Open Pentesting-related jobs
- Open Vulnerability management-related jobs
- Open GCP-related jobs
- Open Analytics-related jobs
- Open SaaS-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open Threat intelligence-related jobs
- Open APIs-related jobs
- Open Java-related jobs
- Open DevOps-related jobs
- Open Security assessment-related jobs
- Open Kubernetes-related jobs
- Open Security Clearance-related jobs
- Open Malware-related jobs
- Open CI/CD-related jobs
- Open IDS-related jobs
- Open DevSecOps-related jobs
- Open CEH-related jobs