Costa Rica_ Senior Compliance Specialist

Costa Rica, Remote

Applications have closed

Zuora

Zuora is the industry leader in subscription management. Build, run and grow your subscription business with Zuora’s suite of advanced billing and revenue recognition tools.

View company page

YOUR MISSION:

The role of a Compliance Engineer is to work with our Trust and Compliance team to:            

  • Drive security compliance efforts from the beginning to the end by maintaining a positive relationship with both internal and external stakeholders
  • Maintain compliance documentation, including audit evidence, controls, and vendor security reviews
  • Design, implement, maintain, and improve programs to address key company risks and prepare internal teams for independent assessments against a wide variety of regulatory and compliance frameworks (PCI, SOC, ISO 27XXX, HIPAA, GDPR, etc) 
  • Monitor the performance of the compliance program through the development of and maintenance of automated systems.
  • Work with cross functional teams to identify risks and gaps in our compliance controls and facilitate remediation across our products and infrastructure.
  • Assist with completing security questionnaires from customers and answering customer questions with respect to compliance; work with the internals team to create customer collateral to educate internal staff and aid in the sales process
  • Assist with requesting/reviewing security questionnaires/contracts from vendors and identify security risks and gaps in the compliance controls to aid in the procurement process
  • Develop automations of risk management, control execution and monitoring

WHAT YOU’LL NEED TO BE SUCCESSFUL

  • 3+ years of experience with a demonstrated track record of success in GRC, internal audit, security, and/or privacy space.  
  • Knowledge of various compliance frameworks (PCI, SOC2, ISO 27001, ISO 27018, HIPAA, GDPR, etc.) 
  • Strong experience with any scripting languages like Ruby, Python, Unix shell, bash, etc.
  • Functional knowledge of multiple security domains and information security industry standards and best practicess
  • Experience leading 3rd party risk management programs, including responding to customer security questionnaires, interacting directly with customer sales and security teams, and reviewing vendor security
  • Solid experience managing compliance initiatives for cloud platforms and interacting with external auditors
  • Strong project management skills 
  • Strong written and verbal communication skills

NICE TO HAVEs

  • A mix of experiences at a Big Four (or similar) audit or consulting firm and at an in-house governance, risk, and compliance function at a SaaS company
  • Industry recognized certification in security ISO 27001 LA / LI D desire to pursue CISSP, CISA, CISM, CCSK, etc. in 6 months.
  • Experience working in an international / global organization

Tags: Bash CISA CISM CISSP Cloud Compliance GDPR Governance HIPAA ISO 27001 Monitoring Privacy Python Risk management Ruby SaaS Scripting SOC SOC 2 UNIX

Regions: Remote/Anywhere North America
Country: Costa Rica
Job stats:  14  1  0
Category: Compliance Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.