Information Security Compliance Analyst
Media.MonksWe’re Media.Monks – global content, data, and media powerhouse. Our solution is simple and singular: Disrupting the industry, driven by digital.
This position is intended to be involved in the implementation and improvement of administrative and technical controls of the company's Information Security Management System. This person should understand the risk assessment process to detect new threats, contribute in the action plan development and promote the progress of control implementation and evolution. The position will cover compliance activities, third parties risk assessments, management of clients requirements, internal awareness and technical controls evaluation.
- Lead the implementation of the global ISMS (based on ISO27001) over the EMEA region.
- Evaluate the compliance status of processes and technology implementations and plan actions to align to the security framework.
- Identify risk related to information security in the technical environment, the relationships with third parties or any component of the company's operations.
- Understand about technical and administrative controls in the different areas: networking, operations, access management, SSDLC, cloud security, end-point protection, physical security, third party risk assessment, organization security and legal compliance.
- Act as a point of contact for third parties questions regarding information security.
- Analyze clients requirements regarding information security and evaluate their accuracy. Follow up the actions needed to comply with those requirements.
- Identify security threats and risks over processes, conducts, technology and context which may affect the information confidentiality, integrity or availability..
- Assist in the definition and construction of security measures to lower the risks identified.
- Solve low complex issues independently with minimum supervision and escalate more complex issues to accurate staff.
- Contribute in the development of awareness material and the process of delivery and measurement.
- Perform routine activities to ensure compliance with security frameworks and legislation.
- Investigate on technologies that could improve the security baseline and the compliance (e.g. DLP, end-point protection, network security, security and vulnerabilities assessment).
- Bachelor's degree in Computer Science, Computer or Systems Engineering or equivalent.
- Minimum of 3 years of experience in related positions.
- Solid knowledge of security on networking, cloud, infrastructure configuration, end-point protection and SDLC.
- Knowledge of the standard ISO 27001/2.
- English fluent (written and oral)
- Excellent communication and social skills.
- Ability to confidently present findings to those with either a technical or non-technical background.
- Self-directed, resourceful, and a critical thinker with attention-to-detail and proactive problem-solving skills.
- Ability to self-organize and plan activities with commitment towards results.
- Ready to learn new contents both from others or self-learned.
- Passionate about self-improvement and suggesting improvements to processes or activities.
- +3 year of experience in Security Risk Management, Information Security, Security controls or Security/IT Audit
- Information Security Certification (e.g. CISSP, Comptia Sec, CISM, CRISC, etc)
- ISO27001 Lead Implementer/Auditor
Qualities to be tested by recruitment:
- Discretion: should have a mindset oriented to data protection and should be discrete by default.
- Curiosity: should not stay comfortable with the information provided but instead try to see beyond in order to find new opportunities for improvement and innovation.
- Self-organised: should be capable of organise different kinds of tasks and assignments and ask for priority guidance if necessary.
- Work under pressure in case of deadlines.
Media.Monks is on a mission to create a new future for this industry. Our vision? Build everything with a belief that changing for good comes from changing who does the work. Yep, that means you. Welcome to the party—one global, cross-cultural collective with a passion for using our skills to create better and a better world. That’s how we’re able to connect the dots between data, content, digital media, and technology from everywhere we are—a true end-to-end model. Joining the Media.Monks collective means having the opportunity to create award-winning work with some of the most gifted, focused, joyful, talents from all over the world.
At Media.Monks, you’ll be joining a highly ambitious company on a global mission to win the decade by changing the industry for good. Partner to 8 of the 10 most innovative companies in the world, Media.Monks works with established as well as up-and-coming global, regional, DTC and B2B brands, helping them own their data and build out customer ecosystems to elicit smart, efficient, high-impact engines for growth. We deliver table stakes quickly, creating cost efficiencies from day one to push up the creative effectiveness of our work with every cycle.
We are an equal-opportunity employer committed to building a respectful and empowering work environment for all people to freely express themselves amongst colleagues who embrace diversity in all respects. Including fresh voices and unique points of view in all aspects of our business not only creates an environment where we can all grow and thrive but also increases our potential to produce work that better represents—and resonates with—the world around us.
* Salary range is an estimate based on our salary survey 💰
Perks/benefits: Startup environment
More jobs like this
Newcastle upon Tyne, United … Newcastle upon Tyne, United Kingdom Full TimeSenior Senior-levelUSD 80K - 100K * USD 80K+ *
Senior Cyber Risk & Compliance AnalystCompliance GDPR Monitoring NIST PCI DSS Risk management Security strategy +2
Career development Flex hours Flex vacation Parental leave Unlimited paid time off
Explore more InfoSec/Cybersecurity career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cyber Security in general, filtered by job title or popular skill, toolset and products used.
- Open Information Security Specialist jobs
- Open Information Security Officer jobs
- Open Staff Product Security Engineer jobs
- Open Senior Security Operations Engineer jobs
- Open Head of Information Security jobs
- Open Senior SOC Analyst jobs
- Open IT Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Security Consultant jobs
- Open Information System Security Officer (ISSO) jobs
- Open Lead Security Engineer jobs
- Open Cybersecurity Analyst jobs
- Open Infrastructure Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Sr. Security Engineer jobs
- Open Senior Penetration Tester jobs
- Open IT Security Analyst jobs
- Open Senior Cybersecurity Engineer jobs
- Open Senior Information Security Engineer jobs
- Open Senior Infrastructure Security Engineer jobs
- Open Staff Security Engineer jobs
- Open Offensive Security Engineer jobs
- Open Senior Security Analyst jobs
- Open Senior Air Defense/BMD Subject Matter Expert jobs
- Open Cyber Program Manager jobs
- Open GCP-related jobs
- Open Clearance-related jobs
- Open Pentesting-related jobs
- Open Governance-related jobs
- Open Network security-related jobs
- Open Risk assessment-related jobs
- Open SaaS-related jobs
- Open ISO 27001-related jobs
- Open Forensics-related jobs
- Open Java-related jobs
- Open Malware-related jobs
- Open Vulnerability management-related jobs
- Open IDS-related jobs
- Open DevOps-related jobs
- Open Cryptography-related jobs
- Open CISM-related jobs
- Open Threat intelligence-related jobs
- Open Analytics-related jobs
- Open Kubernetes-related jobs
- Open APIs-related jobs
- Open CISA-related jobs
- Open IAM-related jobs
- Open IPS-related jobs
- Open TCP/IP-related jobs
- Open DevSecOps-related jobs