Security And Compliance Specialist

Details of the offer

We are looking for a Security and Compliance Specialist in New Zealand! This role is remote, that said most of our team is in Auckland.We have already passed hundreds of security checks and have annual compliance audits. Our ideal candidate is someone who has also successfully helped a small company pass many Enterprise security checks. You take security seriously, but you also value efficiency and you are pragmatic. We are open to making this role part-time, e.g. 3 or 4 days a week.About ThematicThematic is a SaaS platform for customer feedback analysis, powered by the latest AI algorithms. Our goal is to empower companies to get clear and accurate insights from customer feedback in a fast and effortless way. We work with the likes of Google, LinkedIn and Doordash (just to name a few). Our users are researchers, analysts and product operations people. By getting a faster understanding of customer needs, our customers improve their customer metrics, and grow faster. Our ideal customers are enterprises who care about security and AI governance. Your goal is to help them assure that we are aligned with their needs, which will ultimately help us grow.We've been around since 2017 and are a fully remote team of 20+. Our R&D happens in New Zealand, our sales focus has been mainly in the US. We use modern tools like Slack, Jira and Zoom for communication and collaboration. We strive to minimize meetings, but also dedicate time to build a diverse and inclusive company culture. We are well funded (YCombinator, AirTree) and profitable.A successful Security Engineer at Thematic will be the go-to person for the sales team to help fill out and respond to security questions. You will also be responsible for SOC2 audit as well as implementing the processes required for compliance.Your job focus will be as follows:Security questionnaires - (Our current volume varies, some weeks 2-3, others zero)You'll be the first point of communication for any security-related mattersYou'll communicate with others via Slack and with external security teams via email / Zoom / TeamsYou'll fill out security questions in a timely manner, and if necessary jump in after hours / on weekends for time-sensitive compliance projects (We'll keep these at a minimum)You'll collaborate with other teams to find answers, if necessaryYou'll collaborate with other teams to ensure any requirements or changes to processes or infrastructure are implementedYou'll ensure the filling out of security forms is efficient and quickYou'll create artifacts that help sales team communicate with external security teams e.g. our AI Governance practicesCompliance audits - (Once a year, your first one will be at the end of 2025)You'll be the first point of contact for the SOC2 auditorsYou'll lead our annual SOC2 compliance and review (around 8 weeks part-time)You'll ensure we are following security practices necessary to pass SOC2 compliance in an efficient manner (throughout the year, depending on time available)You will use Confluence and Jira heavily, and you'll use other tools required for evidence preparationThroughout, you'll strive to understand the business context and correlate the effort required for compliance initiative with business impactControls and policy management - (Ensure these are appropriate and up to date)Review and maintain policy documentsResearch and write policy documents and updates to existing documents as they are neededEnsure controls are in place for compliance with policy documentsMonitor compliance throughout the year and work with other teams to ensure they remain compliantRequirementsOur ideal candidate has the following expertise:Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field. Relevant professional certifications (e.g., CISA, CISSP, CISM) are a plusMinimum of 2 years of experience in managing or leading SOC2 compliance efforts, including preparation for audits and maintaining ongoing complianceProven track record of efficiently completing security questionnaires for SaaS or technology companiesExcellent verbal and written communication skills, with the ability to convey complex security and compliance concepts to diverse audiencesExceptional attention to detail and accuracy in documentation and reportingStrong analytical and problem-solving skills, with the ability to develop innovative solutions to complex compliance challenges.Nice to have:Strong understanding of cloud infrastructure (e.g., AWS, Azure, GCP) and security best practices if security work is necessary.Demonstrated experience in designing and implementing scalable processes for evidence collection and management to support compliance initiativesExperience working cross-functionally with various teams, such as IT, Legal, and Product, to ensure company-wide compliance with security standardsBenefitsWe know someone like you is in demand right now, so why should you choose to work with us? Well, we take care of our team!You'll have a base salary of $80,000-$100,000 per year (negotiable, and depends on level of experience), plus employee stock optionsYou'll enjoy flexible working hours. Work late, work early, it's up to you how to plan your weekYou can work remotely from anywhere in the world during 1-2 months a yearYou'll work remotely in comfort. We'll pay $400 per month towards a private or a shared office space (tax free)You'll gain exposure to some of the world's top tech brands, and be the one to build relationships with them!You will be a part of a smart and high performing team that makes sure to have fun as well as work hardWe organize regular team activities, as well as a weekly Friday sessions where we bond as a team and learn about topics like "mushroom growing", "work while living in a camper van" or "growing up behind the Iron Curtain", or play a fun gameYou'll bond with the team in the annual team retreat. We've taken our entire team to both Hawaii and New Zealand in the past!If any of the above resonates with you, we want to hear from you!
#J-18808-Ljbffr


Nominal Salary: To be agreed

Source: Whatjobs_Ppc

Job Function:

Requirements

Privacy Specialist

Ko wai matou? Who are we? Zespri is more than simply the world's single-largest marketer of kiwifruit. We like to think of ourselves as fruit on a mission an...


Zespri International - Bay-of-plenty

Published a month ago

Privacy Specialist

Ko wai matou? Who are we?Zespri is more than simply the world's single-largest marketer of kiwifruit. We like to think of ourselves as fruit on a mission and...


Zespri International - Bay-of-plenty

Published a month ago

Compliance Coordinator

Build your best future with the Johnson Controls teamAs a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performa...


Johnson Controls - Bay-of-plenty

Published a month ago

Privacy Specialist

Zespri is more than simply the world's single-largest marketer of kiwifruit. We like to think of ourselves as fruit on a mission and as rebels with a cause: ...


Zespri Group Limited - Bay-of-plenty

Published a month ago

Built at: 2024-12-23T13:43:35.507Z