Qualifications
- 3-6 years in information security, IT risk, or GRC, including at least one framework implementation or audit program you personally worked on (NIST CSF, NIST 800-53, ISO 27001, SOC 2, CIS Controls, or similar).
- Working knowledge of NIST CSF 2.0 - the six Functions (Govern, Identify, Protect, Detect, Respond, Recover), Categories and Subcategories, Implementation Tiers, and Organizational Profiles - or demonstrated ability to get fluent in a comparable framework quickly.
- Hands-on experience securing cloud and SaaS environments (AWS, Azure, or GCP, plus core SaaS platforms such as identity providers, productivity suites, and endpoint tooling). You should be able to read a configuration, not just ask someone about it.
- Demonstrated project management capability: you have kept a multi-workstream effort with distributed owners on schedule, using whatever tooling was at hand.
- Strong technical writing. Policies, procedures, and status reports that are clear, concise, and hold up to outside scrutiny.
- Comfort working with non-security stakeholders - engineers, IT admins, executives - and translating control requirements into work they can actually schedule.
- Able to work independently with limited supervision and produce visible progress in the first two weeks.
- Bilingual English and Spanish communication capabilities
Preferred Qualifications
- Security certification such as CISSP, CISA, CRISC, CISM, Security+, or a cloud security credential (AWS Security Specialty, Azure SC-100, CCSK, CCSP).
- PMP, CAPM, or equivalent formal project management training.
- Experience responding to enterprise customer security reviews and vendor due-diligence questionnaires.
- Familiarity with GRC or compliance-tracking tooling, and with scripting or automation for evidence collection.
- Background in media, content identification, or another data-intensive technology sector.
Security Analyst in dallas at Unknown Company
This position is listed as full time and onsite.