Senior Security Compliance Analyst
hace 1 semana
This is a remote position and must be based in Colombia For nearly two decades, Zonar Systems has been pioneering products and services that make the transportation industry safer, more productive, and more efficient. The Senior Security Compliance Analyst is a key member of the Zonar Security and Compliance team, responsible for leading activities that ensure Zonar’s products and supporting infrastructure meet applicable security and regulatory standards—including SOC 2, FedRAMP, and related customer and internal compliance requirements. This position provides both leadership and hands‑on execution within Zonar’s governance, risk, and compliance (GRC) program. The analyst will coordinate audits, manage evidence and control documentation, drive remediation activities, and work closely with Product Engineering, IT Security, and Corporate Operations teams across the U.S. and LATAM regions. The ideal candidate has direct experience in SaaS security compliance and is comfortable working cross‑functionally with both technical and non‑technical stakeholders. Key Responsibilities and Duties Security Governance and Framework Management (70% Focus) Lead and execute all tasks necessary to achieve and maintain critical security certifications, including SOC2 Type I and Type II and the roadmap towards FedRAMP (20x) compliance. Manage the GRC lifecycle by identifying control gaps, defining necessary security policies and standards, and tracking remediation efforts across engineering teams. Be the primary respondent for all customer and security questionnaires, documentation requests, and due diligence activities. Develop, implement, and maintain security policies, standards, and procedures in collaboration with stakeholders. Monitor regulatory changes and security advisories, recommending and overseeing the implementation of necessary threat and compliance remediations. Conduct risk assessments, document findings, and track remediation activities to closure. Support third‑party vendor security reviews, ensuring vendor compliance with security requirements. Monitor changes in regulatory or framework requirements (e.g., SOC, FedRAMP, ISO 27001, NIST 800-53) and ensure controls remain aligned. Technical Process Oversight (30% Focus) Provide expert‑level guidance and audit support on Secure Software Development Life Cycle (SSDLC) practices, including DevSecOps, Threat Modeling, and Secure Coding. Identify and document security risks and control deficiencies within Zonar Products, articulating the required fix to engineering teams. Collaborate with Engineering to evaluate and recommend strategic security technologies that support compliance requirements. Review system configurations and vulnerability scan results for compliance alignment. Develop and provide security training and awareness programs specifically targeted at engineers and product teams. Knowledge, Skills, and Abilities 5+ years of progressive experience in Information Security and Governance, Risk, and Compliance (GRC), with at least 3 years supporting SaaS product environments. Strong working knowledge of major security frameworks (e.g., ISO 27001, SOC2, and FedRAMP). Proven success participating in or leading SOC2 Type I and Type II and/or FedRAMP audit cycles. • Exceptional analytical and documentation skills, including the ability to create audit‑ready evidence and clear policy materials. Hands‑on familiarity with cloud technologies and controls (e.g., AWS, GCP, IAM, KMS, Security Command Center). Foundational understanding of software development or scripting (Python, Bash, PowerShell) sufficient to collaborate effectively with engineering teams. Bilingual – English and Spanish (fluent/professional working proficiency required). Strong written and verbal communication skills in both languages to collaborate with U.S. and LATAM teams. Preferred Qualifications: Experience using GRC and audit management tools (e.g., Drata, Vanta, Jira, Confluence). • Prior involvement in customer‑facing security assurance or sales support activities. Security certifications (CISA, CISSP, CCSK, or similar) a plus #J-18808-Ljbffr
-
Senior Security Compliance Analyst
hace 2 semanas
WorkFromHome, Colombia Zonar Systems A tiempo completoFor nearly two decades, Zonar Systems has been pioneering products and services that make the transportation industry safer, more productive, and more efficient. The Senior Security Compliance Analyst is a key member of the Zonar Security and Compliance team, responsible for leading activities that ensure Zonar’s products and supporting infrastructure meet...
-
Governance & Compliance Security Analyst
hace 2 días
WorkFromHome, Colombia Edgeuno A tiempo completoAbout EdgeUno EdgeUno empowers the next era of digital connectivity across Latin America. With one of the region’s most interconnected data centers and network platforms, we support mission‑critical workloads for enterprises, ISPs, hyperscalers, and digital platforms. Our culture is built on ownership, agility, technical excellence, and accountability....
-
Remote Security Compliance Lead
hace 1 semana
WorkFromHome, Colombia Zonar A tiempo completoA leading technology firm is seeking a Senior Security Compliance Analyst based in Colombia. This remote role involves leading efforts to ensure compliance with security standards such as SOC2 and FedRAMP. The ideal candidate will have over 5 years of experience in Information Security, particularly in SaaS environments, and possess strong bilingual...
-
Remote Senior Security
hace 2 semanas
WorkFromHome, Colombia Zonar Systems A tiempo completoA technology company is seeking a Senior Security Compliance Analyst to lead compliance activities for their products in Colombia. This remote position requires expertise in Information Security and GRC, with a focus on achieving SOC 2 and FedRAMP certifications. The ideal candidate will be bilingual in English and Spanish and have strong analytical skills....
-
ISO 27001 Security
hace 2 días
WorkFromHome, Colombia Edgeuno A tiempo completoA leading digital connectivity firm in Colombia is seeking a Governance & Compliance Security Analyst responsible for managing the Information Security Management System and ensuring ISO 27001 compliance. The ideal candidate should have a bachelor's degree in Information Security or a related field and possess 2–5+ years of relevant experience. Strong...
-
Senior Data Security Engineer
hace 1 semana
WorkFromHome, Colombia J.S. Held LLC A tiempo completoCompany Description J.S. Held, a global consulting firm providing specialized technical, scientific, financial, and advisory services, is seeking a Senior Data Security Engineer to lead the design, implementation, and governance of enterprise data security programs across platforms such as Microsoft 365, Box, Azure, and emerging AI platforms. This role is...
-
Senior Analyst, Payroll
hace 3 días
WorkFromHome, Colombia Mastercard A tiempo completoOur Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships...
-
Remote Senior Data Security Engineer
hace 1 semana
WorkFromHome, Colombia J.S. Held LLC A tiempo completoA global consulting firm is seeking a Senior Data Security Engineer to lead the design and implementation of data security programs across platforms like Microsoft 365 and Azure. This critical role protects sensitive information and ensures compliance while advancing security capabilities. The ideal candidate will have 7+ years of experience and a deep...
-
LAC Data Security
hace 3 días
WorkFromHome, Colombia Visa A tiempo completoA global payment technology company based in Bogotá is seeking an Ecosystem Security Manager to support data security functions across Latin America and the Caribbean. The ideal candidate will have a Bachelor's degree, 2+ years in Visa Data Security Programs, and 5+ years in Information Security or Risk Management. Responsibilities include managing...
-
LAC Data Security
hace 5 días
WorkFromHome, Colombia Tink A tiempo completoA global payments leader is seeking a LAC Ecosystem Security Manager to oversee data security programs in Latin America. The role requires a Bachelor's degree, extensive experience in Information Security, and knowledge of PCI standards. Ideal candidates will work across multiple programs, manage vendor relationships, and support compliance efforts. Fluency...