Governance & Compliance Security Analyst
hace 6 días
**About**EdgeUno**
EdgeUno empowers the next era of digital connectivity across Latin America. With one of the region’s most interconnected data centers and network platforms, we support mission-critical workloads for enterprises, ISPs, hyperscalers, and digital platforms. Our culture is built on ownership, agility, technical excellence, and accountability.
**Role Summary**
The Governance & Compliance Security Analyst is responsible for maintaining and improving the company’s **information security governance, ISO 27001 compliance,**policies** and procedures, and**third**party** risk management**. This role supports audits and certifications, ensures alignment with regulatory and contractual requirements, and works closely with technical and business teams to keep the Information Security Management System (ISMS) effective and up to date.
**Location & Language**
- Based in Quito
- Advanced English required
**Key Responsibilities**
- **ISO 27001 & ISMS Management**
- Maintain and update the **Information Security Management System (ISMS)** in line with ISO/IEC 27001.
- Coordinate periodic **risk assessments**, Statement of Applicability (SoA) updates, and treatment plans.
- Support **internal and external audits** (preparation, evidence collection, tracking of nonconformities and corrective actions).
- **Policies, Standards & Procedures**
- Develop, review, and maintain **information security policies, standards, and procedures**.
- Coordinate periodic reviews and approvals with management and relevant stakeholders.
- Ensure documentation is aligned with ISO 27001, regulatory requirements, and business needs.
- **Compliance & Regulatory Support**
- Monitor and support compliance with applicable **laws, regulations, and contractual security requirements** (telecom, data protection, client demands).
- Prepare and maintain **evidence** repositories** for certifications, audits, and customer due diligence.
- Support responses to **security questionnaires, RFPs, and client audits**.
- **Third**Party** Risk Management**
- Support the **third**party** risk management process**: security assessments of vendors, service providers, and partners.
- Review certifications and security documentation from third parties (e.g., ISO 27001, SOC 2).
- Track identified risks and remediation actions for critical third parties and maintain an uptodate thirdparty inventory.
- **Documentation, Reporting & Metrics**
- Keep ISMS and governance **documentation well organized and current**.
- Produce **reports and dashboards** on compliance status, audit results, and ISMS performance for management.
- Help define and track **security KPIs/KRIs** related to governance and compliance.
- **Awareness & Support to the Business**
- Contribute to **security awareness initiatives**, especially around policies, acceptable use, and data protection.
- Act as a **point of contact** for questions related to policies, compliance, and thirdparty security requirements.
- Work closely with IT, Security Operations, Legal, HR, Procurement, and business units to ensure controls are understood and applied.
**Requirements**:
- Bachelor’s degree in Information Security, Systems Engineering, Law, Business, or related field (or equivalent experience).
- 2-5+ years of experience in information security, GRC (Governance, Risk & Good understanding of ISO/IEC 27001 and related standards.
- Experience with security policies, procedures, and audit processes.
- Familiarity with basic risk management concepts and methods.
- Ability to review and interpret contracts, SLAs, and security clauses (desirable).
- Strong documentation, organization, and reporting skills.
- Ability to work collaboratively with technical and nontechnical teams.
- Attention to detail, structured thinking, and a proactive mindset.
**Nice to Have**
- Experience in **telecom, ISP, hosting, or cloud** environments.
- Knowledge of **data protection regulations** (e.g., local privacy laws, GDPR exposure).
- Certifications such as **ISO 27001 Lead Implementer/Auditor**, CISA, or similar.
**What We Offer**
- Competitive compensation aligned with senior technical roles in the region
- Opportunity to influence software quality standards across the organization
- Strong engineering culture focused on ownership, automation, and continuous improvement
- Collaborative, multicultural, execution-driven environment
- A critical role in a fast-growing digital infrastructure company operating across Latin America
**Note: Please**submit** your resume in English.
-
Security Risk Governance
hace 1 semana
Bogotá, Colombia Laborintos A tiempo completoThe Specialist, Security Risk Governance role contributes to the overall success of the Security Governance Services / Information Security & Control (IS&C) globally ensuring specific individual goals, plans, initiatives are executed / delivered in support of the team's business strategies and objectives. The incumbent must ensure all activities conducted...
-
Security and Compliance Analyst
hace 3 días
Bogotá, Colombia Equinix A tiempo completo**Security and Compliance Analyst**: - JR-153136 - Hybrid - Bogota - Warsaw - Security, Risk and Business Continuity - Full time **Who are we?** Equinix is the world’s digital infrastructure company®, operating over 260 data centers across the globe. Digital leaders harness Equinix's trusted platform to bring together and interconnect foundational...
-
Cybersecurity Governance, Risk and Compliance Lead
hace 3 semanas
Bogotá, Colombia Quetzalintl A tiempo completoCybersecurity Governance, Risk and Compliance Lead - Bilingual English/Spanish We are seeking a bilingual, experienced, and highly skilled Cybersecurity Governance, Risk, and Compliance (GRC) Lead. Experience managing security awareness and training programs is also required. The ideal candidate will have a deep understanding of cybersecurity frameworks,...
-
Sr. Assurance
hace 2 semanas
Bogotá, Colombia Coupa A tiempo completoSr. Assurance & Compliance Analyst - 10978 Coupa Bogota, D.C., Capital District, Colombia Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and...
-
Security Compliance Manager
hace 2 semanas
Bogotá, Cundinamarca, Colombia Aprende Institute A tiempo completoAprende Institute is seeking an experienced Security Compliance Managerwith strong project management skills to lead our efforts in analyzing, auditing, and implementing security protocol protections to ensure compliance with industry standards such as SOC 2. This role is pivotal in managing security compliance initiatives, working closely with...
-
Information Security Analyst
hace 1 semana
Bogotá, Colombia Rainforest Alliance, Incorporated A tiempo completoThe Opportunity: We are seeking an experienced and highly motivated Information Security Analyst to join our security team. This role will be critical in protecting our digital assets, detecting and responding to security incidents, and ensuring the continuous improvement of our security posture. Key Responsibilities Security Operations & Incident Response:...
-
Information Security Analyst
hace 1 semana
Bogotá, Distrito Capital, Colombia Rainforest Alliance A tiempo completoOpportunity We are seeking an experienced and highly motivated Information Security Analyst to join our security team. This role will be critical in protecting our digital assets, detecting and responding to security incidents, and ensuring the continuous improvement of our security posture. You will work proactively to identify security risks, develop and...
-
Sr. Assurance
hace 2 semanas
Bogotá, Colombia Exari Systems A tiempo completoSr. Assurance & Compliance Analyst – 10978 Apply for this Job Coupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you...
-
Information Security Analyst
hace 2 semanas
Bogotá, Cundinamarca, Colombia Rainforest Alliance A tiempo completoThe Opportunity: We are seeking an experienced and highly motivated Information Security Analyst to join our security team. This role will be critical in protecting our digital assets, detecting and responding to security incidents, and ensuring the continuous improvement of our security posture. You will work proactively to identify security risks,...
-
Sr. Assurance
hace 2 semanas
Bogotá, Colombia Qplusequality A tiempo completoCoupa makes margins multiply through its community-generated AI and industry-leading total spend management platform for businesses large and small. Coupa AI is informed by trillions of dollars of direct and indirect spend data across a global network of 10M+ buyers and suppliers. We empower you with the ability to predict, prescribe, and automate smarter,...