New

Tech Risk Management Analyst

Buenos Aires, Argentina

About AppDirect

Become a digital, global citizen and enable the new generation of digital entrepreneurs around the world. AppDirect offers a subscription commerce platform to sell any product, through any channel, on any device - as a service. We power millions of subscriptions worldwide for organizations. We do this by our values-driven culture - one that enables you to Be Seen, Be Yourself, and Do Your Best Work.

About You

We’re looking for talented yet humble individuals who are smart, passionate, and want to drive disruption in the Information security industry. If you thrive in a fast-paced, collaborative workplace, AppDirect provides an environment where you will be challenged and inspired every day. If you relish the freedom to bring creative, thoughtful solutions to the table that reflect your experience and personality, there's no limit to what you can accomplish here.

What you'll do and how you'll have an impact

You will be a member of the Compliance team (part of the Infosec team) as a Tech Risk Management Analyst. You will join the team primarily responsible for continuous compliance monitoring, risk management, vendor management, and maintaining our various certifications, such as ISO 27001, PCI-DSS, SOC 2, and SOC 1.

You have both soft skills and technical potential and you think that the security team must be an ally and a facilitator for the company and all its members. Below is what we expect from you:

  • Provide overall oversight for continued compliance and ongoing certifications (e.g. SOC 1 and 2, PCI DSS, ISO 27001, NIST CSF, GDPR, HIPAA, ISO 42001, NIST AI RMF, etc.).
  • Collaborate with internal staff to ensure that appropriate controls are implemented, operating properly, in accordance with the corporate policies.
  • Conduct audit readiness assessments and coordinate with internal and external functions and audit resources.
  • Serve as the primary point of contact during external audits, including coordinating evidence requests, facilitating auditor walkthroughs, and managing audit timelines to closure.
  • Improve and maintain the Privacy practice at AppDirect.
  • Develop and implement in collaboration with Engineering and architects mechanisms to automate the generation of evidence.
  • Support security and compliance due diligence and integration activities for M&A transactions.
  • Oversee customers questionnaires by liaising with internal staff and delivering expected results
  • Develop and maintain organization information security policies based on applicable standards, information security requirements, business requirements and legal requirements.
  • Communicate compliance requirements and risk posture to technical and non-technical stakeholders, including executive leadership.
  • Expertise in US certifications, such as GovRAMP or FedRAMP, is considered a strong asset.
  • Demonstrated ability to use AI-assisted workflows to improve efficiency in compliance operation
  • Facilitate discussions and reach decisions that can have a good balance between security and usability.

What we're looking for

  • A degree or comparable experience (~5+ years) in Information Security or a related field.
  • Prior experience in IT compliance and Audit support (SOC2, ISO 27001 and PCI-DSS).
  • Prior experience with risk management and GRC Tools.
  • Good experience with Privacy frameworks and what needs to be implemented to meet customer/internal needs.
  • Successful in cross-functional team collaboration to drive early security adoption 
  • Good understanding of networking, cloud computing, operating systems concepts.
  • Experience on cloud adoption strategies including design and implementation of security controls and compliance monitoring.
  • Experience with project management (planning, organizing, and managing resources to successfully achieve audits).
  • Strong verbal, written and presentations skills with the ability to find innovative solutions to complex problems (compliance vs risk vs security vs usability).
  • Nice to have, any Information Security Certification (CISA, CDPSE, ISO implementer , Security+, CISSP).
  • Demonstrated technical experience in development, networking, IT support, system administrations, etc.

At AppDirect, we believe that innovation thrives in an environment that houses diversity of excellence, experience and thought. We respect each AppDirector as their own fingerprint; unique with no one alike. We foster an environment of inclusion without regard to race, religion, age, sexual orientation, or gender identity enabling AppDirectors to embrace their uniqueness to do their best work. As such, we strongly encourage applications from Indigenous peoples, racialized people, people with disabilities, people from gender and sexually diverse communities, and/or people with intersectional identities.

At AppDirect we take privacy very seriously. For more information about our use and handling of personal data from job applicants, please read our Candidate Privacy Policy. For more information of our general privacy practices, please see AppDirect Privacy Notice: https://www.appdirect.com/about/privacy-notice

Create a Job Alert

Interested in building your career at AppDirect? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf


Select...