
Security Compliance Engineer III
- Brasil
- Permanente
- Período integral
- Health and dental insurance
- Meal and restaurant vouchers
- Fixed monthly stipend for internet and mobile expenses
- Company-issued device (hardware and software)
- Annual bonuses
- Managing or supporting the maintenance and growth of the continuous monitoring program and helping non-compliance teams with implementing their own compliance monitoring functions.
- Analyzing and interpreting industry standards, regulations and laws as well as industry trends in order to help the team continue to refine and define the compliance program.
- Developing and documenting automation to help the company implement better controls but to also monitor the effectiveness of those controls.
- Preparing reporting metrics that capture the compliance posture of the various business units and security and compliance controls within the different environments at InComm Payments.
- Implementing automated evidence collection techniques to assist with external audits and internal monitoring.
- Partnering with security teams, IT teams and the business to identify and analyze security requirements to align with compliance requirements.
- Identifying, investigating, and reporting potential compliance violations and providing guidance on solutions to remediate where necessary.
- Educating and building awareness of compliance requirements and the compliance program as well as security domains and security tools.
- Supporting the organization by creating a security first mindset to facilitate a secure environment while achieving compliance in parallel.
- Leading or participating in internal reviews to assess large and small projects to validate the compliance posture is still intact post change.
- Supporting the team in other activities such as healthcare attestation requests from health plans and annual audit requests for third party audits and assessments.
- Minimum of 5 years of experience in Information Security and/or IT Compliance or related industry.
- Experience in scripting languages and other automation techniques for monitoring program level functions and compliance controls, including evidence gathering and policy-as-code.
- Expert in data collection and analysis techniques.
- Familiarity with systems integration techniques.
- Experience with leading process and program development for large, widespread new functions.
- Experience in performing self-assessments/gap analyses to align with internal and external standards.
- Expert in understanding the security component of compliance requirements and guiding people on how closely related they are.
- Knowledge of applying compliance requirements and methodologies to new and changing system designs and architectures.
- Hands on moderate to expert experience with a broad range of IT and Information Security products and technologies such as identity and access management, vulnerability management, encryption key management, logging, and application security systems.
- Strong analytical problem-solving skills, very detail oriented and organized approach, excellent communication skills and strong interpersonal skills.
- Strong communication and understanding, both written and verbal in English.
- Strong to relay technical concepts in a clear and concise manner.
- Ability to work well in a cross functional team environment.
- Comfortable interfacing with and gaining the trust of all levels of the workforce.
- Must be a self-starter, flexible, innovative, and adaptive.
- Associate Degree, or, Technologo (Technologist) Degree, or higher is required.
- CISA, CISM, CISSP or other equivalent certification preferred, but not required. Career development plan to include certifications upon hire.
- Strong knowledge of technology such as Windows, Linux, Oracle/MSSQL, Azure/AWS, Active Directory, SIEMs, Network Security, and Application Security.
- Strong knowledge and understanding of security best practices (NIST CSF)
- Knowledge and understanding of the following frameworks/regulations: CMS, HIPAA, HITRUST, PCI, US State Laws (NYDFS, CCPA, etc.). Ability and desire to learn more about these obligations where not as strong. The heaviest areas that the team works in are PCI, HITRUST, HIPAA and CMS therefore it is critical to have working knowledge of these and/or be able to learn and apply the concepts of those requirements.