Job details
About this role
Our Mission
iSeatz drives enduring brand loyalty through exceptional, connected experiences. Our digital commerce and technology solutions enable travel and lifestyle bookings for the world’s leading brands in financial services, travel, and hospitality, including American Express, IHG Hotels & Resorts, Qantas, and more.
What We Do
We have a history of long-term trusted relationships and innovation that drives tangible value to our customers through a customizable, scalable, and secure platform, a global third-party marketplace, and loyalty integration. Our proprietary platform processes over $9B per year in transactions.
We aspire to put our customers at the heart of every decision and exceed their expectations with best-in-class solutions and business-value innovations.
What You’ll Do
The Cybersecurity Compliance Engineer reports to the Information Security Manager and supports the Governance, Risk, and Compliance function, partnering with team leads, directors, and compliance auditors to maintain and enhance our compliance initiatives, focusing on data protection and security.
In this role, you will ensure our products, systems, and processes meet applicable regulatory, security, and compliance requirements.
, you will ensure our products, systems, and processes meet applicable regulatory, security, and compliance requirements.
, you will ensure our products, systems, and processes meet applicable regulatory, security, and compliance requirements.
Your Impact
- Ensure day-to-day compliance activities across applicable frameworks and requirements with a focus on PCI DSS but including SOC 2, NIST, GDPR, ISO, and customer-specific security and compliance obligations.
- Lead the preparation and execution of internal and external audits, including evidence collection, control validation, auditor coordination, issue tracking, and remediation follow-up.
- Perform technical security and compliance reviews of third-party vendors and service providers, evaluating security controls, architecture, data handling practices, compliance posture, and associated risks.
- Support customer and partner security assessments, including security questionnaires, evidence requests, technical discussions, and validation of contractual security and compliance requirements.
- Evaluate new technologies and services for security and compliance risk, and provide practical recommendations before implementation or adoption.
- Translate compliance and regulatory requirements into clear technical and operational requirements for Engineering, DevOps, Product, and other teams.
- Support remediation of Pen Test and external audit findings.
- Review and validate technical security controls related to identity and access management, logging and monitoring, vulnerability management, encryption, network security, secrets management, data protection, and secure development practices.
- Manage compliance controls and evidence within compliance automation and GRC platforms, ensuring controls are properly implemented, tested, documented, and supported by appropriate evidence.
- Identify compliance and security gaps through control testing, technical reviews, risk assessments, and monitoring, and work with control owners to develop and track remediation plans through completion.
- Conduct and support periodic risk assessments, access reviews, vendor reviews, policy reviews, and other recurring compliance activities.
- Maintain policies, standards, procedures, control documentation, risk records, exceptions, and other compliance artifacts to ensure they remain accurate and aligned with current business and technical environments.
- Partner with Information Security and technical teams to improve compliance processes through automation, improved monitoring, and more efficient evidence collection and validation.
What You Bring To The Table
To The Table
To The Table
- Experience working in information security, audit, compliance, GRC, or a closely related technical field.
- Strong working knowledge of PCI-DSS assessments, including experience supporting assessments, control testing, evidence collection, and remediation activities.
- Understanding of common security concepts and controls, including IAM, encryption, vulnerability management, logging and monitoring, and data protection.
- Experience performing security and compliance reviews of systems, technologies, processes, or third-party service providers.
- Experience evaluating technical and administrative controls to determine whether they are appropriately designed, implemented, and supported by sufficient evidence.
- Experience with risk assessments, control testing, compliance findings, and remediation tracking.
- Ability to understand technical architectures, system configurations, data flows, and security controls well enough to identify compliance concerns and communicate them effectively.
- Experience managing or supporting internal and external security and compliance audits.
- Strong documentation skills, including experience maintaining policies, procedures, control descriptions, risk records, and audit evidence.
- Strong organizational and project management skills with the ability to manage multiple compliance initiatives, audit requests, and deadlines simultaneously.
- Strong written and verbal communication skills with the ability to explain security and compliance requirements to both technical and non-technical audiences.
- Experience working with GRC or compliance automation platforms such as Drata, Vanta, Secureframe, AuditBoard, or similar tools.
Bonus Points
- Relevant security, audit, risk, or compliance certifications such as CISA, CRISC, PCIP, CISSP, CIA, or ISO 27001 Lead Auditor/Lead Implementer.
- Experience working with additional security and compliance frameworks such as NIST CSF, NIST 800-53, ISO 27001, or similar frameworks.
- Experience supporting compliance programs in AWS or other cloud-native environments.
- Experience mapping controls across multiple compliance frameworks.
- Working knowledge of cloud security and compliance concepts, preferably within AWS environments, including IAM, logging, encryption, network security, and the shared responsibility model.
Pay Range for this Position:
$112,000—$140,000 USD
Location
This role is remote and can be located anywhere inside the continental United States. iSeatz is a New Orleans-based company with Central Time Zone business hours, but feel free to work from your home office, from the beach, or from the cottage you rented for the summer!
What We Bring To The Table
iSeatz has been honored as an Inc. Magazine Best Workplace for the past three years — recognition based on our commitment to transparency, trust, and open communication, as well as our efforts to foster growth for our team members beyond their current roles and responsibilities.
We trust our team members to use their expertise and creativity to deliver high-quality results — without micromanagement — and support them in building careers that are as dynamic and multifaceted as the work we do.
We believe there's no one-size-fits-all approach to engagement or collaboration. That’s why we strive to provide the tools, autonomy, and support employees need to succeed — while delivering exceptional products and services to our customers.
- We recognize that great work deserves meaningful support.
- At iSeatz, we provide competitive compensation and a comprehensive suite of benefits to match.
- Our team members enjoy robust health insurance, a 401(k) plan with company matching, generous paid time off, and up to eight weeks of paid parental leave for eligible caregivers.
- We’re a remote-first company that values flexibility and autonomy, and we invest in continuous learning with an annual professional development allowance.
- Whether you're growing your skills, your family, or your impact — we’re here to support what’s next.
We Value A Diverse Workplace
We are committed to building and maintaining a culture of support, awareness, and sensitivity about the importance and impact of our differences and leverage these differences to build a stronger iSeatz.
If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact the People Operations Team at humanresources@iseatz.com.
A Note About Joining Our Workforce
At iSeatz, we're building a team of bold thinkers, innovative builders, and thoughtful collaborators — people who are excited to make an impact, grow their careers, and help shape the future of travel and loyalty tech.
If you're energized by meaningful work, passionate about creating exceptional experiences, and ready to bring your unique perspective to a team that values trust, growth, and transparency — we can't wait to meet you.