Remote job
Security Compliance Analyst
Job details
About this role
Role overview A fare payment platform serving transit agencies worldwide is hiring a Security Compliance Analyst to keep its security controls running reliably and on time. The role focuses on owning repeatable control processes, supporting customer-facing security work, and helping maintain certifications central to the business. It suits someone who is detail-oriented, organized, and motivated to make recurring work simpler and more reliable.
Responsibilities - Own assigned security control processes end to end: plan them, execute them, gather evidence, and follow findings through to closure. - Run manual and tool-based controls, identifying and closing gaps where controls are missing or inconsistently applied. - Perform periodic reviews such as user access reviews and ensure results and follow-up actions are properly documented. - Operate the Third-Party Risk Management process, assessing suppliers, reviewing their security posture, tracking risks, and scheduling reassessments. - Maintain registers that underpin security and privacy processes (supplier, risk, asset, data processing), keeping them accurate and current. - Support commercial teams by analyzing security and privacy requirements in bids and tenders, and by answering customer security questionnaires and information requests. - Prepare evidence and documentation for audits and certifications such as ISO 27001, SOC 2, PCI DSS, and Cyber Essentials. - Identify and implement opportunities to automate or improve control processes, including the use of AI tools.
Requirements - Hands-on experience in information security, IT compliance, internal control, audit, or a closely related field. - Working understanding of core security concepts such as access control, risk management, and data protection. - Clear writing skills with the ability to structure documentation, registers, and questionnaire responses well. - Strong organization and ability to juggle several recurring tasks and deadlines simultaneously. - Comfort taking ownership of work and asking questions when something is unclear.
Nice to have - Experience with Third-Party Risk Management or vendor security assessments. - Familiarity with frameworks such as ISO 27001, SOC 2, PCI DSS, GDPR, or NIST. - Experience supporting RFPs, tenders, or customer security questionnaires. - Hands-on experience with compliance automation or GRC platforms, including Jira or Confluence. - Interest in automation through scripting, low-code tools, or AI-driven workflow improvements.
Benefits and work setup - Fully remote position open to candidates based in Colombia. - 15 days of paid vacation plus 18 public holidays per year. - Private healthcare, monthly team bonding allowance, and menopause support. - Choice of workstation and the ability to work from any country for up to three months per year. - Annual training allowance (up to $750 USD) and a home office stipend (up to $250 USD).