Match score not available

Sr. Security Compliance Specialist

Remote: 
Full Remote
Contract: 
Experience: 
Mid-level (2-5 years)
Work from: 
North Carolina (USA), United States

Offer summary

Qualifications:

Bachelor's degree in computer science or equivalent experience, 3+ years of security, governance, compliance, or risk management experience in FinTech or SaaS, Familiarity with ISO 27001, SOC 1, SOC 2, NIST frameworks, Experience with GRC tools and methodologies, Ability to communicate effectively across multiple partners.

Key responsabilities:

  • Coordinate security compliance external assessments like SOC 1, SOC 2, ISO 27001
  • Handle quality control of compliance controls such as access reviews and change reviews
  • Perform compliance assessments and work with system owners for remediation
  • Partner with Sales for customer security inquiries and create documentation
  • Identify automation opportunities and partner on project improvements
Avalara logo
Avalara
1001 - 5000 Employees
See more Avalara offers

Job description

Logo Jobgether

Your missions

What You'll Do

Avalara is looking for someone to support a growing team building on the security compliance function. You will be reporting to a Manager of Security Compliance and you will work hybrid out of the Durham, NC area.

This role is not eligible for visa sponsorship.*

You Will

  • Coordinate security compliance external assessments such as SOC 1, SOC 2, ISO 27001.
  • Handle coordination of quality control of assigned compliance controls such as access reviews, change reviews, terminated user analysis.
  • Ensure controls are performed by all partners within defined Service level agreements.
  • Perform compliance assessments and work with system owners to fix.
  • Help enhance Avalara's common controls framework.
  • Help collect and migrate control information into Avalara's GRC platform.
  • Be the contact for go-to-market related security inquiries.
  • Partner with Sales organization to support the sales engagement lifecycle, including customer meetings and customer security inquiries.
  • Develop customer-facing security documentation.
  • Identify areas for automation and business process improvements.
  • Partner with internal and external groups on multiple simultaneous projects.


Job Duties

  • Coordination of security compliance external assessments such as SOC 1, SOC 2, ISO 27001.
  • Coordination, execution, and quality control of assigned compliance controls such as access reviews, change reviews, terminated user analysis.
  • Ensure controls are appropriately performed by all stakeholders within defined SLAs.
  • Perform compliance assessments and work closely with system owners to remediate.
  • Help enhance Avalara’s common controls framework.
  • Assist in collecting and migrating control information into Avalara’s GRC platform.
  • Act as a point of contact for go-to-market related security inquiries.
  • Partner closely with Sales organization to support the sales engagement lifecycle, including customer meetings and customer security inquiries. Develop customer facing security documentation.
  • Identify areas for automation and/or business process improvements.
  • Work strategically and independently with internal and external groups on multiple simultaneous projects.
  • Perform other duties as assigned.


What You'll Need to be Successful

  • You have a Bachelor's degree in computer science, or equivalent experience.
  • You have 3+ years of security, governance, compliance, or risk management experience, in FinTech or SaaS environment.
  • You have 3+ years of professional experience working with ISO 27001, SOC 1, SOC 2, SOX, NIST and other similar frameworks.
  • You have experience with global corporate security, risk management, or governance roles
  • You have 3+ years working with security governance frameworks, regulatory requirements, and industry best practices (e.g., ISO 27001, NIST, GDPR, CCPA).
  • You are familiar with security technologies, GRC tools (eg: ServiceNow), and methodologies.
  • You are experienced in security and privacy risk management principles.
  • You excel in communicating across multiple partners and customers verbally and in writing.


About The Team

Avalara's Organizational Risk, Resilience, Compliance and Audit team (ORRCA) manages multiple risk and compliance projects.

How We'll Take Care of You

Total Rewards

In addition to a great compensation package, paid time off, and paid parental leave, many Avalara employees are eligible for bonuses.

Health & Wellness

Benefits vary by location but generally include private medical, life, and disability insurance.

Inclusive culture and diversity

Avalara strongly supports diversity, equity, and inclusion, and is committed to integrating them into our business practices and our organizational culture. We also have a total of 8 employee-run resource groups, each with senior leadership and exec sponsorship.

Flexible hybrid working

We support hybrid work and flexible schedules for our employees.

Learn more about our benefits by region here: https://careers.avalara.com/

About Avalara

We’re Avalara. We’re defining the relationship between tax and tech.

We’ve already built an industry-leading cloud compliance platform, processing nearly 40 billion customer API calls and over 5 million tax returns a year.

Last year, we became a billion-dollar business, and our tribe expanded by a cool thousand people - there’s nearly 5,000 of us now. Our growth is real, and we’re not slowing down - not until we’ve achieved our mission - to be part of every transaction in the world.

We’re bright, innovative and disruptive, like the orange we love to wear. It captures our quirky spirit and optimistic mindset. It shows off the culture we’ve designed, that empowers our people to win. Ownership and achievement go hand in hand here. We instill passion in our people through the trust we place in them.

We’ve been different from day one. Join us, and your career will be too.

EEO Statement

We’re an Equal Opportunity Employer. Supporting diversity and inclusion is a cornerstone of our company — we don’t want people to fit into our culture, but to enrich it. All qualified candidates will receive consideration for employment without regard to race, color, creed, religion, age, gender, national orientation, disability, sexual orientation, US Veteran status, or any other factor protected by law. If you require any reasonable adjustments during the recruitment process, please let us know.

Required profile

Experience

Level of experience: Mid-level (2-5 years)
Spoken language(s):
Check out the description to know which languages are mandatory.

Soft Skills

  • verbal-communication-skills
  • quality-control

Compliance Officer Related jobs