Bachelor’s degree in cybersecurity or related field, master’s preferred., Minimum of five years’ experience in information security, with at least two years in software development., Experience with ISO27001, SOC2 audits, and regulatory compliance such as GDPR, CCPA, PCI., Proficiency with Microsoft Azure, O365, PowerShell, and secure SDLC tools..
Key responsibilities:
Partner with development teams to integrate security into the SDLC.
Ensure compliance with ISO27001 and SOC2 standards through audits.
Conduct internal audits and manage security assessments and reviews.
Serve as the primary contact for vendors and champion security best practices.
Report this Job
Help us maintain the quality of our job listings. If you find any issues
with this job post, please let us know. Select the reason you're reporting
this job:
K2 Integrity is the preeminent risk, compliance, investigations, and monitoring firm—built by industry leaders, driven by interdisciplinary teams, and supported by cutting-edge technology to safeguard our clients’ operations, reputations, and economic security. K2 Integrity represents the merger of K2 Intelligence, an industry-leading investigative, compliance, and cyber defense services firm founded in 2009 by Jeremy M. Kroll and Jules B. Kroll, the originator of the modern corporate investigations industry, and Financial Integrity Network (FIN), a premier strategic advisory firm founded by Juan Zarate and Chip Poncy dedicated to helping clients achieve their financial integrity goals. K2 Integrity leverages unmatched multidisciplinary experience to develop cutting-edge solutions, stimulate business opportunities, and shape global economic security in a complex world. Whether it’s protecting clients’ assets or navigating the complex financial regulatory landscape to help clients identify, manage, and mitigate risk, K2 Integrity is an advisor trusted to meet and exceed clients’ goals in a rapidly changing world. To learn more about how K2 Integrity is revolutionizing the management of risk, visit our website, www.k2integrity.com.
K2 Integrity is seeking an experienced Information Security Analyst who is passionate about secure software development and developer enablement. This is a contract role. This candidate will be responsible for the design, implementation, and management of ISO27001-compliant security controls within our software development process. The ideal candidate will have the ability to collaborate with a software development team, raise awareness of secure coding practices, and foster a security-focused culture. We are looking for someone with the expertise to integrate robust security measures seamlessly into the development process, ensuring that security becomes an integral part of our software development lifecycle.
Responsibilities:
Partner with software development teams to integrate security practices into the software development process.
Ensure that SDLC processes comply with ISO27001 and SOC2 audit standards within agreed timeframes.
Develop and maintain policies, coding standards, and best practices for developers.
Maintain and support internal security systems relevant for secure software development.
Identify and correct issues with vendors, suppliers, and subcontractors as required.
Identify security gaps and manage gap mitigation.
Participation in audit, incident response and access review processes.
Serve as the primary point of contact for technology vendors, coordinating support activities, managing vendor relationships, and ensuring timely resolution of issues.
Champion good security practices and assist developers with questions.
Act as project manager for information security projects.
Qualifications:
Bachelor’s of science in cybersecurity required; master’s preferred.
At least five years’ experience in the information security field and at least 2 years within software development
Experience with Microsoft Azure, O365, and PowerShell.
Experience with software tools which facilitate secure SDLC.
Experience completing ISO27001, and SOC2 audits.
Experience with regulatory compliance (GDPR, CCPA, PCI).
Good understanding of information security principles.
Ability to explain complex theories to development staff.
Strong knowledge of operating systems and related security issues (Windows, Linux, mobile).
Strong knowledge of network security systems and practices.
Strong knowledge of encryption technologies and common issues.
Any security certification or progress towards a certification is a plus.
Strong desire to learn, research, and problem solving.
Excellent communication skills.
This role is work from home (USA).
Required profile
Experience
Level of experience:Mid-level (2-5 years)
Spoken language(s):
English
Check out the description to know which languages are mandatory.