The Role
Support information security compliance programs focused on ISO 27001, SOC 1, and SOC 2. Develop and maintain security policies, conduct risk assessments and gap analyses using ISO 27001 and NIST CSF controls, prepare audit and customer RFI documentation, track remediation, report compliance metrics, and perform third-party vendor risk assessments.
Summary Generated by Built In
Job Description:
- Support the implementation,
maintenance, and continuous improvement of information security compliance
programs, specifically focusing on
ISO 27001, SOC 1 and SOC 2.
- Develop, review, and update security policies,
procedures, and guidelines to align with relevant compliance frameworks
and regulatory requirements.
- Conduct risk assessments and gap analyses
against ISO 27001 and NIST CSF controls to identify areas for
improvement and ensure audit readiness.
- Prepare and compile documentation, evidence, and responses
for customer RFIs and audit requests efficiently and accurately.
- Contribute in identification, assessment, and mitigation of
information security risks in accordance with established risk management
frameworks.
- Maintain comprehensive documentation of security
controls, compliance activities, and remediation plans.
- Prepare regular reports on compliance status,
key metrics, and areas of concern for management and stakeholders.
- Perform comprehensive third-party risk
assessments to evaluate vendor compliance with information security
policies.
- Ensure effective communication and documentation
of third-party risk assessments.
Skills Required
- Knowledge of ISO 27001 information security compliance requirements
- Knowledge of SOC 1 and SOC 2 compliance frameworks
- Knowledge of NIST Cybersecurity Framework controls
- Experience conducting information security risk assessments and gap analyses
- Experience performing third-party information security risk assessments
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
NopalCyber provides integrated offensive and defensive cybersecurity solutions for organizations seeking resilience and compliance. Its offerings include managed extended detection and response, attack surface management, breach and attack simulation, advisory services, and 24/7 security operations. AI-driven products such as Nopal360°, NopalGo, and Cyber Intelligence Quotient help clients quantify, visualize, and reduce cyber risk across their IT environments while tailored service packages broaden access to enterprise-grade protection.








