The Security & Compliance Associate is responsible for supporting governance, risk, and compliance (GRC) operations while ensuring adherence to security frameworks such as SOC 2, PCI DSS, GDPR, and other applicable standards. The role focuses on compliance monitoring, audit coordination, identity and access management, vulnerability management, penetration testing, vendor risk management, security awareness, and customer security support. Working closely with cross-functional teams, auditors, and third-party vendors, the associate ensures timely completion of compliance activities, maintains security documentation and evidence, drives remediation efforts, and contributes to strengthening the organization's overall security posture through process improvements and automation.
Governance, Risk & Compliance (GRC), Security Compliance, SOC 2, PCI DSS, GDPR, ISO 27001, HIPAA, Vanta, Audit Coordination, Compliance Monitoring, Compliance Evidence Management, Control Assessments, Internal Audits, Policy Management, SOP Management, Regulatory Compliance, Penetration Testing Coordination, Vulnerability Management, Security Operations, Incident Response, Business Continuity Planning (BCP), Disaster Recovery (DR), Identity & Access Management (IAM), User Access Reviews, Multi-Factor Authentication (MFA), Single Sign-On (SSO), Okta, Azure AD, Jamf, Microsoft Intune, Privileged Access Management (PAM), Vendor Risk Management, Third-Party Risk Management, Subprocessor Management, Patch Management, SAST, DAST, OSS License Compliance, Endpoint Security, Mobile Device Management (MDM), Endpoint Detection & Response (EDR), Email Security, Phishing Analysis, KnowBe4, Security Awareness Training, Risk Register Management, Customer Security Questionnaires, Trust Center Management, Security Metrics, KPI Reporting, Jira, Linear, Spreadsheet Management, Workflow Automation, Zapier, n8n, Microsoft Power Automate, AI Tools, ChatGPT, Claude, Communication, Documentation, Stakeholder Management, Problem Solving, Process Improvement.