SOC分析师
SOC Analyst
这是一个远程职位。
SyncEzy 是一家在 B2B SAAS 领域快速增长的集成公司,专注于建筑、施工和服务业。我们是一家独立且自筹资金的公司,不接受风险投资。这是一份真正的远程/居家办公职位。我们的员工分布在 4 个国家和 15 个城市。我们以扁平化的组织结构和友好、轻松的文化为荣。
我们正在寻找一位动手能力强的信息安全与合规分析师(GRC),负责日常维护我们的安全和合规状态。该职位将支持并协调 SOC 2、ISO 27001 和 Cyber Essentials 的合规工作,并与工程、DevOps、IT 和管理层紧密合作,确保控制措施有效运行,并在全年保持审计就绪状态。
这是一个以执行为导向的职位。成功的候选人应能自如地在政策工作、证据收集、终端/软件合规、风险跟踪、访问审查和审计协调之间切换。高级工程经理将继续作为管理和升级的负责人,而分析师将成为常规合规操作和后续工作的主要负责人。
主要职责
·全年保持 SOC 2、ISO 27001 和 Cyber Essentials 的准备状态,而不是将其视为一年一度的审计任务。
·负责常规的合规管理、证据收集、控制监控和后续工作,使工程领导能够专注于产品交付和技术管理。
·将合规要求转化为工程、DevOps 和 IT 团队可操作的实践,同时避免不必要的运营负担。
·尽早识别差距,跟踪整改直至关闭,并保持清晰的文档,证明控制措施设计合理且有效运行。
要求
必备资格与技能
·2-4 年 GRC、信息安全合规、安全保证、IT 审计或相关领域的实际经验。
·至少接触过一个主要的安全/合规框架,如 SOC 2 或 ISO 27001;熟悉 Cyber Essentials 是强烈优先考虑的。
·有收集、审查和整理审计证据的经验,并与技术控制负责人合作。
·具备良好的文档编写和政策撰写能力,注重一致性和可审计性。
·了解云环境、身份和访问管理、终端设备
查看英文原文
This is a remote position.
SyncEzy is a growing Integration Company in the B2B SAAS space, with a strong focus on the Construction, Trades, and Service Industries. We are fiercely independent & bootstrapped, NOT VC Funded. This is A TRUE Remote /work-from-home position. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly, easy-going culture.
We are looking for a hands-on Information Security & Compliance Analyst (GRC)to take ownership of the day-to-day activities required to maintain our security and compliance posture. The role will support and coordinate compliance activities across SOC 2, ISO 27001 and Cyber Essentials, and will work closely with Engineering, DevOps, IT and management to keep controls operating effectively and evidence audit-ready throughout the year.
This is an execution-focused role.The successful candidate should be comfortable moving between policy work, evidence collection, endpoint/software compliance, risk tracking, access reviews and audit coordination. The Senior Engineering Manager will remain the management and escalation point, while the analyst becomes the primary owner of routine compliance operations and follow-up.
Primary Objectives
·Maintain year-round readiness for SOC 2, ISO 27001 and Cyber Essentials rather than treating compliance as a once-a-year audit exercise.
·Own routine compliance administration, evidence collection, control monitoring and follow-up so engineering leadership can remain focused on product delivery and technical management.
·Translate compliance requirements into practical actions for Engineering, DevOps and IT teams without creating unnecessary operational overhead.
·Identify gaps early, track remediation to closure and maintain clear documentation showing that controls are designed and operating effectively.
Requirements
Required Qualifications & Skills
·2–4 years of relevant experience in GRC, information security compliance, security assurance, IT audit or a closely related role.
·Practical exposure to at least one major security/compliance framework such as SOC 2 or ISO 27001; familiarity with Cyber Essentials is strongly preferred.
·Experience collecting, reviewing and organizing audit evidence and working with technical control owners.
·Strong documentation and policy-writing skills with attention to consistency and audibility.
·Working understanding of cloud environments, identity and access management, endpoint security, vulnerability management, logging, backups and change management.
·Ability to read technical evidence and ask the right questions without needing to be a software engineer or DevOps engineer.
·Strong ownership, follow-up and organizational skills; comfortable tracking multiple recurring compliance activities simultaneously.
·Clear written and verbal communication skills and the ability to work with both technical and non-technical stakeholders.
Preferred / Good-to-Have·Experience with compliance automation or GRC platforms such as Vanta, Drata, Sprinto or equivalent tools.
·Experience working in a SaaS, software-development or cloud-first organization.
·Familiarity with MDM / endpoint-management tooling and software inventory reviews.
·Exposure to AWS, Azure or other public-cloud security controls.
·Experience supporting customer security questionnaires or vendor-risk assessments.
·Relevant certifications such as ISO 27001 Internal Auditor / Lead Implementer, Security+, CISA, CRISC or similar are useful but not mandatory.
Benefits
Benefits · A TRUE Remote / Work from Home position. We are a Global Remote company, and have been remote working long before it was made popular by COVID. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly and going culture.
Competitive Salary + All the belowSalary range:7-9 lacs
Allowance for Internet / Phone costs
Company Hardware provided after completing probation.
Continuous development and education allowances.
Flexible Remote work from anywhere (As long as you have good internet and communication)
Excellent growth opportunities, growth into leadership for the right candidate
Generous policies around leave / social and training allowances
End of year Bonuses based on company + Individual performance.
Zero Commute, Work while you work, play while you play. Perfect Work / Life balance.
Remote job opportunities and other benefits to be discussed during the interviewFlexible, family friendly & fun work environment
Originally posted on Himalayas