安全合规顾问(SOC 2、PCI DSS、HIPAA、NYDFS 500),合同制
Security Compliance Consultant (SOC 2, PCI DSS, HIPAA, NYDFS 500), Contract
Invadel 是一家位于纽约市的渗透测试公司。每次服务都是固定范围和固定价格,以书面形式确认,公开价格见 invadel.com/pricing,并提供免费重新测试。这是一个合同职位,远程工作,仅限美国境内,按项目支付;通常每个客户项目的工作量为一至三天,附属于渗透测试,还有偶尔的准备性审查。
你将负责:编写每份报告中的框架映射部分以及客户交给审计师和客户的证明信;在测试开始前,根据驱动测试的要求(例如 PCI DSS 11.4 分段测试或 NYDFS 500.5)审查客户范围并标记差距;回答审计师和客户的安全问卷跟进问题;为客户进行首次 SOC 2 Type II 或 PCI DSS 评估做准备时开展准备性审查;保持合规映射模板的更新。
我们需要:至少四年安全合规、审计或 GRC 经验,有 SOC 2 直接经验,并至少掌握 PCI DSS、HIPAA、ISO 27001、NYDFS 500 或 CMMC 中的一项;具备足够的技术基础,能够阅读渗透测试结果并解释其对控制的影响;能为审计师、高管和工程师撰写清晰的文档;位于美国并拥有在此工作的授权;提供两个专业推荐人。
加分项:有评估师方面经验(QSA、SOC 2 审计团队、C3PAO)或在合规自动化平台工作过;有纽约金融服务业或医疗客户经验。
完整描述、薪资范围和申请方式:
最初发布于 Himalayas
查看英文原文
Invadel is a New York City penetration testing firm. Every engagement is fixed-scope and fixed-price, agreed in writing, with public prices at invadel.com/pricing and a free retest. This is a contract role, remote within the United States, paid per engagement; work is typically one to three days per client engagement, attached to a penetration test, plus occasional readiness reviews.
What you will do: produce the framework mapping section of each report and the attestation letter clients hand to auditors and customers; review client scope against the requirement that drives the test (for example PCI DSS 11.4 segmentation testing or NYDFS 500.5) and flag gaps before testing starts; answer auditor and customer security questionnaire follow-ups with the client; run readiness reviews for clients preparing for a first SOC 2 Type II or PCI DSS assessment; keep the compliance mapping templates current.
What we need: four or more years in security compliance, audit or GRC with direct experience of SOC 2 and at least one of PCI DSS, HIPAA, ISO 27001, NYDFS 500 or CMMC; enough technical grounding to read a penetration test finding and explain what it means for a control; clear writing for auditors, executives and engineers; based in the United States with authorization to work here; two professional references.
Nice to have: time on the assessor side (QSA, SOC 2 audit team, C3PAO) or inside a compliance automation platform; experience with New York financial services or healthcare clients.
Full description, pay range and application:
Originally posted on Himalayas