Specialist, Information Security and Privacy
Mindtickle
Full Time3+ yearsPosted 3 days ago
Let the right jobs find you
Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.
Overview
Position Type
Full Time
Experience
3+ years
Job Description
Key Responsibilities
- Serve as the main point of contact for sales and customer teams regarding security, privacy, and compliance topics, communicating with customers and prospects through RFPs, emails, or calls.
- Review customer/prospect questionnaires and security addendums, providing and building necessary information, collaterals, and resources.
- Maintain information security reports, RFP knowledgebase, and security assets for the security due diligence process utilizing existing RFP management tools.
- Work flexibly across all teams in the organization, driving security RFP and third-party risk management projects, including sales, customer success, product, and engineering.
- Own the third-party risk management process, including planning, scoping, needs analysis, ongoing project management, and communication with stakeholders.
- Conduct security due diligence on new third parties and perform periodic risk reviews of existing third parties.
- Own and manage controls across SOC 2 Type II, ISO standards, 21 CFR Part 11, and HIPAA frameworks, maintaining an up-to-date control landscape and evidence inventory.
- Coordinate and support external audits end-to-end - from audit scoping and evidence preparation to auditor walkthroughs and post-audit remediation tracking.
- Manage compliance tracking across Google Workspace (Sheets, Drive, Docs, Gmail) - maintaining structured control registers, evidence repositories, and policy documentation.
- Send and track corrective action communications to control owners, following up through resolution and maintaining a clear audit trail.
- Conduct periodic internal compliance reviews and produce structured reports for leadership.
- Collaborate closely with privacy, internal governance, audit, Engineering, DevOps, Legal, and HR teams to gather necessary information related to compliance and ensure controls are implemented.
- Work with engineering, business applications, legal, and other teams as required to fulfill customer, prospect, or third-party compliance requirements.
- Maintain and periodically review information security policies, procedures, and standards in Google Docs, ensuring they remain current and aligned with framework controls.
- Coordinate access reviews, vendor security assessments, and third-party risk evaluations as part of the ongoing compliance calendar.
- Undertake any other reasonable and related tasks associated with the role.
Requirements
Experience and Background
- 3-5 years of experience in information security and compliance, with exposure to cloud software platforms (AWS/GCP).
- Extensive experience in handling customer security queries, including RFPs, questionnaires, security architecture reviews, and data protection evaluations.
- Experience in managing third-party risk evaluation and management processes.
- Strong understanding of cloud governance and technology security controls covered in SOC 2, ISO Standards, NIST, GDPR, HIPAA, CSA STAR, CIS, etc.
Tooling and Workflow
- Proficient in Google Workspace - comfortable using Sheets for control tracking, Drive and Docs for policy and evidence management, Gmail for formal communications, and Calendar for scheduling.
- Utilize existing RFP management tools to maintain the knowledge base in line with changing customer needs, global standards, product releases, and updates.
- Experience using Jira for cross-functional issue tracking and Slack for team collaboration.
Soft Skills and Working Style
- Excellent communication, interpersonal, project management, and issue-resolution skills.
- Strong written communication skills - able to draft clear policy documents, corrective action notices, and executive summaries.
- Strong analytical and organizational skills, with the ability to work effectively as part of a team.
- Proactive, pragmatic, and self-driven - able to learn quickly, take initiative, identify gaps, propose solutions, and drive complex projects in a fast-paced SaaS environment.
Good to have:
- Certifications: CISSP, CISM, CISA, CRISC, CCSP, ISO 27001, ISO 42001, ISO 22301, CompTIA Security+, etc.
- Understanding of data privacy principles under GDPR and HIPAA, including data classification, retention policies, and subject rights processes.