Senior Compliance Analyst
Posted on 1/27/2023
INACTIVE
Locations
Remote • United States
Experience Level
Entry
Junior
Mid
Senior
Expert
Desired Skills
Management
Communications
Requirements
- Ability to work a west coast schedule
- Extensive knowledge of at least 2 or more of the following compliance frameworks (NIST 800-53, PCI, SOC, ISO 27000 Series)
- Experience with baseline security subsets of control activities to help meet external audit certifications
- 2-3 years experience in security controls or related area
- Big 4 Experience or Management Consulting Experience preferred
- Japanese proficiency preferred
- BA or BS Degree
- Experience with cloud computing and the acronyms that come with it - SaaS, IaaS and PaaS
- QSA, CISA, CIA, CISSP or other related certifications a plus
- Excellent written, verbal communication and presentation skills
- Willingness to wear different hats and work on areas where needed
- Amazing organizational skills with a drive to succeed in a fast-paced environment
- Ability to get stuff done, and has strong integrity - make mom proud!
Responsibilities
- Drive and support Compliance programs such as ISMAP, ISO 27001, 27017 and 27018, SOC 1,2 and 3, PCI
- Assess, report and mature the compliance posture for Box's internal policies and guidelines as well as regulatory requirements based on frameworks including NIST 800-53, PCI DSS, ISO 27000 Series, HIPAA, SOC for Service Organizations, SOX
- Responsible for continuous monitoring, remediation, and reporting of controls to management and coordinate cross functional team meetings to remediate and close the control gaps
- Work with cross functional teams like on things like vulnerability management in support of audits
- Communicate gaps to management and coordinate cross functional team meetings to remediate and close the control gaps
- Drive improvements in existing processes and develop new innovative and efficient solutions
- Maintain evidence documentation across internal stakeholders for a repeatable process
- Collaborate with internal and external stakeholders to understand risks to critical infrastructure by defining potential business impacts
- Support both regulatory and customer audits
- Build relationships with internal and external stakeholders
Cloud content management and file sharing service
Company Overview
Box is on a mission to make businesses more productive, competitive, and powerful by connecting people and their most important information. The company operates one of the world's largest cloud storage platforms.
Benefits
- Health and Wellness
- Family Support
- Generous Time Off
- Financial Benefits
- Community
- Evolving Workplace
Company Core Values
- Blow our customers' minds
- Take risks. Fail fast. GSD
- 10x it!
- Be an owner. It's your company
- Bring you (___) self to work every day
- Be candid and assume good intent
- Make mom proud