Full-Time

Information Security Risk and Compliance

Multiple Teams

Posted on 8/14/2025

PurpleBox

PurpleBox

Cloud security consulting and managed services

No salary listed

Atlanta, GA, USA

Remote

Category
IT & Security (1)
Requirements
  • Bachelor’s degree in Computer Science, Information Technology, Business Administration, or related field
  • Experience in information security risk assessment, compliance and/or security operations
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences
  • Strong analytical skills to analyze security requirements and relate them to appropriate security controls
  • Working knowledge of relevant security regulations, standards and frameworks, including SOC2, ISO27000, PCI, HIPAA, and NIST CSF
Responsibilities
  • Manage and execute the day-to-day information security risk and compliance operational activities
  • Develop and recommend appropriate information security policies, standards, procedures, checklists, and guidelines using generally recognized security concepts tailored to meet the requirements of the organization
  • Identify and document specific security issues, propose resolution options, and interpret matters from the perspective of involved stakeholders
  • Communicate regularly with teams and staff as part of risk assessments, follow-up on open issues, status tracking, and other miscellaneous items
  • Independently design, recommend, plan, develop, and support implementation of project-specific security solutions to meet requirements
  • Manage remediation of identified risks and vulnerabilities; identify those within the organization responsible for remediation tasks; track progress on remediation of identified risks and vulnerabilities and provide appropriate reporting to all constituents
  • Provides regular reporting metrics on the current state of the program
  • Other duties as assigned
Desired Qualifications
  • Previous experience in one or more of the areas below is a plus: IT Security Strategy and Management, Risk Management, IT Audit, and Compliance, Network, System, Database administration, support and/or help-desk experience, Application Security, Software Development, Security Monitoring, Data Loss Prevention, Incident Response
  • Professional certifications such as CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor) or other similar credential is a plus

PurpleBox provides secure cloud solutions and managed services, including security assessments, compliance work, vulnerability testing, policy design, threat monitoring, application security, and managed web application firewall, plus AWS-based cloud transformation and migration services. It works by performing risk and vulnerability assessments, then designing and implementing security controls and monitoring, and guiding clients from strategy through migration to secure cloud architectures with ongoing management. The company differentiates itself with an end-to-end offering that combines security consulting with cloud transformation, backed by an AWS partnership and a broad focus from SCADA to web applications. Its goal is to help clients securely move to the cloud, meet regulatory requirements, reduce risk, and optimize cloud costs while ensuring operational resilience.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

Simplify Jobs

Simplify's Take

What believers are saying

  • MDR market grows from $6.28B in 2026 to $19.01B by 2031 at 24.8% CAGR.
  • Cloud security demand surges with 25.2% CAGR in MDR cloud deployments.
  • $50M Atlanta venture fund announced March 2026 boosts regional cybersecurity.

What critics are saying

  • CrowdStrike's 25% market share undercuts PurpleBox via AI threat detection.
  • Palo Alto Prisma Cloud's 40% dominance erodes PurpleBox AWS/Azure services.
  • CISA SECURE 2.0 mandate Q2 2026 bars PurpleBox from federal contracts.

What makes PurpleBox unique

  • PurpleBox specializes in PCI ASV vulnerability scanning for compliance.
  • PurpleBox integrates DevSecOps into CI/CD pipelines for enterprises.
  • PurpleBox targets Atlanta SMBs with tailored MDR services.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

401(k) Retirement Plan

Remote Work Options

INACTIVE