Information Security Analyst

2 weeks ago
Freelance
Mid Level
Cybersecurity
Didomi

Didomi

Didomi offers innovative solutions for organizations to collect, respect, and leverage user choices in compliance with data privacy regulations, driving higher customer engagement and increasing consumer trust.

IT Services
51-250
Founded 2017
$46M raised

Description

  • Maintain and improve the ISO 27001 management system so controls remain effective, documented, and continuously evidenced.
  • Support internal audits, surveillance audits, and recertification cycles, including the unified audit covering Didomi and acquired business units.
  • Track corrective actions, nonconformities, and continuous improvement initiatives through to closure.
  • Run recurring security calendar activities, including vulnerability scanning campaigns, quarterly access reviews, risk assessments, business continuity tests, and policy review cycles.
  • Triage vulnerability findings from AWS GuardDuty, Inspector, and other sources and help define remediation priorities.
  • Perform periodic access reviews across critical systems such as Google Workspace, AWS, Slack, JAMF, GitLab, GitHub, and internal applications.
  • Review new tools, vendors, and SaaS applications for security and compliance risks before adoption.
  • Help assess and harden internal workflows with a focus on identity and access management, MFA, SSO, and data handling.
  • Support security questionnaires, RFPs, and customer due diligence requests.
  • Support broader initiatives such as AI governance, SaaS governance, and integrating acquired entities into the ISO scope.

Requirements

  • 3+ years of experience in a GRC, compliance, or information security analyst role, ideally in a SaaS or technology company.
  • Solid working knowledge of ISO 27001, including Annex A controls and the audit process.
  • Hands-on experience with vulnerability management tools and access governance processes.
  • Hands-on experience with Vanta, including running ISO 27001 or comparable audits end-to-end on the platform.
  • Hands-on experience with AWS security tools, especially GuardDuty and Inspector, including triaging findings and proposing remediation priorities.
  • Demonstrated use of AI tooling to accelerate recurring compliance and documentation work, with concrete examples of what you have built or automated.
  • Strong bias toward removing unnecessary process and proposing lighter alternatives.
  • Strong written communication in English, with the ability to explain security topics clearly to engineers, executives, and customers.
  • Pragmatic mindset focused on controls that work in practice rather than only on paper.
  • Experience supporting HIPAA or HITRUST programs and mapping requirements across frameworks, preferred.
  • Familiarity with cloud environments, especially AWS, and common SaaS administration tools such as Google Workspace, Slack, and identity providers, preferred.
  • Exposure to security questionnaire platforms and trust center tooling, preferred.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Fractional Cyber Security Analyst (Advisor Network)

Arootah 11-50 Professional Services

Arootah is seeking an experienced Cybersecurity Analyst to join its advisor network and support hedge fund and family office clients on project-based cybersecurity engagements.

Active Directory Azure Cybersecurity Encryption Network Security Penetration Testing SQL Windows Server
2 days, 14 hours ago

OSINT Investigator and Trainer - Contractor - Arabic speaker - Sudan

Centre for Information Resilience 11-50 Diversified Consumer Services

CIR is hiring a remote contractor for its Sudan Witness project to investigate, document, and support responses to human rights abuses and conflict-related harm in Sudan through open-source research and training work.

3 days, 13 hours ago

Surveillance Officer

Prevail Partners 11-50 Professional Services

Prevail Partners is seeking experienced Surveillance Officers to support an Ultra High Net Worth client through discreet protective surveillance operations within a specialist security programme.

1 week, 2 days ago

Rogue Risk Analysis Group (RRAG) - Team Leader

Apogee Global RMS Professional Services

Apogee Global RMS is hiring a Team Leader for its Rogue Risk Analysis Group to lead research, publishing, and team development for executive-focused risk intelligence and advisory products.

1 week, 5 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers