Information Security Analyst

1 month ago
Freelance
Mid Level
Cybersecurity
Didomi

Didomi

Didomi offers innovative solutions for organizations to collect, respect, and leverage user choices in compliance with data privacy regulations, driving higher customer engagement and increasing consumer trust.

IT Services
51-250
Founded 2017
$46M raised

Description

  • Maintain and improve the ISO 27001 management system so controls remain effective, documented, and continuously evidenced.
  • Support internal audits, surveillance audits, and recertification cycles, including the unified audit covering Didomi and acquired business units.
  • Track corrective actions, nonconformities, and continuous improvement initiatives through to closure.
  • Run recurring security calendar activities, including vulnerability scanning campaigns, quarterly access reviews, risk assessments, business continuity tests, and policy review cycles.
  • Triage vulnerability findings from AWS GuardDuty, Inspector, and other sources and help define remediation priorities.
  • Perform periodic access reviews across critical systems such as Google Workspace, AWS, Slack, JAMF, GitLab, GitHub, and internal applications.
  • Review new tools, vendors, and SaaS applications for security and compliance risks before adoption.
  • Help assess and harden internal workflows with a focus on identity and access management, MFA, SSO, and data handling.
  • Support security questionnaires, RFPs, and customer due diligence requests.
  • Support broader initiatives such as AI governance, SaaS governance, and integrating acquired entities into the ISO scope.

Requirements

  • 3+ years of experience in a GRC, compliance, or information security analyst role, ideally in a SaaS or technology company.
  • Solid working knowledge of ISO 27001, including Annex A controls and the audit process.
  • Hands-on experience with vulnerability management tools and access governance processes.
  • Hands-on experience with Vanta, including running ISO 27001 or comparable audits end-to-end on the platform.
  • Hands-on experience with AWS security tools, especially GuardDuty and Inspector, including triaging findings and proposing remediation priorities.
  • Demonstrated use of AI tooling to accelerate recurring compliance and documentation work, with concrete examples of what you have built or automated.
  • Strong bias toward removing unnecessary process and proposing lighter alternatives.
  • Strong written communication in English, with the ability to explain security topics clearly to engineers, executives, and customers.
  • Pragmatic mindset focused on controls that work in practice rather than only on paper.
  • Experience supporting HIPAA or HITRUST programs and mapping requirements across frameworks, preferred.
  • Familiarity with cloud environments, especially AWS, and common SaaS administration tools such as Google Workspace, Slack, and identity providers, preferred.
  • Exposure to security questionnaire platforms and trust center tooling, preferred.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Vulnerability Management Analyst

Skyepoint Decisions 51-250 Internet Software & Services

SkyePoint Decisions is hiring a fully remote Vulnerability Management Analyst to support a federal cybersecurity program by tracking, prioritizing, and reporting security vulnerabilities across enterprise systems and infrastructure.

Cybersecurity
1 week, 1 day ago

Threat Detection & Response Analyst

Skyepoint Decisions 51-250 Internet Software & Services

SkyePoint Decisions is hiring a fully remote Threat Detection & Response Analyst to monitor, investigate, and respond to cybersecurity threats supporting federal clients and mission-critical systems.

AWS Azure Cybersecurity GCP Network Security
1 week, 1 day ago

Incident Response Analyst

Skyepoint Decisions 51-250 Internet Software & Services

SkyePoint Decisions is hiring a fully remote Incident Response Analyst to support federal cybersecurity operations by monitoring, investigating, and responding to security incidents across enterprise, cloud, network, and endpoint environments.

Cybersecurity Linux Palo Alto SIEM Splunk
1 week, 1 day ago

OSINT Trainer and Investigator - Contractor - Burmese speaker - Myanmar

Centre for Information Resilience 11-50 Diversified Consumer Services

Centre for Information Resilience is hiring a remote contractor to support Myanmar Witness’s capacity-building, open-source investigations, and engagement with civil society partners on conflict-related human rights documentation in Myanmar.

1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers