Senior Compliance Engineer POST NUMBER: 407394
Summary:
Vaco Staffing is conducting a search on behalf of a SaaS software organization in need of a Sr. Compliance Engineer with a background in policy-writing, procedural documentation, and audit program management skills.
Project Details:
- This is a 3–4-month contract position very likely to extend and does have a chance to convert but not a guarantee. The pay rate is 65/hr. w2 with some flexibility (within reason for the right candidate)
- The position is 100% remote.
- Must be willing to work on Vaco w2 directly, no c2c, third party inquiries or 1099 candidates.
- Unable to sponsor now, unable to sponsor in future.
- Background Checks will be included in the process.
The role of a Sr. Compliance Engineer is to work with our Trust and Compliance team to:
- Drive security compliance efforts from the beginning to the end by maintaining a positive relationship with both internal and external stakeholders.
- Maintain compliance documentation, including audit evidence, controls, and vendor security reviews.
- Design, implement, maintain, and improve programs to address key company risks and prepare internal teams for independent assessments against a wide variety of regulatory and compliance frameworks (PCI, SOC, ISO 27XXX, HIPAA, GDPR, etc)
- Monitor the performance of the compliance program through the development of and maintenance of automated systems.
- Work with cross functional teams to identify risks and gaps in our compliance controls and facilitate remediation across our products and infrastructure.
- Assist with completing security questionnaires from customers and answering customer questions with respect to compliance; work with the internals team to create customer collateral to educate internal staff and aid in the sales process!
- Assist with requesting/reviewing security questionnaires/contracts from vendors and identify security risks and gaps in the compliance controls to aid in the procurement process!
- Develop automations of risk management, control execution and monitoring
WHAT YOU’LL NEED TO BE SUCCESSFUL
- 5 years of experience with a demonstrated track record of success in GRC, internal audit, security, and/or privacy space.
- Knowledge of various compliance frameworks (PCI, SOC2, ISO 27001, ISO 27018, HIPAA, GDPR, etc.)
- Strong experience with any scripting languages like Ruby, Python, Unix shell, bash, etc.
- Functional knowledge of multiple security domains and information security industry standards and best practices including public and private cloud
- Experience leading 3rd party risk management programs, including responding to customer security questionnaires, interacting directly with customer sales and security teams, and reviewing vendor security!
- Solid experience managing compliance initiatives for cloud platforms and interacting with external auditors.
- Strong project management skills
- Strong written and verbal communication skills
- A mix of experiences at a Big Four (or similar) audit or consulting firm and at an in-house governance, risk, and compliance function at a SaaS company
- Industry recognized certification in security ISO 27001 LA / LI or desire to pursue CISSP, CISA, CISM, CCSK, etc. in 6 months.
- Experience working in an international / global organization.
Vaco values a diverse workplace and strongly encourages women, people of color, LGBTQ+ individuals, people with disabilities, members of ethnic minorities, foreign-born residents, and veterans to apply.
EEO Notice
Vaco is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law.
Vaco LLC and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco LLC and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact HR@vaco.com .
Vaco also wants all applicants to know their rights that workplace discrimination is illegal.
By submitting to this position, you agree that you will be giving Vaco the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal.
Privacy Notice
Vaco LLC and its parents, affiliates, and subsidiaries (“we,” “our,” or “Vaco”) respects your privacy and are committed to providing transparent notice of our policies.
- California residents may access Vaco’s HR Notice at Collection for California Applicants and Employees here.
- Virginia residents may access our state specific policies here.
- Residents of all other states may access our policies here.
- Canadian residents may access our policies in English here and in French here.
- Residents of countries governed by GDPR may access our policies here.
Pay Transparency Notice
Determining compensation for this role (and others) at Vaco depends upon a wide array of factors including but not limited to:
- the individual’s skill sets, experience and training;
- licensure and certification requirements;
- office location and other geographic considerations;
- other business and organizational needs.
With that said, as required by local law, Vaco believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.