Senior Compliance Specialist, Governance, Risk and Compliance @ HashiCorp | Jobright.ai
JOBSarrow
RecommendedLiked
0
Applied
0
External
0
Senior Compliance Specialist, Governance, Risk and Compliance jobs in United States
200+ applicants
company-logo

HashiCorp · 9 hours ago

Senior Compliance Specialist, Governance, Risk and Compliance

ftfMaximize your interview chances
Cloud InfrastructureCyber Security
badNo H1Bnote

Insider Connection @HashiCorp

Discover valuable connections within the company who might provide insights and potential referrals.
Get 3x more responses when you reach out via email instead of LinkedIn.

Responsibilities

Help oversee and mentor existing compliance analyst(s)
Work with external auditors and controls owners on SOC 2 and ISO 27001/17/18 including:
Ensure contracting is in place with external auditor to conduct attestation/certifications on an annual basis
Confirm scope of SOC 2 and ISO audits
Prepare the ISO scope documentation and Statement of Applicability (SOA)
Develop project plan including key milestones and timelines, working with HashiCorp’s auditor
Identify and confirm control owners before the audit begins
Prepare control owners for external assessments
Prepare internal communications, including weekly status updates that outline the status of the program, potential risks and call to action items
Host walkthroughs and prepare and/or review walkthrough agendas
Perform the final review of evidence that is gathered by control owners before submitting to the auditors
Monitoring and tracking control exceptions, if applicable, and help teams create remediation plans for gaps/audit findings
Development of the system description, including working with relevant control owners for input
Prepare and facilitate regular management reviews as part of ISO 27001
Provide program oversight of the annual ISO Internal Audit
Maintain and document the scope/boundaries of the compliance program (cloud accounts, repositories, Github teams, etc.) including updates, removals and additions.
Identify and propose improvement to the Security Policy and participate in the annual Security Policy review
Support requests received for Security Policy exceptions, including following up on approved exceptions expiring.
Maintain documentation such as HashiCorp’s Common Control Framework (CCF), including developing new controls, completeness and accuracy of the information including framework mappings
Work with controls owners to identify opportunities for automating manual processes and controls
Develop, maintain and deliver on control owner enablement trainings
Provide input on program metrics and collect and report on metrics data
Support other GRC tasks as required

Qualification

Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.

Compliance program experienceSOC 2 knowledgeISO 27001 knowledgeAudit experienceCloud environment experienceMulti-cloud environment experienceSecurity compliance frameworksAWS experienceAzure experienceAutomation of processesOSCAL experienceTraining developmentResponsivenessTechnical communicationProject management

Required

Minimum of 8 years of related professional compliance and controls program experience
Previous experience in a cloud environment, preferably AWS and/or Azure
Advanced level knowledge either SOC 2 or ISO 27001
Experience leading internal and/or external audits, working as the liaison between auditors and the business
Comfortable working with both deeply technical and non-technical resources
Flexible in daily hours (e.g. willingness to work longer hours during end of quarter and peak periods, and audit)
Highly responsive
Ability to prioritize and track multiple projects and tasks in parallel

Preferred

Experience working in a large, multi-cloud environment
Deep understanding of common security compliance frameworks, attestations and certifications
Previous experience at a technology or SaaS company in a similar role
Experience working with OSCAL

Company

HashiCorp

company-logo
HashiCorp is a remote-first company that solves development, security, and operations challenges in infrastructure.

Funding

Current Stage
Public Company
Total Funding
$349.18M
Key Investors
Franklin TempletonIVPNotable Capital
2024-04-24Acquired· undefined
2022-07-29IPO· undefined
2021-03-01Secondary Market· undefined

Leadership Team

leader-logo
David McJannet
CEO
linkedin
leader-logo
Armon Dadgar
Co-Founder and CTO
linkedin
Company data provided by crunchbase
logo

Orion

Your AI Copilot