Information Security Analyst

1 month, 2 weeks ago
Freelance
Mid Level
Cybersecurity
Didomi

Didomi

Didomi offers innovative solutions for organizations to collect, respect, and leverage user choices in compliance with data privacy regulations, driving higher customer engagement and increasing consumer trust.

IT Services
51-250
Founded 2017
$46M raised

Description

  • Maintain and improve the ISO 27001 management system so controls remain effective, documented, and continuously evidenced.
  • Support internal audits, surveillance audits, and recertification cycles, including the unified audit covering Didomi and acquired business units.
  • Track corrective actions, nonconformities, and continuous improvement initiatives through to closure.
  • Run recurring security calendar activities, including vulnerability scanning campaigns, quarterly access reviews, risk assessments, business continuity tests, and policy review cycles.
  • Triage vulnerability findings from AWS GuardDuty, Inspector, and other sources and help define remediation priorities.
  • Perform periodic access reviews across critical systems such as Google Workspace, AWS, Slack, JAMF, GitLab, GitHub, and internal applications.
  • Review new tools, vendors, and SaaS applications for security and compliance risks before adoption.
  • Help assess and harden internal workflows with a focus on identity and access management, MFA, SSO, and data handling.
  • Support security questionnaires, RFPs, and customer due diligence requests.
  • Support broader initiatives such as AI governance, SaaS governance, and integrating acquired entities into the ISO scope.

Requirements

  • 3+ years of experience in a GRC, compliance, or information security analyst role, ideally in a SaaS or technology company.
  • Solid working knowledge of ISO 27001, including Annex A controls and the audit process.
  • Hands-on experience with vulnerability management tools and access governance processes.
  • Hands-on experience with Vanta, including running ISO 27001 or comparable audits end-to-end on the platform.
  • Hands-on experience with AWS security tools, especially GuardDuty and Inspector, including triaging findings and proposing remediation priorities.
  • Demonstrated use of AI tooling to accelerate recurring compliance and documentation work, with concrete examples of what you have built or automated.
  • Strong bias toward removing unnecessary process and proposing lighter alternatives.
  • Strong written communication in English, with the ability to explain security topics clearly to engineers, executives, and customers.
  • Pragmatic mindset focused on controls that work in practice rather than only on paper.
  • Experience supporting HIPAA or HITRUST programs and mapping requirements across frameworks, preferred.
  • Familiarity with cloud environments, especially AWS, and common SaaS administration tools such as Google Workspace, Slack, and identity providers, preferred.
  • Exposure to security questionnaire platforms and trust center tooling, preferred.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Threat Researcher

GreyNoise 51-250 Internet Software & Services

GreyNoise Intelligence is hiring a Threat Researcher to investigate emerging cyber threats and produce actionable intelligence that helps security practitioners detect, disrupt, and impose costs on adversaries.

Embedded Systems SQL
1 day, 15 hours ago

Associate Principal Cyber Threat Intelligence Analyst

Dragos 251-1K Professional Services

Dragos is hiring an OT Cyber Threat Intelligence Analyst to support a Singapore government security team with threat hunting, intelligence analysis, and incident response for critical infrastructure environments.

LLM SIEM
2 days, 16 hours ago

Security Operations Analyst II

Alphasense 51-250 Industrial Conglomerates

AlphaSense is hiring a Security Operations Analyst II to join its fully remote Security Operations team in Canada and help triage alerts, investigate incidents, and improve detection coverage.

AWS DNS GCP SIEM TCP/IP TLS
3 days, 16 hours ago

CyberSecurity Specialist

Avertium 251-1K IT Services

Avertium is hiring a Cyber Security Specialist to support 24x7 SOC monitoring and incident response for mid-market and enterprise clients.

Cybersecurity DNS Encryption HIPAA HTTP SIEM TCP/IP
3 days, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers