About the position
ENVIRONMENT:
LEAD and support Information Security Governance, Risk Management, Compliance & Security Assurance activities of a PE-based global Logistics Operation urgently seeking a Cybersecurity Assurance & Compliance Specialist. This role is responsible for maintaining and advancing Security Certification programs, including SOC 2 Type II, CMMC Level 2, and ISO/IEC 27001, while ensuring continuous audit readiness and compliance with applicable regulatory and customer requirements. You will serve as the primary point of contact for external auditors, certification bodies, customer security assessments, and internal stakeholders. The role will also oversee enterprise Cyber Risk Management activities, maintain the cybersecurity risk register, and coordinate remediation efforts across business and technology teams.
DUTIES:
Compliance & Certification Management -
- Lead and coordinate all activities associated with:
- SOC 2 Type II Compliance and Audits
- CMMC Level 2 Certification and Maintenance
- ISO/IEC 27001 Certification, Surveillance Audits, and Continuous Improvement
- Maintain audit readiness programs and compliance roadmaps.
- Coordinate internal and external assessments, audits, and certification engagements.
- Manage evidence collection and control validation activities.
- Track audit findings, corrective actions, and remediation plans through completion.
- Monitor regulatory, customer, and industry framework changes that may impact compliance obligations.
- Maintain framework mappings between SOC 2, CMMC, ISO 27001, NIST 800-171, CIS Controls, and other applicable standards.
Audit & Assurance Management -
- Serve as the primary liaison to auditors, assessors, and certification bodies.
- Develop and maintain audit evidence repositories and supporting documentation.
- Coordinate interviews, testing activities, walkthroughs, and auditor requests.
- Perform internal compliance reviews and readiness assessments.
- Establish and maintain policies, standards, procedures, and control documentation required for certification programs.
- Track compliance metrics and provide regular reporting to leadership.
Customer Security Assurance -
- Own customer Cybersecurity due diligence requests and security questionnaires.
- Coordinate responses to customer assessments, RFP security sections, and vendor security reviews.
- Maintain a knowledge base of approved security responses and supporting evidence.
- Partner with Sales, Legal, Privacy, Infrastructure, and Security teams to provide accurate and timely responses.
- Participate in customer security discussions and explain the organization's security and compliance posture.
- Support contract reviews involving Cybersecurity requirements and obligations.
Cyber Risk Management -
- Manage and maintain the enterprise Cybersecurity Risk Register.
- Facilitate periodic Cybersecurity risk assessments across business processes, systems, applications, cloud environments, and third-party vendors.
- Identify, assess, document, and prioritize Cybersecurity risks using established risk methodologies.
- Develop and maintain risk scoring frameworks and risk treatment processes.
- Coordinate with risk owners to establish mitigation strategies, compensating controls, and remediation plans.
- Track remediation activities and monitor residual risk levels.
- Support Enterprise Risk Management (ERM) initiatives by providing Cybersecurity risk input and reporting.
- Prepare cyber risk presentations, dashboards, and metrics for leadership and governance committees.
- Develop and maintain Key Risk Indicators (KRIs) and compliance metrics to measure program effectiveness.
- Ensure risks are appropriately mapped to applicable regulatory, contractual, and compliance requirements.
Governance & Security Program Support -
- Support the development and maintenance of Information Security policies, standards, and procedures.
- Coordinate annual policy reviews and control effectiveness assessments.
- Assist with third-party Risk Management and Vendor Security reviews.
- Support security awareness and compliance training initiatives.
- Promote continuous improvement of Governance, Compliance, and Risk Management practices.
- Contribute to security program maturity and strategic compliance initiatives.
REQUIREMENTS:
Qualifications –
- Bachelor's Degree in Information Security, Cybersecurity, Information Technology, Risk Management, Business Administration, or a related discipline is preferred. An equivalent combination of education, professional certification, and relevant experience may be considered.
Experience/Skills -
- Minimum 5 years of experience in Cybersecurity, Information Security, IT Audit, Risk Management, Governance, or Compliance.
- Minimum 3 years of direct experience supporting one or more of the following:
- SOC 2
- ISO/IEC 27001
- CMMC
- NIST 800-171
- Internal or external audits.
- Security certification programs.
- Experience managing compliance documentation, evidence collection, and audit coordination.
- Experience conducting risk assessments and maintaining risk registers.
- Experience responding to customer Cybersecurity questionnaires and security assessments.
- Proficient with Microsoft 365 productivity and collaboration tools, including Teams, Word, Excel, PowerPoint, and SharePoint.
- Comfortable with governance, risk, compliance, policy management, reporting, and documentation platforms.
- Able to read and interpret business cases, project plans, risk reports, policies, procedures, training materials, and audit documentation.
- Able to prepare clear written summaries.
ATTRIBUTES:
- Strong written and verbal communication skills.
- Demonstrated ability to influence stakeholders across multiple business functions and regions.
- Strong analytical, organizational, and problem-solving skills.
Desired Skills:
- Cybersecurity
- Assurance
- Compliance Specialist