Information Assurance and Compliance Analyst
Keeper Security, Inc. · Chicago, IL · 1 wk ago
RemoteRemoteLegalFull-time
About the role
This is a 100% remote position from select locations, with an opportunity to work a hybrid schedule for candidates based in the Chicago, IL metro area.
Responsibilities
- Develop and implement comprehensive cybersecurity policies, ensuring alignment with frameworks such as NIST CSF, and government standards like IL5 and FedRAMP HIGH
- Manage and maintain compliance with government security standards and ensure policies address both technical and non-technical security needs
- Define data classification and protection requirements for IT systems to safeguard sensitive information
- Collaborate with cross-functional teams to ensure cybersecurity policies are effectively integrated into business operations
- Education employees on privacy protections and security restrictions, delivering training and communication to increase awareness
- Regularly review and update cybersecurity policies to maintain compliance with evolving regulations and industry best practices
- Support the Approval to Operate (ATO) process by ensuring all systems meet required security standards
- Troubleshoot security policy implementation issues and provide solutions to enhance protection
Requirements
- 4+ years of experience in developing, implementing, and managing cybersecurity policies
- Comprehensive understanding of cybersecurity frameworks, with proficiency in NIST Cybersecurity Framework (CSF), practical application of framework principles in enterprise environments, and the ability to translate theoretical framework guidelines into actionable security strategies
- Experience in achieving and maintaining high-level security compliance, including government security standards like DoD Impact Level 5(IL5), FedRAMP HIGH authorization requirements, SOC2, and ISO
- Expertise in developing and implementing data classification policies and defining data protection requirements for IT systems
- Strong knowledge of AWS Cloud Platform
- Prominent capability to prepare and support comprehensive security documentation for compliance audits
- Excellent communication and training skills to effectively educate employees on privacy protections and restrictions
- Ability to review existing policies and drive practical implementation to ensure effective protection
- Familiarity with the Approval to Operate (ATO) process and its role in ensuring the security of IT systems
- Relevant certifications, such as CISSP, CISM, or CIPP/US, are highly desirable
- Ability to pass an enhanced security background check, including a financial vulnerability assessment
Benefits
- Medical, Dental & Vision (inclusive of domestic partnerships)
- Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life
- Voluntary Short/Long Term Disability Insurance
- 401K (Roth/Traditional)
- A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc)
- Above market annual bonuses
Classification
Exempt
Keeper Candidate Privacy Notice
[Content of the Keeper Candidate Privacy Notice]