Information Security Client Compliance Analyst
ISS STOXX · Norman, OK · 5 days ago
HybridFull-time
About the role
We are seeking a Client Compliance Analyst to join our Information Security Governance, Risk, and Compliance (GRC) function. This role involves coordinating information security due diligence activities with a focus on clear and professional communication with clients and internal teams.
Responsibilities
- Act as the primary point of contact for client information security due diligence requests
- Communicate clearly and professionally with clients, vendors, and internal stakeholders
- Explain information security concepts and processes in plain, non-technical language
- Track requests and provide regular updates to ensure expectations are managed effectively
Requirements
- Excellent written and verbal communication skills
- Strong customer service mindset, with a professional and helpful approach
- Highly organized, with good attention to detail
- Able to manage multiple requests and deadlines simultaneously
- Comfortable working with a variety of stakeholders at different levels
- 2-5 years of prior experience, preferably in an information security or client facing role
- Bachelor's degree preferred, equivalent experience and/or certifications also considered
Preferred
- Basic understanding of information security, risk, compliance, or GRC concepts
- Experience responding to client questionnaires or third-party assessments
- Familiarity with standards such as ISO 27001, SOC 2, or supplier due diligence processes
Learning & Development
Full support will be provided to build knowledge in information security and GRC. Ideal for someone early in their infosec or risk career, or transitioning into the field. A positive attitude and willingness to learn are more important than deep technical expertise.
Who This Role Suits
This role is well suited to someone who:
- Enjoys working in a client-facing or service-oriented role
- Is confident communicating complex topics in a clear, friendly way
- Wants to develop a career in information security without needing a technical background