Information Security Compliance Lead
Apex Systems · Atlanta, GA · 1 wk ago
Information TechnologyContract
Location: Atlanta, Georgia or Washington, D.C. (Partial Remote)
About the role
We are seeking a highly experienced Information Security Compliance Lead to support the organization globally. This role is responsible for driving key functions within the enterprise security compliance program, ensuring alignment with regulatory requirements and internal policy obligations. The position requires a seasoned practitioner with expertise in managing complex, multi-environment compliance programs.
Responsibilities
- Lead the global cybersecurity compliance program, including strategy, governance, and roadmap development.
- Direct enterprise compliance activities across frameworks such as PCI, SOX, GDPR, SWIFT, NIST CSF, and ISO 27001/27002.
- Oversee the design, implementation, and testing of cybersecurity controls across various environments.
- Direct the end-to-end audit and assessment lifecycle, from planning and scoping to testing and closure.
- Lead remediation of cybersecurity, audit, and compliance findings through root cause analysis and corrective action planning.
- Translate compliance insights into practical recommendations to inform team priorities and business decisions.
- Engage with technical and business teams to ensure accountability for control ownership and remediation of compliance deficiencies.
- Analyze and report globally on compliance and remediation trends, producing actionable reporting for continuous improvement.
Requirements
- 7+ years of experience in cybersecurity risk, compliance, or a related function.
- 5+ years working in regulatory assessments and requirements.
- Experience managing a team of 2+ personnel.
- Strong expertise across cloud (AWS, Azure, GCP), on-premises, and application environments.
- Bachelor’s degree in computer science, business administration, Engineering, IT, or a related technical field.
- Certifications such as CISA, CISSP, CISM, or CRISC.
- Experience with GRC tools, ServiceNow, and cloud technologies.
- Knowledge of risk frameworks such as NIST, ISO, PCI, and SOX.
- Experience with vulnerability remediation tracking, reporting, and dashboarding.
Preferred Qualifications
- One or more of the following certifications: CISSP, CRISC, CISA.
- 5+ years of prior experience in a related field; media or entertainment industry experience is a plus.
- Familiarity with streaming and similar products or services.
- 5+ years of Big 4 experience or in a related field.
- Experience working in a national or global company.
- Risk mitigation experience with AWS and/or other Cloud Databases such as Azure, GCP.
- Knowledge of metrics and visualization tools such as Power BI or Tableau.
Benefits
- Medical, dental, vision, life, and disability insurance plans.
- Employee Stock Purchase Program (ESPP).
- 401K program with company match after 12 months of tenure.
- Health Savings Account (HSA) on the HDHP plan.
- SupportLinc Employee Assistance Program (EAP) with up to 8 free counseling sessions.
- Corporate discount savings program and other discounts.
- On-demand training program, access to certification prep, and a library of technical and leadership courses/books/seminars after 6+ months of tenure.
- Certification discounts and perks to associations that include CompTIA and IIBA.
- Dedicated customer service team for benefits and resources, including a certified Career Coach.