Security Analyst II
Blue Yonder is a global leader in AI-driven digital supply chain solutions, dedicated to empowering businesses worldwide to optimize and transform their operations through innovative and intelligent technology. We help organizations improve efficiency, reduce costs, and enhance customer satisfaction while fostering a dynamic, inclusive, and collaborative work environment that values diversity and professional growth.
About the role
The Staff Security Analyst II, GRC at Blue Yonder plays a vital role in maintaining and enhancing the company's security compliance posture. This position involves working closely with cross-functional teams to ensure that Blue Yonder’s products and internal processes adhere to relevant IT and security controls that meet regulatory, industry, and internal standards. The role requires leading internal control assessments, managing audit activities, and supporting evidence collection for compliance purposes. The ideal candidate will identify control deficiencies, drive remediation efforts, and ensure audit readiness across the organization.
Responsibilities
- Lead internal IT and security control assessments aligned with best practice standards and frameworks (ISO 27001/27701/22301, SOC1/2 Type II, etc.)
- Identify control deficiencies and collaborate with stakeholders to drive remediation activities
- Support evidence collection and documentation to facilitate internal and external audits
- Regularly communicate compliance status and posture to stakeholders and leadership teams
- Stay current with evolving regulatory and security compliance standards and frameworks
- Train control owners and relevant personnel for audit participation and evidence collection
- Plan, coordinate, and manage internal and external audit activities, including scheduling and scope definition
- Review audit reports, respond to findings, and track remediation efforts to closure
Qualifications
- Minimum of 7 years of experience in information security compliance or IT audit roles
- Strong understanding of IT and security control frameworks such as ISO 27001, SOC1, SOC2
- Familiarity with cloud security practices and the shared responsibility model
- Experience performing end-to-end IT and security control testing and remediation tracking
- Excellent communication and stakeholder management skills
- Strong analytical and problem-solving abilities
- Certifications such as CISA, CISM, or CISSP are preferred but not mandatory
- Experience working with AI compliance frameworks such as ISO 42001 is a plus
- Bachelor’s degree or equivalent in Information Systems, Cybersecurity, Business, or related fields
Benefits
- Comprehensive Medical, Dental, and Vision coverage
- 401K plan with company matching contributions
- Flexible Time Off policy to support work-life balance
- Corporate Fitness Program to promote well-being
- Voluntary benefits including Legal Plans, Accident and Hospital Indemnity, Pet Insurance, and more