Back to Jobs

IT Security Compliance Analyst

Remote, USA Full-time Posted 2025-11-24
About the position Boomi is looking for a detail-oriented, technically savvy Security Compliance Analyst to join our Governance, Risk, and Compliance (GRC) team. In this role, you will manage the lifecycle of security audits, perform internal assessments, and ensure our cloud infrastructure remains compliant with international and regional frameworks. You will help translate complex regulatory requirements into actionable technical controls for our DevOps and Engineering teams. Responsibilities • Audit Management: Lead the preparation, execution, and remediation phases for global audits including SOC 1/SOC 2, ISO 27001/27701, and Cyber Essentials Plus. • Public Sector Compliance: Maintain Boomi’s FedRAMP authorization status (Moderate/High) and support Australian government requirements via the IRAP framework. • Continuous Monitoring: Perform regular internal gap analyses and "mock audits" to ensure controls are operating effectively throughout the year, not just during audit windows. • Stakeholder Collaboration: Work closely with Engineering, Legal, and HR to document processes and evidence that satisfy security control requirements. • Risk Assessment: Identify and communicate security risks associated with third-party vendors and internal architectural changes. • Evidence Collection Automation: Drive initiatives to automate compliance evidence collection to reduce "audit fatigue" across the technical organization. Requirements • Experience: 4+ years in IT Audit, Information Security, or Compliance, specifically within a SaaS or Cloud Service Provider environment. • Framework Expertise: Deep functional knowledge of SOC 2, ISO 27001, and NIST 800-53 (FedRAMP). • Technical Literacy: Ability to understand cloud infrastructure concepts (AWS/Azure) and explain security controls related to IAM, encryption, and vulnerability management. • Communication: Exceptional ability to translate "auditor-speak" into technical requirements for developers. Nice-to-haves • Certifications: CISA, CRISC, CISM, or CISSP • Familiarity with international standards like IRAP or Cyber Essentials is highly preferred. • Familiarity with the following services: Knowbe4, SafeBase, Ascend, and/or Jira Apply tot his job Apply To this Job

Similar Jobs

Senior Product Manager, AI Platform (Remote, US)

Remote, USA Full-time

Manager, Global Supply Chain – Data Center

Remote, USA Full-time

Temp Accountant – Short Term

Remote, USA Full-time

Tech Support Representative

Remote, USA Full-time

**Experienced Remote Research Participant – Paid Online Surveys, Focus Groups, and Product Testing**

Remote, USA Full-time

Remote Sales Chat Representative – High‑Earning Commission‑Based Role Selling Shipping Containers via Facebook Marketplace

Remote, USA Full-time

Content Writer, Creative Writer, English Assessment Content Writer

Remote, USA Full-time

Lead Consultant, Product Management – Technical

Remote, USA Full-time

Remote Wealth Manager Associate - Path to Lead Advisor

Remote, USA Full-time

Part-Time Investment & Wealth Management Advisor; Work from Home

Remote, USA Full-time

Apply Now: Local Class A Truck Driver

Remote, USA Full-time

Apply Now: Looking for Burlington LSAT Tutor in Burlington, NC

Remote, USA Full-time

Certified Procedural Coding Spec - Surg

Remote, USA Full-time

Apply Now: Looking for Classroom Teaching Aide in Logan, UT

Remote, USA Full-time

Remote Business Development Expert

Remote, USA Full-time

( Call Center Representative ) Walgreens Data Entry Jobs...

Remote, USA Full-time

Apply Now: Live Chat Support Specialist

Remote, USA Full-time

`Urgently Hiring | Customer Service Representat...

Remote, USA Full-time

Experienced Remote Email Chat Representative and Call Centre Support Specialist – Delivering Exceptional Client Service and Driving Customer Satisfaction

Remote, USA Full-time

Remote Medical Accounts Receivable

Remote, USA Full-time