Job Summary
The Information Security (IS) Compliance Specialist will be responsible for supporting the management of compliance processes to help OVHcloud meet industry standard cloud computing certifications and applicable legal and regulatory compliance requirements with a high concentration on information security. As a part of the compliance team, you will play a strategic role in coordinating and executing OVHcloud US certification & compliance strategy for programs like ISO 27001, PCI-DSS, HIPAA, and SOC.
Base pay range : $85,000 - $95,000 (based on relevant experience).
Essential Duties & Responsibilities
- Support the execution of certification & compliance roadmap working with cross-functional teams and external auditing agencies.
- Accurately interpret, map, and communicate information systems compliance regulations and requirements within the organization, leveraging best practices.
- Conduct internal assessments and audits at planned intervals and on an ad hoc basis to evaluate and validate the design and operational effectiveness of policies, standards, and internal control framework to help reduce risk in the organization.
- Organize and support internal audits and external compliance / certification audits for the organization.
- Monitor open audit items from internal audits and external compliance / certification audits to ensure completion of remediation activities defined in the agreed action plans and risk treatment plans.
- Continuously search for ways to improve and optimize current processes related to compliance policies, standards, and external requirements.
- Provide compliance-focused support to sales, product, and legal teams.
Minimum Requirements
Bachelor’s degree in information systems or a related technical field preferred; equivalent experience considered in lieu of degree.4+ years of experience working in an information security, information technology or information risk management related field possessing thorough understanding of industry standards and regulations including ISO 27001, SSAE18 SOC 1, 2 & 3, Payment Card Industry (PCI-DSS), HIPAA, Cloud Star Alliance (CSA) and Sarbanes-Oxley (SOX).Experience with compliance programs in a service provider market preferred.Must be a self-starter and possess the qualities to work efficiently, effectively, and autonomously with general supervisionDemonstrated ability to multi-task, respond to needs quickly and efficiently and prioritize work with a strong attention to detailAbility to work well under pressure and respond to tight deadlines while exercising sound judgmentDemonstrated experience in managing compliance programs for financial services organization or organizations with similar information security needs and requirementsFamiliarity and understanding of broad range of IT technical controls, hardware and software products, cloud computing, or hosting servicesMust have excellent analytical skills; extensive Microsoft Excel experience a plusWorking Conditions
Standard office environment