Senior Security Compliance Engineer

Feedzai
Summary
Join Feedzai's Security Team as a Compliance professional to design, develop, and maintain automated solutions for upholding the company's continuous compliance program. You will ensure compliance with core standards and regulations, maintain Feedzai's security control framework, perform risk analysis, and provide remediation recommendations. The role involves developing and maintaining policies, processes, and procedures, supporting audits, and contributing to company-wide security training. You will collaborate with a team of subject matter experts and work with various industry regulations and requirements. This position offers the opportunity to work remotely and be part of a dynamic team focused on fighting financial fraud and crime.
Requirements
- Knowledge of compliance and regulatory frameworks (PCI DSS, ISO/IEC 27001, SOC 2, NIST, CIS, GDPR, etc.)
- Understanding of cloud security concepts (e.g.: Amazon Web Services (AWS) IAM, GCP or Azure security principles, etc.) and integrating security controls through DevOps and Infrastructure as a Service (IaaS) techniques
- Excellent communication skills (written and verbal) with an ability to articulate complex topics in a clear and concise manner
Responsibilities
- Ensure compliance with core applicable standards and regulations (PCI DSS, ISO/IEC 27001, SOC 2, NIST, CIS, GDPR) and participate in the audit processes
- Maintain Feedzaiโs security control framework and continuous control monitoring
- Perform risk analysis and provide prioritized remediation recommendations
- Assist in the development, maintenance, and revision of policies, processes, standards and procedures
- Design, develop and maintain automated solutions to uphold Feedzaiโs continuous compliance program across a broad set of industry regulations and requirements
- Support clients, vendors and regulatory audits, including questionnaire and agreement reviewing
- Support company wide security and data privacy training
Preferred Qualifications
Knowledge of container orchestration systems such as Kubernetes is welcomed