Senior Compliance Specialist

Costa Rica, Remote

Apply now

YOUR MISSION:

The role of a Compliance Engineer is to work with our Trust and Compliance team to:            

  • Drive security compliance efforts from the beginning to the end by maintaining a positive relationship with both internal and external stakeholders
  • Maintain compliance documentation, including audit evidence, controls, and vendor security reviews
  • Design, implement, maintain, and improve programs to address key company risks and prepare internal teams for independent assessments against a wide variety of regulatory and compliance frameworks (PCI, SOC, ISO 27XXX, HIPAA, GDPR, etc) 
  • Monitor the performance of the compliance program through the development of and maintenance of automated systems.
  • Work with cross functional teams to identify risks and gaps in our compliance controls and facilitate remediation across our products and infrastructure.
  • Assist with completing security questionnaires from customers and answering customer questions with respect to compliance; work with the internals team to create customer collateral to educate internal staff and aid in the sales process
  • Assist with requesting/reviewing security questionnaires/contracts from vendors and identify security risks and gaps in the compliance controls to aid in the procurement process
  • Develop automations of risk management, control execution and monitoring

WHAT YOU’LL NEED TO BE SUCCESSFUL

  • 3+ years of experience with a demonstrated track record of success in GRC, internal audit, security, and/or privacy space.  
  • Knowledge of various compliance frameworks (PCI, SOC2, ISO 27001, ISO 27018, HIPAA, GDPR, etc.) 
  • Strong experience with any scripting languages like Ruby, Python, Unix shell, bash, etc.
  • Functional knowledge of multiple security domains and information security industry standards and best practicess
  • Experience leading 3rd party risk management programs, including responding to customer security questionnaires, interacting directly with customer sales and security teams, and reviewing vendor security
  • Solid experience managing compliance initiatives for cloud platforms and interacting with external auditors
  • Strong project management skills 
  • Strong written and verbal communication skills

NICE TO HAVEs

  • A mix of experiences at a Big Four (or similar) audit or consulting firm and at an in-house governance, risk, and compliance function at a SaaS company
  • Industry recognized certification in security ISO 27001 LA / LI D desire to pursue CISSP, CISA, CISM, CCSK, etc. in 6 months.
  • Experience working in an international / global organization

Apply now


Let’s do this.

You’re unique and we’re on a journey – so let’s embark on a unique journey together. We encourage you to apply to all roles that utilize your skills and ignite the passion within you.

No matter where you’re located, or which team you work on, you’ll be part of a group of people working together to build a better world: The World Subscribed.

Go ahead and apply!

 

 

Get to Know Us

Go ahead, take a look inside #ZEOLife. Meet our ZEOs and learn what it’s like to be a part of our team.

Read the Life at Zuora Blog

Choosing to Challenge, Today and Everyday at Zuora

Zuora’s executive team shares their insights on how we can “Choose to Challenge”...

Read more  

Choosing to Challenge, Today and Everyday at Zuora

C-Crets to Advocating for Yourself at Work

Four steps everyone can take to guide their career to the next level while maint...

Read more  

C-Crets to Advocating for Yourself at Work

Highlights from the Subscription Experience 2021

The global Subscribed experience goes virtual in our first ever Subscription Exp...

Read more  

Highlights from the Subscription Experience 2021

Connect with us

All about relationships. Let’s connect!