Skip to content
← Back to job listings

Senior Security & Compliance Analyst

Headspace Health · Santa Monica, United States

External listingfull-time28 days ago

About The Role

Join Headspace Health as a Senior Security & Compliance Analyst. In this role, you will work closely with various teams to ensure adequate security capabilities and controls are in place to mitigate security risks and meet compliance requirements. You will also conduct security architecture/application reviews, support product testing during audits, and serve as the subject matter expert for security-related technical components. Telecommuting is permitted, and the position offers comprehensive benefits, including medical, dental, and vision healthcare plans, paid parental leave, flexible paid time off, and a 401K with company match.

  • Collaborer avec les architectes de cybersécurité, l'officier de la vie privée, le conseiller juridique, l'ingénierie et les équipes de gestion de produit pour garantir des capacités et des contrôles de sécurité adéquats.
  • Fournir des réponses détaillées aux questionnaires d'évaluation de la sécurité en travaillant en étroite collaboration avec les prospects et les gestionnaires de propositions.
  • Rechercher, concevoir, défendre et recommander de nouvelles technologies de sécurité, architectures et produits pour répondre à toutes les exigences de conformité.
  • Must have experience with the following: industry security compliance frameworks and regulations (ISO 27001/2, PCI-DSS, HIPAA, GDPR, FedRAMP, HITRUST, SOC 1, SOC 2, and international privacy requirements; cloud security concepts (DevSecOps, Infrastructure as Code (IaC), Continuous Integration/Continuous Deployment (CI/CD), Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST)); agile secure software development lifecycle and distinguishing core inputs and outputs in each cycle; security engineering practices (incident response, anti-malware solutions, threat detection, and vulnerability management); assessing and managing risks associated with third-party vendors and partners handling PII/PHI; developing and delivering security awareness training, emphasizing compliance and best practices in handling sensitive client information
  • Education Requirements: Bachelor’s degree or foreign equivalent in Computer Engineering, Management Information Systems, Cybersecurity or related field
  • Experience Requirements: Two (2) years of experience in the position offered, as a Security Analyst or related occupation

This is an external listing. JobSpring does not represent or verify the employer. Report this listing