- Company Name
- Largeton Group
- Job Title
- Cybersecurity Analyst
- Job Description
-
Job title: Senior Cybersecurity Analyst
Role Summary: Lead and manage information security governance, risk, and compliance (GRC) initiatives, driving ISO 27001 and SOC 2 audit readiness, cloud security controls, incident response, and continuous improvement across the organization.
Expectations: • Deliver end‑to‑end ISO 27001 and SOC 2 audit execution with executive reporting. • Act as primary liaison for internal and external security audits. • Drive risk assessment, gap analysis, and remediation planning to meet regulatory and framework requirements.
Key Responsibilities:
- Develop, implement, and maintain information security policies, standards, and procedures.
- Lead ISO 27001 and SOC 2 Type I & Type II audits from scoping through final verification.
- Coordinate with engineering, IT, and compliance teams to remediate audit findings and improve security posture.
- Design, enforce, and monitor cloud security controls across AWS, Azure, and GCP environments.
- Conduct risk assessments, gap analyses, and remediation planning for security controls.
- Support incident response activities, security assessments, and third‑party/vendor risk reviews.
- Maintain audit evidence, compliance documentation, and executive‑level reporting.
- Drive continuous improvement initiatives to enhance overall security maturity.
Required Skills:
- Strong understanding of GRC frameworks (ISO 27001, NIST, CIS Controls).
- Proficiency with SOC 2 audit processes and audit evidence documentation.
- Experience designing and managing cloud security controls (AWS, Azure, GCP).
- Risk assessment, gap analysis, and remediation planning expertise.
- Incident response coordination and third‑party risk assessment skills.
- Excellent written and verbal communication, capable of presenting to executive stakeholders.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Professional certifications (e.g., CISSP, CISM, ISO 27001 Lead Implementer/Auditor, SOC 2 Auditor) considered essential.