Jobs and Careers
EC
IT Security Senior Associate
EcoVadisSpainRemotefull_timeVerifiedPosted 11 Jan 2023
About the role
<h3>Company Description</h3><p><em>Work smart, have fun and make an impact!</em></p><p><strong>EcoVadis is the leading provider of business sustainability ratings.</strong></p><p>Our solutions are backed by an international team of experts and powerful technology. We analyze data and build sustainability scorecards that give companies actionable insights into their environmental, social and ethical risks.</p><p><strong>Why apply to EcoVadis?</strong></p><p>Be a part of the global sustainability change in business. Grow your career. Work with extraordinary people. Feel valued for your contribution.</p><p>Learn more about our team and culture on <a href="https://ecovadis.com/careers/">EcoVadis careers page</a></p><p>If you have questions about the company or open roles you can <a href="https://ecovadis.career-inspiration.com/app/home">Chat with an insider</a></p><h3>Job Description</h3><p>Our IT Security team is seeking an IT Security Senior Associate to lead the security operations practices in our company, and bring forth security expertise in a fast-growing team. You will be the main point of contact for the alignment and provide hands-on collaboration in all areas of IT Security, ensuring that we deliver an outstanding service to our internal and external customers and stakeholders. </p><p>As the IT Security Senior Associate, you will become the main point of contact and coordinator for the remediation of any improvement areas, as well as the ‘face’ of our team towards our Sales and Customer Solutions’ teams. Also, your knowledge and willingness to learn on new security trends and technologies will be of great value to our company, while identifying efficiency and automation opportunities.</p><p>This role, reporting directly to the IT Security Director, will include the following responsibilities:</p><ul><li>Define and conduct security reviews (technical and compliance checks) of our network, systems and platforms, and track the remediation of any identified gaps;</li><li>Coordinate and organize evidence gathering for certification testing and audits;</li><li>Delineate and execute a control testing strategy to comply with internal IT Security framework compliance, standards, and other applicable regulations;</li><li>Establish and collaborate in the creation and maintenance of security guidelines for multiple technologies (e.g. SASE solutions, security baselines, etc.);</li><li>Perform security reviews on SaaS applications used internally, and establish a formal process of application sanctioning and periodic review;</li><li>Manage and lead improvements in the resiliency of non-cloud environments and operations (DRP, Backups, Domains, Incident Response);</li><li>Maintain the security posture of our external surface, and manage issue remediations as necessary;</li><li>Ensure proper documentation, configuration and operation of our security protective measures, and ensure that necessary fixes are planned and executed;</li><li>Develop reports, dashboards and other mechanisms to report on project tracking, remediation progress, and other domains that require continuous follow-up;</li><li>Promote an IT Security culture, and collaborate with the team in the creation of articles, FAQs, and documentation related to security awareness and training;</li><li>Active support on security questionnaires, contract reviews and client meetings;</li><li>Advocate for continuous improvement and automation wherever possible;</li><li>Assist with other organization security projects and tasks as required.</li></ul><h3>Qualifications</h3><ul><li>3+ years of experience in a similar role in a relevant software or internet service industry;</li><li>Minimum Bachelor of Science degree in Computer Science, Computer Engineering, or a related technical field;</li><li>Strong experience in designing and implementing security guidelines and mechanisms to check adherence to such standards; </li><li>Experience in conducting manual and/or automatic security compliance reviews;</li><li>Good knowledge of IT Security frameworks (e.g. ISO 27001, NIST CSF, etc.);</li><li>Managing and prioritizing multiple tasks in accordance with high level objectives;</li><li>Strong foundation in and in-depth technical knowledge of security engineering, computer and network security, authentication and security protocols;</li><li>Experience with engaging external stakeholders (e.g. clients) regarding security protection methods, and agreeing on contractual clauses;</li><li>Educated in the creation of reports and dashboards for different technical and executive stakeholders;</li><li>Ability to conduct research about areas unknown to him/her, and use that knowledge to deliver security guidelines and propose improvements;</li><li>Capacity to be organized and efficient handling diverse tasks simultaneously;</li><li>Open to work in an international, multilingual environment;</li><li>Proficient in English (oral and written);</li><li>Hands-on experience with Google Worksp
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s