Jobs and Careers
PE

Cybersecurity Compliance Engineer

Penumbra
United Statesfull_timeVerifiedPosted 15 Jan 2025
💰 $175,233/yr($117,815/yr$175,233/yr)

About the role

As a Cybersecurity Compliance Engineer, you will assess internal and external systems for compliance gaps, manage risk assessment processes, assist with audits, and collaborate with cross-functional teams to implement and maintain security controls that meet or exceed compliance requirements. You will play a critical role in supporting the security and governance initiatives of the organization.
Specific Duties and Responsibilities: ·         Ensure organizational compliance with relevant laws, regulations, and standards (e.g., PCI-DSS, HIPAA, GDPR, SOC 2, SOX, NIST, ISO 27001, etc.). ·         Manage and update compliance documentation and ensure all security policies and procedures are current and adhere to industry standards. ·         Regularly assess compliance status through internal audits and gap analysis and identify areas for improvement. ·         Conduct Internal Audit across IT domains using the ITGC controls framework across Network, IAM, Data/ End-point, Product and SOC ·         Assist in the preparation for internal and external audits, ensuring proper documentation and remediation of non-compliant areas.·         Perform risk assessments and work with cross-functional teams to identify, analyze, and mitigate IT security risks and vulnerabilities that could affect compliance. ·         Facilitate the implementation of corrective actions and control improvements based on audit findings. ·         Develop, implement, and maintain IT security policies, procedures, and controls to ensure ongoing compliance with regulations. ·         Support the review and drafting of security-related policies, ensuring they are consistent with compliance and security best practices. ·         Work closely with internal stakeholders, including IT, legal, and operations teams, to ensure compliance requirements are understood and met across the organization. ·         Provide guidance to management and technical teams on implementing security controls and meeting compliance objectives. ·         Educate employees on security and compliance best practices and provide training, as necessary. ·         Monitor compliance status regularly and generate compliance reports for management, stakeholders, and auditors. ·         Track compliance metrics and KPIs, ensuring the organization remains up to date with evolving regulatory requirements.·         Assist with incident investigations related to non-compliance and support remediation activities, as necessary. ·         Ensure that incidents that impact compliance are documented and reported to the relevant authorities as per regulatory requirements. ·         Plan and execute realistic, high-fidelity red team operations to simulate adversary tactics, techniques, and procedures (TTPs) against internal and external Penumbra systems. ·         Adversary emulation to simulate advanced persistent threats (APTs), including social engineering (e.g., phishing, vishing), physical penetration testing, and network exploitation. ·         Develop, deploy, and maintain custom attack tools, scripts, and payloads to support red team engagements. ·         Adhere to the Company’s Quality Management System (QMS) as well as domestic and global quality system regulations, standards, and procedures. ·         Understand relevant security, privacy and compliance principles and adhere to the regulations, standards, and procedures that are applicable to the Company. ·         Ensure other members of the department follow the QMS, regulations, standards, and procedures. ·         Perform other work-related duties as assigned.
Position Qualifications:·         Bachelor's degree in Information Technology, Computer Science, Information Security, or related field with 5+ years of experience, or equivalent combination of education and experience·         Preferred certifications in any of the following: Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) ·         5+ years of experience in IT security, risk management, or IT compliance roles. ·         Solid understanding of IT governance frameworks, security standards, and compliance regulations (e.g., PCI-DSS, HIPAA, GDPR, NIST, SOC 2, SOX, ISO 27001). ·         Experience with internal and external audit processes, risk assessments, and compliance reporting. ·         Familiarity with IT security technologies (firewalls, SIEM, encryption, identity management systems, etc.) is a plus. ·         Familiarity with current security frameworks (e.g., MITRE AT

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Penumbra

View company profile →