Jobs and Careers
PE
Cybersecurity Compliance Engineer
PenumbraUnited Statesfull_timeVerifiedPosted 15 Jan 2025
💰 $175,233/yr($117,815/yr – $175,233/yr)
About the role
As a Cybersecurity Compliance Engineer, you will assess internal and external systems for compliance gaps, manage risk assessment processes, assist with audits, and collaborate with cross-functional teams to implement and maintain security controls that meet or exceed compliance requirements. You will play a critical role in supporting the security and governance initiatives of the organization.
Specific Duties and Responsibilities: · Ensure organizational compliance with relevant laws, regulations, and standards (e.g., PCI-DSS, HIPAA, GDPR, SOC 2, SOX, NIST, ISO 27001, etc.). · Manage and update compliance documentation and ensure all security policies and procedures are current and adhere to industry standards. · Regularly assess compliance status through internal audits and gap analysis and identify areas for improvement. · Conduct Internal Audit across IT domains using the ITGC controls framework across Network, IAM, Data/ End-point, Product and SOC · Assist in the preparation for internal and external audits, ensuring proper documentation and remediation of non-compliant areas.· Perform risk assessments and work with cross-functional teams to identify, analyze, and mitigate IT security risks and vulnerabilities that could affect compliance. · Facilitate the implementation of corrective actions and control improvements based on audit findings. · Develop, implement, and maintain IT security policies, procedures, and controls to ensure ongoing compliance with regulations. · Support the review and drafting of security-related policies, ensuring they are consistent with compliance and security best practices. · Work closely with internal stakeholders, including IT, legal, and operations teams, to ensure compliance requirements are understood and met across the organization. · Provide guidance to management and technical teams on implementing security controls and meeting compliance objectives. · Educate employees on security and compliance best practices and provide training, as necessary. · Monitor compliance status regularly and generate compliance reports for management, stakeholders, and auditors. · Track compliance metrics and KPIs, ensuring the organization remains up to date with evolving regulatory requirements.· Assist with incident investigations related to non-compliance and support remediation activities, as necessary. · Ensure that incidents that impact compliance are documented and reported to the relevant authorities as per regulatory requirements. · Plan and execute realistic, high-fidelity red team operations to simulate adversary tactics, techniques, and procedures (TTPs) against internal and external Penumbra systems. · Adversary emulation to simulate advanced persistent threats (APTs), including social engineering (e.g., phishing, vishing), physical penetration testing, and network exploitation. · Develop, deploy, and maintain custom attack tools, scripts, and payloads to support red team engagements. · Adhere to the Company’s Quality Management System (QMS) as well as domestic and global quality system regulations, standards, and procedures. · Understand relevant security, privacy and compliance principles and adhere to the regulations, standards, and procedures that are applicable to the Company. · Ensure other members of the department follow the QMS, regulations, standards, and procedures. · Perform other work-related duties as assigned.
Position Qualifications:· Bachelor's degree in Information Technology, Computer Science, Information Security, or related field with 5+ years of experience, or equivalent combination of education and experience· Preferred certifications in any of the following: Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) · 5+ years of experience in IT security, risk management, or IT compliance roles. · Solid understanding of IT governance frameworks, security standards, and compliance regulations (e.g., PCI-DSS, HIPAA, GDPR, NIST, SOC 2, SOX, ISO 27001). · Experience with internal and external audit processes, risk assessments, and compliance reporting. · Familiarity with IT security technologies (firewalls, SIEM, encryption, identity management systems, etc.) is a plus. · Familiarity with current security frameworks (e.g., MITRE AT
Specific Duties and Responsibilities: · Ensure organizational compliance with relevant laws, regulations, and standards (e.g., PCI-DSS, HIPAA, GDPR, SOC 2, SOX, NIST, ISO 27001, etc.). · Manage and update compliance documentation and ensure all security policies and procedures are current and adhere to industry standards. · Regularly assess compliance status through internal audits and gap analysis and identify areas for improvement. · Conduct Internal Audit across IT domains using the ITGC controls framework across Network, IAM, Data/ End-point, Product and SOC · Assist in the preparation for internal and external audits, ensuring proper documentation and remediation of non-compliant areas.· Perform risk assessments and work with cross-functional teams to identify, analyze, and mitigate IT security risks and vulnerabilities that could affect compliance. · Facilitate the implementation of corrective actions and control improvements based on audit findings. · Develop, implement, and maintain IT security policies, procedures, and controls to ensure ongoing compliance with regulations. · Support the review and drafting of security-related policies, ensuring they are consistent with compliance and security best practices. · Work closely with internal stakeholders, including IT, legal, and operations teams, to ensure compliance requirements are understood and met across the organization. · Provide guidance to management and technical teams on implementing security controls and meeting compliance objectives. · Educate employees on security and compliance best practices and provide training, as necessary. · Monitor compliance status regularly and generate compliance reports for management, stakeholders, and auditors. · Track compliance metrics and KPIs, ensuring the organization remains up to date with evolving regulatory requirements.· Assist with incident investigations related to non-compliance and support remediation activities, as necessary. · Ensure that incidents that impact compliance are documented and reported to the relevant authorities as per regulatory requirements. · Plan and execute realistic, high-fidelity red team operations to simulate adversary tactics, techniques, and procedures (TTPs) against internal and external Penumbra systems. · Adversary emulation to simulate advanced persistent threats (APTs), including social engineering (e.g., phishing, vishing), physical penetration testing, and network exploitation. · Develop, deploy, and maintain custom attack tools, scripts, and payloads to support red team engagements. · Adhere to the Company’s Quality Management System (QMS) as well as domestic and global quality system regulations, standards, and procedures. · Understand relevant security, privacy and compliance principles and adhere to the regulations, standards, and procedures that are applicable to the Company. · Ensure other members of the department follow the QMS, regulations, standards, and procedures. · Perform other work-related duties as assigned.
Position Qualifications:· Bachelor's degree in Information Technology, Computer Science, Information Security, or related field with 5+ years of experience, or equivalent combination of education and experience· Preferred certifications in any of the following: Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) · 5+ years of experience in IT security, risk management, or IT compliance roles. · Solid understanding of IT governance frameworks, security standards, and compliance regulations (e.g., PCI-DSS, HIPAA, GDPR, NIST, SOC 2, SOX, ISO 27001). · Experience with internal and external audit processes, risk assessments, and compliance reporting. · Familiarity with IT security technologies (firewalls, SIEM, encryption, identity management systems, etc.) is a plus. · Familiarity with current security frameworks (e.g., MITRE AT
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s