Staff Information Security Analyst
ForgeRockAbout the role
About ForgeRock:
In today’s highly connected digital world, understanding, managing and securing the identity of individuals and things is essential to safety and success of both businesses and their customers. Billions of people connect from anywhere, use a wide variety of devices and expect a seamless yet secure experience.
The ForgeRock mission is to provide the most simple and comprehensive Identity and Access Management Platform to help our customers deepen their relationships with their consumers and improve the productivity and connectivity of their employees and partners. Our identity solution enables great digital experiences and is embedded with a rich set of security, privacy and consent features. We deliver our platform through both cloud services and on-premises software.
Our customers are some of the biggest companies, organizations, and even countries in the world. On any given day, it’s likely that the ForgeRock Identity Platform helped keep your data safe, gave you access to stuff, and supported trusted relationships between you, companies and the devices you were using.
ForgeRock is headquartered in San Francisco, but we are a global company with offices in the following cities: Vancouver, WA; Austin, TX; Bristol, UK; Grenoble FR; Oslo NO; and Singapore. Please read more about us at forgerock.com or follow ForgeRock on Twitter at http://www.twitter.com/forgerock.
Role Purpose Statement:
As an Information Security Analyst, you will work under the direction of the Information Security Manager and CISO to develop, maintain and optimise ForgeRock’s ISMS and related procedures, partnering with stakeholders to continuously advance ForgeRock’s security standards. You will be responsible for performing security compliance assessments across ForgeRock’s processes, staff and technology stack, and that of our partners and suppliers, developing associated reporting capabilities, and ensuring risk treatment is managed appropriately in accordance with ForgeRock’s security policies and related procedures.
Main Responsibilities:
- Work with the Information Security Manager and CISO to develop and optimise ForgeRock’s internal compliance program and related policies and procedures
- Work closely with ForgeRock’s customer-facing functions to respond to customer queries and requests for information about the company’s security and risk posture ensuring customer contractual requirements for security controls are met or tracked to delivery;
- Develop and optimise ForgeRock’s Risk Management Program and work with relevant stakeholders to treat, remediate and minimise risk across the organisation
- Ensure suitable due diligence and oversight of third party and supplier risk: performing risk assessments and conducting audits of critical suppliers as required
- Work with technical teams to expand the Security Compliance Program across ForgeRock’s technology stack
- Develop, monitor and report security GRC metrics and trends to relevant stakeholders
- Document and report control deficiencies and gaps to internal stakeholders and work closely with internal stakeholders to develop and implement suitable remediations
Skills & Qualifications (required)
- At least 5 years’ experience working in a security governance, risk and compliance role within the IT industry
- Experience with customer security assurance
- Experience working with cloud-based technologies (GCP, AWS or Azure)
- Good knowledge and understanding of SOC 2 and its application to corporate procedures
Skills & Qualifications (desirable):
- Experience with ISO 27001, ISO 27017 or CSA CCM v4.0.2;
- CISSP, CISM or equivalent industry standard certification;
- Good working knowledge of Google Cloud Platform;
- Experience with GRC practices within the context of software development;
- Proven management & delivery of IT process improvement projects.
The typical hiring range for this role is $116,000 - 139,000 in annual base compensation. Bonus and commission eligible roles will provide the opportunity to earn additional income based on performance against objectives. Candidate location and qualifications will be assessed to determine final compensation. In addition, our generous total rewards package includes health and wellness benefits, retirement savings plans, risk insurances, paid time off, parental leave, plus other supplemental offerings. For part-timers, your coverage will vary.
Life at ForgeRock:
We believe in and facilitate a flexible, collaborative work environment. We’re growing quickly, but re
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s