Jobs and Careers
IV

Senior Security Compliance Engineer

Ivalua
United Statesfull_timeVerifiedPosted 9 May 2023

About the role

Senior Security Compliance Engineer

 

About Ivalua

A “Magic Quadrant” leader, Ivalua’s solutions work in a complex global economy.  Our innovative Source-to-Pay solutions include automating customized workflows to source, contract, request, procure, receive, and pay for goods and services across the enterprise, refining the procurement lifecycle while reducing cost and risk of spending on indirect goods, direct goods and services, and improving supplier collaboration.

All companies want the best and brightest. At Ivalua, we also want team members who have a global point of view and who bring customer-focused enthusiasm and ambition to the table. We are a company of doers, of problem solvers, of figure-it-outers. We have fun and we work hard. This is a truly global company with a diverse team of contributors and a set of core values that people can feel every day across all our offices.

About Team

Our team is very hands-on with a strong mindset of problem solving while also having the ability to think of the implementation holistically and provide solutions that solve the customer’s long-term challenges. Our team works hard, plays hard and enjoys all indoor and outdoor activities that the company organizes from time to time, so that you can focus, work collaboratively, and be at your creative best. 

Responsibilities:

  • Work collaboratively with R&D, IT, Sales and other stakeholders to develop FedRAMP Moderate, PCI and other technical security certification strategies and execute in a timely manner, ensuring alignment of certification strategies and execution plans to business and product imperatives.
  • Understand complex technical security architectures (including Azure cloud architecture) and apply that to certification and compliance projects as needed.
  • Provide documented expert technical guidance to the IT and R&D teams on implementation details and options to meet standards such as NIST SP 800-53 Rev 4/5, NIST SP 800-37, NIST 800-171, DFARS 252.204-7012, FISMA, ITAR, FedRAMP Moderate, StateRAMP, PCI etc.
  • Develop a solid technical understanding of the product line to speak fluently with consultants, certification agencies, and more to achieve certifications with a few additional resources as possible. Represent Ivalua to external organizations such as ISOs, StateRAMP/FedRAMP PMO, DISA, 3PAO assessors, etc.
  • Actively drive and/or participate in architectural discussion and decisions to build out of a new GovCloud/XRAMP environment and Credit/Debit/P-Card/V-Card holder environment.
  • Own, manage, and coordinate PCI DSS QSA, StateRAMP, FISMA/FedRAMP Moderate Equivalent/FedRAMP Ready audits.
  • Build, update and maintain System Security Plan and other artifacts needed to successfully meet requirements for 3PAO FedRAMP Moderate Equivalent/ FedRAMP Readyand PCI audits or customers.
  • Maintain and manage continuous monitoring of controls needed for the GovCloud/PCI programs.
  • Work closely with Sales and Marketing teams to build sales artifacts that clearly communicates the GovCloud/xRAMP and PCI Compliant Payment offerings to prospects and customers.
  • Support Sales and CSMs by attending customer meetings to walk them through security controls supporting GovCloud/xRAMP and PCI Compliant Payment offerings.
  • Work closely with IT and business functions to enhance the existing DR/BCP capabilities (e.g improve documented procedures, address known gaps), test and document Disaster Recovery and Business Continuity Program on a periodic basis.
  • Support other GRC team members with various security audits/certifications/self-assessments, including SOC1/SOC2, HIPAA, NIST 800-53, ISO27001, PCI, etc.
  • Track and drive remediation of control deficiencies and gaps identified internally and externally.

Skills Required:

  • High degree of initiatives, dependable and able to work well with limited supervision.
  • Effectively communicate with all invested areas of the organization and management stakeholders, from engineering to leadership
  • Understand the challenges of working in a distributed environment with multiple teams working on different problems.
  • Be detailed oriented and with ability to dig deeper into the nuances of security controls.
  • Curious, positive, “can-do” and transparent attitude is very critical for success.
  • Experience in managing or executing assessments and audits against some of the InfoSec frameworks such as NIST-800 53, PCI, FedRAMP, StateRAMP, etc.
  • Demonstrated project management, analytical and problem-solving skills.
  • Excellent interpersonal, communication and organizational skills
  • Team player with the ability to interface effectively with a broad range of individuals and ro

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Ivalua

View company profile →