Jobs and Careers
EX

Security Standards Compliance Specialist - 100% US REMOTE

Experian
United StatesRemotefull_timeVerifiedPosted 23 May 2023

About the role

Company Description

Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years we’ve been named in the 100 “World’s Most Innovative Companies” by Forbes Magazine

Job Description

The primary responsibility of the Sec Standards Compliance team would be to establish and manage specific security standards’ compliance (such PCI, HIPAA, ISO 27002, SOC 2, etc.) more as a well-rounded programme vs. annual project activities. The team will be required to have a strong interface with technical and business experts and articulate audit needs, processes and drive remediation. This is achieved by quickly understanding the business environment, critical products and processes, internal and external standards and regulations and building excellent relationships across Experian Globally. This position is a part of the Global Security Office (GSO). The GSO sets and ensures that the Information Security policy and standards are implemented across Experian.  

 

The InfoSec Standards Compliance Specialist is responsible for, but not limited to, the following: 

  • Establish and managed specific standards’ compliance (such PCI, HIPAA, ISO 27002, SOC 2, FISMA/FedRAMP etc.) more as a well-rounded program vs. annual project activities. The elements of the program include many of the traits listed below.  

  • Facilitate aforementioned attestations, audits and certification efforts for the businesses and technology.  Partner with client support functions to coordinate and schedule timescales and teams.  

  • Contribute to the management of overall program and owner of specified workstreams with full accountability for successful delivery 

  • Working closely with other stakeholders to establish the program and workstream governance framework and ensuring adherence to those standards thereafter 

  • Establishing, documenting, maintaining and communicating project scope, milestone/detailed plans, risks and issues and then proactively using as a basis for all discussions across the program to ensure full alignment 

  • Proactively engaging with key stakeholders and providing facilitation to allow full engagement and participation across the program. 

  • Providing meaningful status reports at program level and closely collaborating with workstream owners to deliver workstream level reporting 

  • Manages relationships with key regulatory and industry assessment vendors. 

  • Works alongside policy and standards team to incorporate changes into the enterprise policy document based on compliance assessment results. 

  • Develop metrics and reporting to demonstrate standards compliance status. 

  • Communicate the standards compliance posture and effectiveness to Management on a scheduled basis. 

  • Follow up on deficiencies identified in reviews and external audits to ensure appropriate remediation measures have been achieved timely. Track mitigation steps and ensure that risks are managed appropriately and in a timely manner. 

  • Manages a complex group of projects as it relates to post audit or ready assessment activities.  

  • Manages timelines, resources, project plans, action item logs, status reports and statistics to ensure milestones, goals and commitments are met. 

  • Actively contribute to a culture where the fair treatment of customers is at the heart of the Experian business.  Take personal responsibility to ensure that you adhere to all regulatory requirements and apply appropriate controls in the interests of our customers. 

 

Qualifications

  • Bachelor’s degree in computer science or relevant field or equivalent demonstrable experience. 
  • Experience in the information security standards area. 

  • Requires subject matter expert knowledge of the specific security standards such as PCI, HIPAA, SOC, ISO 27001/2, FISMA/FedRAMP, GLBA, NIST, FCA, FCRA, CFPB, UK data protection act, etc. 

  • Prior experience of managing these or similar compliance programs and managing engagement reviews (from scheduling to completion) is a must requirement. 

  • Demonstrated success in leading, controlling, & completing IT projects. 

  • Prior audit experience in any of the above areas a significant plus. 

  • Proven ability to combine business acumen, technical acumen and process expertise to define control requirements for  SOC 1 & SOC 2, HIPAA, PCI, ISO 27002, FISMA, FedRamp.  

  • Proven ability to influence & gain buy-in at multiple levels, acros

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Experian

View company profile →