Search by job, company or skills

Exxat

Security Engineer - Compliance

new job description bg glownew job description bg glownew job description bg svg
  • Posted 20 days ago
  • Be among the first 10 applicants
Early Applicant

Job Description

We're looking for a self-driven Compliance Security Engineer to take ownership of our security and privacy compliance initiatives. You'll play a key role in implementing, maintaining, and enhancing compliance with frameworks like ISO 27001 HIPAA, SOC 2 and TX-RAMP. This role is ideal for professionals who thrive in independent environments, enjoy solving real-world problems, and want to work across multiple frameworks with direct organizational impact.

Compliance Ownership

The core responsibilities for the job include the following:

  • Manage end-to-end compliance programs, including ISO 27001 HIPAA, SOC 2 TX-RAMP.
  • Coordinate with vendors, auditors, and internal teams to ensure timely and complete compliance.

Policy And Documentation

  • Create and maintain security policies, SOPs, audit documentation, and risk registers.
  • Track compliance gaps and work with teams on remediation efforts.

Audit And Risk Management

  • Act as the point of contact during audits and certification processes.
  • Conduct risk assessments and recommend security improvements.
  • Drive recurring activities such as access reviews, internal audits, and awareness training.

Stakeholder And Vendor Collaboration

  • Engage with external compliance service providers.
  • Prepare and present compliance status, risks, and mitigation reports to leadership.

Requirements

  • Strong work ethic, self-motivation, and reliability.
  • Excellent problem-solving ability and eagerness to learn.
  • 2-5 years of experience in security compliance, risk management, or audit.
  • Experience managing compliance frameworks such as ISO 27001 HIPAA, and SOC 2
  • Ability to independently manage compliance programs.
  • Proficiency in access control, risk management, security frameworks, and governance models.
  • Experience with documentation, policy creation, and audit coordination.
  • Excellent communication and stakeholder management skills.
  • Exposure to AI tools or prompt-based compliance support is a strong plus.
  • Certifications such as ISO 27001 Lead Auditor/Implementer, CISA, CISM, CIPT are preferred but not mandatory.

Preferred (Good To Have)

  • Experience with GRC tools.
  • Familiarity with cloud security (Azure, AWS, GCP).
  • Understanding of vendor risk management and third-party security assessments.

This job was posted by Kiruthika Paramasivam from Exxat.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 132345199