Back to Jobs

IT Security Compliance Analyst

Remote, USA Full-time Posted 2025-11-24
About the position Boomi is looking for a detail-oriented, technically savvy Security Compliance Analyst to join our Governance, Risk, and Compliance (GRC) team. In this role, you will manage the lifecycle of security audits, perform internal assessments, and ensure our cloud infrastructure remains compliant with international and regional frameworks. You will help translate complex regulatory requirements into actionable technical controls for our DevOps and Engineering teams. Responsibilities • Audit Management: Lead the preparation, execution, and remediation phases for global audits including SOC 1/SOC 2, ISO 27001/27701, and Cyber Essentials Plus. • Public Sector Compliance: Maintain Boomi’s FedRAMP authorization status (Moderate/High) and support Australian government requirements via the IRAP framework. • Continuous Monitoring: Perform regular internal gap analyses and "mock audits" to ensure controls are operating effectively throughout the year, not just during audit windows. • Stakeholder Collaboration: Work closely with Engineering, Legal, and HR to document processes and evidence that satisfy security control requirements. • Risk Assessment: Identify and communicate security risks associated with third-party vendors and internal architectural changes. • Evidence Collection Automation: Drive initiatives to automate compliance evidence collection to reduce "audit fatigue" across the technical organization. Requirements • Experience: 4+ years in IT Audit, Information Security, or Compliance, specifically within a SaaS or Cloud Service Provider environment. • Framework Expertise: Deep functional knowledge of SOC 2, ISO 27001, and NIST 800-53 (FedRAMP). • Technical Literacy: Ability to understand cloud infrastructure concepts (AWS/Azure) and explain security controls related to IAM, encryption, and vulnerability management. • Communication: Exceptional ability to translate "auditor-speak" into technical requirements for developers. Nice-to-haves • Certifications: CISA, CRISC, CISM, or CISSP • Familiarity with international standards like IRAP or Cyber Essentials is highly preferred. • Familiarity with the following services: Knowbe4, SafeBase, Ascend, and/or Jira Apply tot his job Apply To this Job

Similar Jobs

Senior Product Manager, AI Platform (Remote, US)

Remote, USA Full-time

Data/Solutions Architect

Remote, USA Full-time

Manager, Global Supply Chain – Data Center

Remote, USA Full-time

Ediscovery Consultants

Remote, USA Full-time

**Experienced Remote Research Participant – Paid Online Surveys, Focus Groups, and Product Testing**

Remote, USA Full-time

Remote Sales Chat Representative – High‑Earning Commission‑Based Role Selling Shipping Containers via Facebook Marketplace

Remote, USA Full-time

Content Writer, Creative Writer, English Assessment Content Writer

Remote, USA Full-time

Lead Consultant, Product Management – Technical

Remote, USA Full-time

Verizon Customer Service Representative

Remote, USA Full-time

Customs Brokerage Representative II: Mon-Friday: 6 am - 2:30 pm EST **Remote**

Remote, USA Full-time

**Experienced Chat Moderator – Remote Community Management and Discord Server Governance**

Remote, USA Full-time

LN Venues, Venue Applications Support Analyst Lead

Remote, USA Full-time

Outreach Analyst/Call Center Rep

Remote, USA Full-time

Remote Customer Support Representative

Remote, USA Full-time

Data Scientist Senior - Compliance Analytics

Remote, USA Full-time

Urgently Require Stretch Therapist/Athletic Trainer in Wichita, KS

Remote, USA Full-time

Experienced Full Stack Psychic Tarot Chat Operator - Remote Position with Flexible Hours and Growth Opportunities

Remote, USA Full-time

Inside Sales Rep - Remote

Remote, USA Full-time

Enterprise Senior Customer Success Manager

Remote, USA Full-time

Citizens Teller- Part Time – Amazon Store

Remote, USA Full-time