Information Security Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Hey!We’re Scale Up, and our client is looking to hire a Information Security Analyst.Type of Employment: Contractor (Long-term) Work Modality: 100% Remote Work Schedule: Full-time Time Zone: U.S. Pacific Time (PST) with overlap during business hours About Our Client Our client is a fast-growing U.S.-based cybersecurity and compliance consulting firm that partners with technology startups to strengthen their security posture and achieve compliance with frameworks such as SOC 2, ISO **, HIPAA, and more.They act as an extension of their clients’ security teams, providing GRC consulting, audit readiness, vendor risk management, and virtual CISO services.As the company continues to grow, they are expanding their team with professionals who enjoy working across multiple clients in a fast-paced consulting environment.About The Role You’ll own the vendor security questionnaire process from end to end across multiple client accounts.You’ll work closely with U.S.-based startups, monitoring incoming security requests, coordinating with technical stakeholders, and completing security questionnaires accurately and on time.This role requires a solid understanding of security frameworks, strong organizational skills, and the ability to communicate clearly with both technical and non-technical stakeholders.This is an excellent opportunity for someone with experience in GRC, security compliance, or vendor risk who enjoys supporting multiple clients and playing a key role in helping companies close enterprise deals.Key Responsibilities Monitor client Slack channels and respond promptly to incoming security questionnaire requests.Create and manage tickets in Jira, Linear, or other ticketing systems to track requests through completion.Complete vendor security questionnaires (SIG, CAIQ, custom questionnaires) through spreadsheets and security platforms such as OneTrust, Whistic, SecurityScorecard, and similar tools.Develop a deep understanding of each client’s security posture, policies, controls, and technical environment.Maintain and continuously improve client answer libraries and knowledge bases.Coordinate with security consultants, engineers, and subject matter experts whenever technical clarification is needed.Escalate recurring gaps or missing controls that impact questionnaire responses.Ensure all questionnaires are completed accurately and within customer deadlines.Requirements 2-4 years of experience completing vendor security questionnaires, working in GRC/compliance, or in a security-related client-facing role.Hands-on experience completing SIG, CAIQ, or custom vendor security questionnaires.Working knowledge of SOC 2 and ISO **.Understanding of common security concepts, including: Single Sign-On (SSO) Multi-Factor Authentication (MFA) Endpoint Management Encryption (at rest & in transit) Cloud infrastructure fundamentals Backup & Disaster Recovery Vendor Risk Management Strong organizational skills with the ability to manage multiple requests simultaneously.Excellent judgment regarding when to answer independently and when to involve technical SMEs.Excellent written communication skills.Professional English (written and spoken).Nice to Have Experience handling a high volume of vendor security questionnaires.Experience with: Conveyor SafeBase Vanta Whistic Trust Center platforms Experience maintaining questionnaire knowledge bases.Experience working alongside Sales or Revenue teams supporting enterprise deals.Certifications such as: CompTIA Security+ ISC2 Certified in Cybersecurity (CC) Similar cybersecurity certifications #J-*****-Ljbffr
Requirements
Requirements 2-4 years of experience completing vendor security questionnaires, working in GRC/compliance, or in a security-related client-facing role. Hands-on experience completing SIG, CAIQ, or custom vendor security questionnaires. Working knowledge of SOC 2 and ISO **. Understanding of common security concepts, including: Single Sign-On (SSO) Multi-Factor Authentication (MFA) Endpoint Management Encryption (at rest & in transit) Cloud infrastructure fundamentals Backup & Disaster Recovery Vendor Risk Management Strong organizational skills with the ability to manage multiple requests simultaneously. Excellent judgment regarding when to answer independently and when to involve technical SMEs. Excellent written communication skills. Professional English (written and spoken). Nice to Have Experience handling a high volume of vendor security questionnaires. Experience with: Conveyor SafeBase Vanta Whistic Trust Center platforms Experience maintaining questionnaire knowledge bases. Experience working alongside Sales or Revenue teams supporting enterprise deals. Certifications such as: CompTIA Security+ ISC2 Certified in Cybersecurity (CC) Similar cybersecurity certifications #J-**-Ljbffr
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Top-Paying Tech Jobs (with Salaries)
Data Analyst Salary in the UK
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again