Senior Security Compliance Specialist

LaBella
  • Rochester, NY
  • $90,000–$110,000 Per Year
17 days ago

Job Description

We are currently looking to hire a Senior Security Compliance Specialist for LaBella's Operations Department. This position is located at our Rochester, NY office.

The primary responsibilities of this position are the program management, administration, and maintenance of LaBella's ISO 27001 and Information Security System (ISMS) program.

Specific Duties/Responsibilities include but are not necessarily limited to the following:

  • Management of LaBella's ISMS committee including scheduling, providing agendas, and keeping minutes of meetings, ensuring membership is maintained as current and relevant.
  • Management of LaBella's ISO 27001 and Information Security Management System (ISMS) program, in cooperation with the Security Operations Manager, including but not limited to:
  • Security policy, process, and procedure development and maintenance, in cooperation with Security, IT, and other department and division leadership.
  • ISO 27001 document control, including versioning, management reviews and approvals, communication to employees, and updating/maintaining ISO 27001 document management sites including internal and external facing document control web-based sites.
  • Developing and maintaining risk assessment and risk acceptance workflow, risk treatment/mitigation plans, and updating LaBella's risk register in coordination with relevant department and division leaders and executive management on required intervals.
  • Development of communication and coordination with executive, department, and division management, regional and office managers, internal and external communication managers, relevant third parties (clients, vendors, etc.), and LaBella data owners.
  • Coordinate ISO audits with internal and external resources and develop, track, and communicate corrective action plans
  • Collect and maintain ISO 27001/ ISMS evidence and control documentation, managing the GRC (Governance, Risk Management, and Compliance) platform
  • Establish and maintain an ISMS control ownership model, including assignment of control owners, control performers, approvers, review frequency, evidence requirements, and escalation paths for overdue or deficient controls.
  • Coordinate ISMS objectives, metrics, key performance indicators, and key risk indicators, and prepare recurring reporting for the ISMS committee, executive leadership, Security, IT, Operations, and other relevant stakeholders.
  • Maintain an ISMS compliance calendar covering internal audits, external audits, management reviews, policy reviews, risk assessments, access reviews, supplier reviews, evidence collection deadlines, training requirements, and certification milestones.
  • Coordinate with incident response, business continuity, disaster recovery, and crisis management stakeholders to ensure relevant plans, tests, lessons learned, and corrective actions are captured within the ISMS.
  • Promote continual improvement of the ISMS by identifying process gaps, control weaknesses, and opportunities to improve efficiency and consistency,
  • Coordinate with IT and Operations staff to ensure system performance and compliance with industry standards for physical and digital security items such as surveillance cameras, access control systems, endpoint management systems, 7x24 SOC, and information security management software as they relate to ISO 27001 certification.

Salary Range: $90,000 - $110,000 per year

The specific salary offered may be influenced by a variety of factors including but not limited to the candidate's relevant experience, education, and work location.

Numbers & Facts

LocationRochester, NY
Salary$90,000–$110,000 Per Year

Skills

  • Access Controlunmatched
  • Auditingunmatched
  • Communication Skillsunmatched
  • Computer Securityunmatched
  • Continuous Improvementunmatched
  • Corrective Actionunmatched
  • Crisis Managementunmatched
  • Disaster Recoveryunmatched
  • Document Controlunmatched
  • Document Managementunmatched
  • External Auditunmatched
  • ISO (International Organization for Standardization)unmatched
  • Incident Responseunmatched
  • Industry Standardsunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Meeting Minutesunmatched
  • Office Managementunmatched
  • Operations Managementunmatched
  • Performance Metricsunmatched
  • Physical Securityunmatched
  • Policy Developmentunmatched
  • Procedure Developmentunmatched
  • Process Developmentunmatched
  • Project/Program Managementunmatched
  • Regulatory Complianceunmatched
  • Reporting Skillsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Complianceunmatched
  • Security Monitoringunmatched
  • Security Policyunmatched
  • Security Softwareunmatched
  • Source Code/Configuration Management (SCM)unmatched
  • Surveillanceunmatched
  • Systems Administration/Managementunmatched
  • Time Managementunmatched
  • Treatment Planunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder