yandex
dnsfilter
Страна
США
Зарплата
120 000 $ – 135 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
УдалённоПолная занятость

Security & Compliance Analyst

Оценка ИИ

Отличная позиция для GRC-специалиста, который не хочет терять технические навыки. Высокая зарплата для США, удаленный формат работы и культура быстрорастущего стартапа делают вакансию очень привлекательной.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Роль требует сочетания глубоких знаний в области комплаенса (SOC 2, Vanta) и практических навыков в ИБ-операциях. Кандидату необходимо иметь опыт работы именно в SaaS-стартапах и уметь самостоятельно вести аудит.

Анализ зарплаты

Медиана130 000 $
Рынок110 000 $ – 155 000 $
Оценка ИИ

Предлагаемая зарплата ($120k - $135k) полностью соответствует рыночному уровню для специалистов среднего и старшего звена в области GRC в США, особенно в секторе SaaS. Она находится в пределах медианы для компаний на стадии роста.

Сопроводительное письмо

I am writing to express my strong interest in the Security & Compliance Analyst position at DNSFilter. With over 4 years of experience in GRC and security operations within the SaaS sector, I have a proven track record of leading successful SOC 2 Type II audits and managing compliance automation platforms like Vanta. My background perfectly aligns with your 70/30 split between governance and hands-on security operations, as I enjoy both the strategic oversight of risk management and the technical challenges of access management and security observability.

In my previous role, I not only maintained compliance frameworks but also actively collaborated with engineering teams to improve device posture and identity provider configurations. I am particularly drawn to DNSFilter’s mission of revolutionizing network security through AI-driven threat intelligence. I am confident that my experience in vendor security reviews and policy management, combined with my technical curiosity, will allow me to contribute immediately to your team's success and help maintain the high security standards your customers expect.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в dnsfilter уже сейчас

Присоединяйтесь к DNSFilter и станьте ключевым звеном в обеспечении безопасности инновационной SaaS-платформы!

Описание вакансии

DNSFilter’s mission is to protect our customers and partners with products they love to use! We are revolutionizing network security by providing fast, accurate, and reliable threat protection and content filtering. We're a rapidly growing company dedicated to creating a safer internet for businesses and organizations worldwide. Leveraging AI-driven threat intelligence, DNSFilter empowers our customers to proactively block threats before they impact their networks. We foster a collaborative, innovative, and results-oriented culture where every team member contributes to our mission of making the internet safer.

As we continue our product-fueled growth by adding new features and broadening our solution to meet the needs of the global market, it's clear there's a missing piece. That's where you come in!

We are looking for a Security & Compliance Analyst to own our compliance program and contribute to hands-on security operations. This is a hybrid role that comprises roughly 70% Governance, Risk, and Compliance and 30% Security Operations. You will be the person who keeps our compliance engine running while also rolling up your sleeves on projects related to access management, device posture, and security observability. This is not a role where you'll just be writing policies no one reads. You'll work alongside the rest of the security team, touch real systems, and directly improve our security posture; not just document it.

Eligible candidates have and can work successfully in a small to mid-sized fast-paced, hyper-growth, SaaS start-up or scale-up organization. This is a full-time role with a preference for candidates in the United States.

We recognize that people come with a wealth of experience and talent beyond just the technical requirements of a job. If you feel like this job is for you, please apply. We believe diversity of experience and skills, including transferable skills, combined with passion, is a key to innovation and excellence; therefore, we encourage people from all backgrounds to apply to our positions!

At DNSFilter, you will:Own Governance, Risk, and Compliance:

  • SOC 2 audit program - Drive our annual Type II audit end-to-end: evidence collection, auditor selection & coordination, remediation tracking, and readiness assessments
  • Compliance platform management - Own our Vanta instance as the primary admin: monitor controls, resolve alerts, maintain integrations, improve our trust center, and keep evidence collection automated
  • Customer security questionnaires - Respond to customer security assessments, RFPs, and due diligence requests
  • Vendor security reviews - Evaluate third-party vendors for security risk, manage the vendor review pipeline, and work cross-team to maintain our approved vendor registry
  • Policy management - Maintain, update, and drive approval cycles for security policies, standards, and procedures

Contribute to Security Operations:

  • Security observability - Improve our ability to detect and respond by working on logging, alerting, and tuning
  • Access management & device posture - Help implement and improve IdP configurations, access management, and endpoint compliance policies
  • Misc security projects - support other security team members on larger initiatives as capacity allows

To qualify for this role, you have:

  • 3–5 years in a GRC, compliance, or security analyst role at a SaaS or technology company
  • Hands-on admin-level experience with a compliance automation platform (Vanta, Drata, Secureframe, or similar)
  • Led or significantly contributed to at least one SOC 2 Type II audit cycle
  • Have led or substantially participated in at least one large technical project or deployment
  • Strong written communication
  • Self-directed and organized

Strong bonus points for:

  • Experience with identity providers (Okta, Azure AD/Entra, Google Workspace) at an admin or configuration level
  • Experience with GDPR or other data privacy frameworks
  • Familiarity with endpoint management tools (Jamf, Intune, Kandji)
  • Exposure to SIEM or log management platforms
  • Experience working in this role at a SaaS organization in the 100–500 employee range

We Offer:

  • Pathway to promotion to additional organizational positions and responsibilities based upon results and performance, not just time in the chair.  You help us grow, and we will help you grow.
  • Passionate and intelligent colleagues who work hard and have a good time doing it
  • Paid company-wide week off at the end of each year
  • Flexible Vacation Policy
  • Awesome company swag
  • Full medical, dental, and vision benefits for US, UK, and Canada-based employees
  • Full short-term disability and life benefits; available long-term disability
  • Retirement savings account options with vested company matching for qualifying employees
  • In-person annual gatherings. Last time we all spent a week on a beach in the Dominican Republic!

DNSFilter is a pay-for-performance organization, which means there is an opportunity to advance your compensation based on performance over time. The hiring base pay is dependent on several factors, including level, function, training, transferable skills, work experience, business needs, and geographic location. As a hybrid company, our compensation reflects the cost of labor across several U.S. and global geographic markets. We pay differently based on those defined markets. Our Talent Team can share more about the specific salary range for the job location during the hiring process.

DNSFilter participates in the E-Verify program.

At DNSFilter, we utilize sophisticated software and tools to identify and eliminate Deepfake candidates. This approach helps us maintain the integrity of our hiring process, ensuring that we select the most qualified and genuine individuals to join our team.

U.S. hiring salary range

$120,000—$135,000 USD

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • GRC
  • SOC 2
  • Vanta
  • SaaS Security
  • Access Management
  • Identity Management
  • Okta
  • Azure AD
  • Google Workspace
  • Jamf
  • Intune
  • SIEM
  • GDPR

Возможные вопросы на собеседовании

Проверка практического опыта работы с основным инструментом автоматизации комплаенса, указанным в вакансии.

Расскажите о вашем опыте администрирования Vanta или аналогичной платформы: какие интеграции вы настраивали и как обрабатывали критические алерты?

Вакансия предполагает владение процессом аудита SOC 2 Type II от начала до конца.

Опишите ваш самый сложный цикл аудита SOC 2 Type II: с какими трудностями при сборе доказательств вы столкнулись и как их решили?

Роль на 30% состоит из SecOps, включая управление доступом.

Какой у вас опыт настройки конфигураций IdP (например, Okta или Azure AD) для обеспечения соблюдения политик безопасности и условного доступа?

Оценка способности кандидата анализировать риски сторонних сервисов.

Как вы выстраиваете процесс оценки безопасности вендоров (Vendor Security Review), чтобы не замедлять бизнес-процессы, но минимизировать риски?

Проверка навыков коммуникации и работы с клиентами.

Как вы подходите к ответам на объемные опросники безопасности от крупных корпоративных клиентов (Customer Security Questionnaires)?

Похожие вакансии

Атом Безопасность
200 000 ₽ – 400 000 ₽

Application Security Еngineer (AppSec)

УдалённоРоссия
C++ · Rust · JavaScript · Python · TypeScript · SAST · DAST · SCA · ASOC · CI/CD · GitLab CI · Docker · Fuzzing · Threat Modeling
+14 навыков
NDA
Не указана

Head of SOC (Центр мониторинга кибербезопасности)

HeadВ офисеКыргызстан
SoC · SIEM · Incident Response · Cybersecurity Strategy · Security Architecture · Team Management
+6 навыков
HaaS Platform
от 400 000 ₽

Pentester (Offensive Security)

SeniorУдалённоРоссия
Pentesting · Linux · Python · Bash · Burp Suite · NMAP · OWASP Top 10 · Network Security · Red Team · Vulnerability Assessment · Go · JavaScript · C++
+13 навыков
СберАвто
200 000 ₽ – 350 000 ₽

Специалист по информационной безопасности

SeniorУдалённоРоссия
Fortinet · Palo Alto Networks · Check Point · ELK stack · Splunk · Cisco Prime · MaxPatrol · ArcSight · SolarWinds · VPN · PKI · OSPF · EIGRP · BGP · Kaspersky Security Center · Cortex XDR · Solar Dozor · Ansible · Terraform · Vulnerability Management · Patch Management
+21 навыков
Крупная международная ИТ компания
Не указана

Solution Sales Consultant (Cybersecurity)

В офисеУзбекистан
Cybersecurity · Solution Sales · Discovery Sessions · Business Analysis · English · Russian · Uzbek
+7 навыков
СберАвто
Не указана

Application security specialist

SeniorУдалённоРоссия
SAST · DAST · IAST · RASP · SCA · WAF · SSDLC · DevSecOps · OWASP · Linux · Python · Go · Threat Modeling
+13 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

dnsfilter
Страна
США
Зарплата
120 000 $ – 135 000 $