IT Security, Risk & Compliance Analyst

JOB OVERVIEW


Plan A Technologies is seeking a proactive, organized, and detail-oriented IT Security, Risk & Compliance Analyst. In this role, you will support the hands-on operation and continuous improvement of our internal enterprise security program, working directly with the IT Security, Risk & Compliance Manager.

Working closely with senior leadership and engineering teams—as well as cross-functional stakeholders in IT, HR, and Project Management—you will help execute routine internal controls, track remediation efforts, assist with vendor and client security evaluations, and triage endpoint security events.

This is a versatile role combining internal Governance, Risk, and Compliance (GRC) execution with practical endpoint security oversight, ideal for a practitioner looking to grow their career across both security operations and GRC.


Please note: you must have at least 3+ years of hands-on experience in Information Security, IT Audit, Technical Support, or GRC roles to be considered for this role.


JOB RESPONSIBILITIES

  • Internal Control Execution & Tracking: Maintain and execute the periodic InfoSec controls calendar (monitoring workstation OS/app patching status, EDR status, vulnerability scans, and infrastructure/web maintenance).

  • Cross-Functional Stakeholder Coordination: Partner persistently with diverse teams (HR, IT, Software Engineering, Project Management) to enforce security requirements and drive open remediation items to completion (e.g., onboarding training compliance, vulnerability findings, process action items).

  • Policy & Documentation: Help write, update, and maintain IT security policies, standard operating procedures (SOPs), and user guidelines.

  • Incident Response & Triage: Assist senior engineers and leadership in monitoring, investigating, and triaging security events and potential incidents at both the endpoint and application levels.

  • Vendor & Partner Reviews: Perform baseline security evaluations and risk questionnaires for third-party vendors and software tools.

  • Client Security Support & DDQs: Assist in completing Client Due Diligence Questionnaires (DDQs) and help review security-related clauses in client and vendor contracts.

  • Technical Security Advisory & Awareness: Provide guidance to internal teams on security best practices, and help organize/deliver security awareness training and campaigns to end-users.

  • Continuous Improvement & Metrics: Track security metrics, logs, and remediation efforts to continuously strengthen the organization's posture.



EXPERIENCE

  • 3+ years of hands-on experience in Information Security, IT Audit, Technical Support, or GRC roles.

  • Working familiarity with Endpoint Detection & Response (EDR) platforms, Mobile Device Management (MDM, like Microsoft Intune), and patch management processes.

  • Experience organizing, executing, and tracking user information security awareness campaigns and training for both technical and non-technical staff.

  • Fundamental understanding of cloud ecosystems, SaaS tools, source control workflows, and baseline networking concepts.

  • Baseline working knowledge of major security frameworks (SOC 2, ISO 27001) and privacy regulations.

  • Exceptional organizational skills with strong, professional follow-up habits to coordinate tasks across multiple departments.

  • Fluent in written and spoken English with clear communication skills to collaborate with internal teams and external clients.

  • Strong analytical problem-solving skills with a high degree of attention to detail.

  • Ability to prioritize tasks, handle multiple assignments, and meet deadlines in a fast-paced environment.

  • Collaborative mindset with a customer-first attitude when advising internal stakeholders and clients.

  • Initiative and drive to do great things.


Nice to Have

  • GRC Experience: Prior experience implementing and maintaining corporate information security programs aligned with international standards (such as ISO 27001 or SOC 2).

  • Certifications: Entry-to-mid certifications such as CompTIA Security+, Associate of ISC², GIAC, or vendor-neutral GRC/security certifications.

  • Scripting Skills: Basic scripting skills (PowerShell, Python, or Bash) for automation and evidence gathering.



ABOUT THE COMPANY/BENEFITS

Plan A Technologies is a global engineering firm created to solve the toughest tech challenges facing today’s businesses. Founded by software entrepreneurs Aron Ezra and Slav Kulik, Plan A helps organizations analyze their tech ecosystem to identify exactly what needs to be improved across their products and infrastructure—and then builds the solutions to fix it.

Rather than offering theoretical ideas or software that never launches, Plan A combines elite engineering talent with custom-built, proprietary AI agents to deliver fast, secure, production-ready solutions. Its capabilities span proprietary AI agent deployment, custom software development, application modernization, data platforms, cloud migrations, systems integration, and practical technical advice.

With more than 500 successful product deployments completed worldwide, Plan A helps organizations of every size—from ambitious startups to global enterprises—modernize their systems, automate complex operations, and stay ahead of the technology curve.


Read more about us here: www.PlanAtechnologies.com


Location: Work From Home 100% of the time, or come into one of our global offices. Up to you.


Great colleagues and an upbeat work environment: You'll join an excellent team of supportive engineers and project managers who work hard but don't ever compete with each other.


Benefits: Vacation, Brand New Laptop, and More: You’ll get a generous vacation schedule and other goodies.


If this sounds like you, we'd love to hear from you!


See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available