Information Security Specialist

1 week ago


boston, United States Boston Consulting Group Full time
WHAT YOU'LL DO
The right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit processes and be able to collaborate with the team. The candidate must be a proactive team player, be able to communicate information and explanation to guide solutions. Additionally, the candidate must demonstrate strong customer service to set of internal stakeholders and develop positive and collaborative relationships within own area.
The successful candidate possesses excellent interpersonal and communication skills, both written and oral, required to partner with team members and stakeholders across the business to identify compliance gaps, issues and risks.
The role will report to the head of Governance & Risk Management for BCG X and sit within BCG’s information Security team.
YOU'RE GOOD AT
  • Understanding cybersecurity compliance frameworks - SOC 1, SOC 2, ISO 27k.

  • Have a risk mindset, eye for detail, and can apply critical thinking.

  • Working with auditors, audit request lists and taking ownership of gathering security audit evidence.

  • Coordinating audits and conducting reviews of deliverable to verify compliance with internal policies and industry best practices.

  • Thorough with an eye for detail to ensure completeness of audit and compliance requests.

  • Ensuring clear and expedient escalations with informed recommendations to management.

  • Being a team player and working to achieve common goal in a dynamic setting.

  • Identify and leverage lessons learned and best practices from audits, fostering the culture of continuous improvement within BCG.


YOU BRING (EXPERIENCE & QUALIFICATIONS)
  • Broad working knowledge in key areas of security compliance frameworks (SOC 1, SOC 2, HITRUST, ISO 27k).

  • Minimum of 2 years’ experience working with security compliance audits.

  • A minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred.

  • Fluent in English (verbal and written) Strong communication.

  • Flexibility in scheduling, capable and willing to attend conference calls outside of regular working hours to accommodate the geographical requirements and time zones of our stakeholders, and team members.

  • Flexibility in scheduling, capable and willing to attend conference calls outside of regular working hours to accommodate the geographical requirements and time zones of our stakeholders, and team members.

  • Strong work management, and work ethics required.

  • Ability to work successfully within a cohesive and matrixed team environment.

  • Superior interpersonal and communication skills; projects confidence and trust.


YOU'LL WORK WITH
The role will report to the head of Governance & Risk Management for BCG X and sit within BCG’s information Security risk management team, working closely with product and engineering, security and IT teams.


  • Boston, Massachusetts, United States Finance Full time

    Exciting Opportunity for Information Security Risk Specialist - Technology Risk ManagementAbout the Company:We are a prominent Financial Institution in search of a skilled Information Security Risk Specialist to become a part of our Technology Risk Management team. Our commitment lies in prioritizing the interests of our clients, employees, communities, and...


  • Boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DOThe right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DO The right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DOThe right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, United States Boston Consulting Group Full time

    WHAT YOU'LL DO The right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, United States The Computer Merchant, LTD. Full time

    JOB TITLE: Information Security Engineer JOB LOCATION: Boston, MA WAGE RANGE*: 60 - 67/ hour JOB NUMBER: 33818687 REQUIRED EXPERIENCE: BA or BS degree in Computer Science, Information Technology or related field preferred. Strong technical knowledge in at least one of the technical domains of information security such as access control systems, firewalls,...


  • Boston, United States Whitridge Associates Full time

    As an Information Security Specialist, you will be responsible for managing and improving our information security programs, focusing on vulnerability management, remediation, and security program analysis. Your expertise in email security, Proofpoint, and E5 licensing security features will be crucial in maintaining a robust security framework. You will...


  • Boston, United States InfiCare Technologies Full time

    Job DescriptionJob DescriptionHi There,Hope you are doing great.InfiCare has been providing Contingent Staffing and Direct Hire staffing services to its clients across the US and in four continents Since XX01. Starting from a modest beginning in X001, today we service clients ranging from Fortune X0X companies to medium sized businesses as well as small...


  • Boston, Massachusetts, United States The Computer Merchant, LTD. Full time

    Job SummaryThe Computer Merchant, LTD. is seeking a highly skilled Cyber Security Operations Specialist to join our team. As a key member of our security operations team, you will be responsible for monitoring and responding to security alerts, reviewing and improving our Splunk SIEM logs, and conducting threat hunting and incident response activities.Key...


  • Boston, MA, United States Boston Consulting Group Full time

    WHAT YOU'LL DO The right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, MA, United States Boston Consulting Group Full time

    WHAT YOU'LL DO The right candidate is responsible for managing security compliance for BCG’s software and data offerings in alignment with AICPA’s SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • Boston, Massachusetts, United States Tetrad Digital Integrity LLC Full time

    Mid-Level Cybersecurity Specialist at Tetrad Digital Integrity Tetrad Digital Integrity LLC is a leading firm in the cybersecurity sector, committed to safeguarding clients against digital threats. We are in search of a mid-level Cybersecurity Specialist to enhance our team, focusing on supporting critical cybersecurity initiatives. Key...


  • Boston, United States Creative Financial Staffing Full time

    Information Technology Support Specialist - hybrid work schedule - downtown BostonAbout the Company and Opportunity:Established and thriving organization seeks a full time IT Support Specialist to join a busy team.Employees here enjoy collaboration and customer focus.The company has a reputation for giving back to the communityOutstanding employee benefits...


  • Boston, United States Creative Financial Staffing Full time

    Information Technology Support Specialist - hybrid work schedule - downtown BostonAbout the Company and Opportunity: Established and thriving organization seeks a full time IT Support Specialist to join a busy team. Employees here enjoy collaboration and customer focus. The company has a reputation for giving back to the community Outstanding employee...


  • Boston, MA, United States Boston Consulting Group Full time

    WHAT YOU'LL DO The right candidate is responsible for managing security compliance for BCG's software and data offerings in alignment with AICPA's SOC 1 and SOC 2 framework and ISO 27001 standards. The right candidate must be able to demonstrate understanding of the fundamental security compliance frameworks, understand security and compliance audit...


  • South Boston, Virginia, United States DSI Security Full time

    Position OverviewAt DSI Security, we offer more than just a paycheck; we provide a fulfilling career path. Our core values and motto, Do What You Say You Will Do, resonate throughout our organization, ensuring that every employee feels valued and part of a greater mission.We are committed to fostering a work environment that mirrors the principles and...


  • Boston, United States BOSTON TRUST WALDEN COMPANY Full time

    Job DescriptionJob DescriptionBoston Trust Walden Company Overview Boston Trust Walden Company is an independent, employee-owned firm that provides investment management services to institutional investors and private wealth clients. The firm manages approximately $16 billion in client assets.Boston Trust Walden distinguishes itself in several key ways,...


  • Boston, United States Metasys Technologies, Inc. Full time

    Information Security Engineer Boston, MA (hybrid, 3 days onsite) 6+Month Contract This hybrid role requires initial in-office training in the Northeast (several weeks minimum), with subsequent flexibility to work remotely. Typically, the schedule involves three days onsite and two days offsite, based on the manager's discretion. Normal office hours are...


  • Boston, United States Metasys Technologies, Inc. Full time

    Information Security Engineer Boston, MA (hybrid, 3 days onsite) 6+Month Contract This hybrid role requires initial in-office training in the Northeast (several weeks minimum), with subsequent flexibility to work remotely. Typically, the schedule involves three days onsite and two days offsite, based on the manager's discretion. Normal office hours are...


  • Boston, United States Rose International Full time

    Date Posted: 08/27/2024Hiring Organization: Rose InternationalPosition Number: 469992Job Title: Information Security GRC AnalystJob Location: Boston, MA, USA, 02116Work Model: HybridEmployment Type: TemporaryEstimated Duration (In months): 10Min Hourly Rate($): 50.00Max Hourly Rate($): 55.00Must Have Skills/Attributes: Compliance, Data Security, Governance,...