Jostens logo
JostensPosted 1 month ago

Sr. Security Analyst – Control Design & Implementation Assurance

RemoteDominican Republic

InternshipSenior Level

Job Summary

Conduct independent, risk-based assessments of IT systems, applications, cloud services, and OT environments to evaluate control design, implementation, and operating effectiveness. Partner with engineering and business teams across project lifecycles to embed security requirements, validate configurations, and identify gaps in identity management, network segmentation, and data protection. Document findings, facilitate remediation validation, and support readiness activities for SOC 2, PCI DSS, SOX, and NIST frameworks. Translate technical risks into executive-level reports and drive continuous improvements to security governance and assurance practices.

Required Qualifications

  • Minimum 5+ years of experience in Information Security, Security Assurance, GRC, Technology Risk, IT Audit or Risk Management roles
  • Bachelor's degree in Information Systems, Information Security, Accounting, Business, or a related field (or equivalent experience)
  • Experience performing IT control assessments and security reviews across applications, infrastructure, and cloud environments
  • Working knowledge of security frameworks and audit standards (e.g., ISO 27001, SOC 2, PCI DSS, SOX, NIST)
  • Experience partnering with project and technical teams to assess security design and implementation
  • Strong ability to document findings, risks, and recommendations in an audit‐ready manner
  • Experience using GRC tools for risk, control, and issue management

Desired Qualifications

  • Prior experience in security assurance, technology risk, compliance assessments, or external audit/consulting
  • Prior experience as a business or systems analyst supporting existing systems or implementing new systems
  • Exposure to OT environments and/or physical security controls
  • Professional certifications such as CISA, CISSP, CRISC, or equivalent
  • Experience supporting and advising regulated or customer‐assured environments, including PCI, SOX, and SOC 2 programs

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce