As a Senior Security Governance Analyst, you will manage security compliance programs, drive improvements in security posture, and collaborate with stakeholders to address audit and regulatory needs.
This role is for someone who is looking to positively impact Rapid7 with their information security knowledge by contributing to Security Trust & Governance Compliance programs for the EMEA and APAC regions. An information security, governance & compliance and/or information technology background would set you up for success in this position. Your ability to successfully carry out cross-functional work will require strong communication skills, patience, and a solution-oriented attitude.
You'll join us in our Belfast (UK) or Prague (Czech Republic) office and work with an energized team that cares deeply about the success of these initiatives, and leadership that values work-life balance, an inclusive culture, and your ongoing career development.
About the Team
Rapid7's Trust & Governance team functions within the Information Security department and plays a crucial role in supporting the organization's mission. We ensure we meet our duty of care to our customers, employees, and shareholders by creating effective governance for upholding internal security policies, identifying and managing security risk, distributing foundational security expertise across every department to create an exceptional security culture, and bolstering customer and community trust by providing accessible and transparent information about our internal security program. This role partners closely with other InfoSec teams, Legal, Procurement, and many other teams at Rapid7.
About the Role
We're looking for a Senior Security Governance Analyst to drive and support audit, compliance, customer facing interactions and partner closely with stakeholders throughout the organization to drive continued awareness and improvement in the Security GRC domain.
In this role, you will:
The skills you'll bring include:
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
About Rapid7
Rapid7 (NASDAQ: RPD) helps organizations across the globe protect what matters most so innovation can thrive in an increasingly connected world. Our comprehensive technology, services, and community-focused research simplify the complex for security teams, helping them reduce vulnerabilities, monitor for malicious behavior, be in 10 places at once, and shut down attacks. We're on a mission to make security solutions easier to use and access so we can bring safety and resilience to more people. With more than 10,000 customers across 140+ countries, Rapid7 is a leader in cybersecurity that has earned numerous industry accolades and recognition for our technology and culture.
#LI-SIM
You'll join us in our Belfast (UK) or Prague (Czech Republic) office and work with an energized team that cares deeply about the success of these initiatives, and leadership that values work-life balance, an inclusive culture, and your ongoing career development.
About the Team
Rapid7's Trust & Governance team functions within the Information Security department and plays a crucial role in supporting the organization's mission. We ensure we meet our duty of care to our customers, employees, and shareholders by creating effective governance for upholding internal security policies, identifying and managing security risk, distributing foundational security expertise across every department to create an exceptional security culture, and bolstering customer and community trust by providing accessible and transparent information about our internal security program. This role partners closely with other InfoSec teams, Legal, Procurement, and many other teams at Rapid7.
About the Role
We're looking for a Senior Security Governance Analyst to drive and support audit, compliance, customer facing interactions and partner closely with stakeholders throughout the organization to drive continued awareness and improvement in the Security GRC domain.
In this role, you will:
- Drive security compliance efforts identifying, analyzing and enabling requirements and controls implementation, to set up a high bar at Rapid7 and meet our customers and auditors expectations.
- Lead all compliance program initiatives for EMEA and APAC regions. You will be globally engaging with teams and external stakeholders to ensure business compliance needs are met while improving Rapid7's security posture.
- Act as an security-SME-in-the-middle between external stakeholders and internal experts to ensure accurate security responses tied to our regulatory and contractual requirements.
- Constantly influence Rapid7 to improve its security posture leveraging compliance and security frameworks adapting them to contextual needs.
- Address questions about Rapid7's internal security program from customers, prospects, and auditors. This will often require working with other members of the Information Security team, and with other Rapid7 teams, including Engineering, Product Management, Content Strategy, and Legal.
- Work in different initiatives simultaneously managing expectations with all stakeholders.
- Assist lead members of the security team with tasks related to:
- General information security risk management and assessment initiatives
- Identify risks while evaluating the design and operational effectiveness of controls to report opportunities for improvement
- Define and product metrics for Management consumption
- Aiding in security awareness and culture initiatives throughout the company
- Compliance program maintenance and audit management
- Policy and standard development
- Workflow/process improvements
The skills you'll bring include:
- 6+ years of experience in information security, information technology, audit/compliance management, data privacy/management, or an adjacent field.
- Deep understanding of EMEA and APAC Security compliance regimes and regulations such as NIS2, DORA, CE+, IRAP, DESC CSP, C5, ENS, etc.
- Experience with security standards/frameworks such as ISO 27001, SOC2, PCI, NIST CSF, CIS CSC, etc.
- Ability to analyze security requirements, identify gaps and help to define corrective actions.
- Strong project management abilities, including ability to coordinate initiatives across technical and non-technical teams/stakeholders and managing distributed teams and projects.
- Experience collaborating closely with security partners, including incident response, red teams, architects, and engineers to seamlessly incorporate cybersecurity controls and risk management processes into their day-to-day operations.
- Strong communication skills with the ability to translate complex technical concepts into business language
- Knowledge of public cloud environments, sdlc and access management process among others.
- Interested in emerging technologies such as Artificial Intelligence or Quantum Computing and in general with the fast evolving threat landscape.
We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today.
About Rapid7
Rapid7 (NASDAQ: RPD) helps organizations across the globe protect what matters most so innovation can thrive in an increasingly connected world. Our comprehensive technology, services, and community-focused research simplify the complex for security teams, helping them reduce vulnerabilities, monitor for malicious behavior, be in 10 places at once, and shut down attacks. We're on a mission to make security solutions easier to use and access so we can bring safety and resilience to more people. With more than 10,000 customers across 140+ countries, Rapid7 is a leader in cybersecurity that has earned numerous industry accolades and recognition for our technology and culture.
#LI-SIM
Top Skills
Cis Csc
Iso 27001
Nist Csf
Pci
Soc2
Similar Jobs at Rapid7
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
The Product Security Consultant evaluates IT architectures, deploys Rapid7 products, automates solutions, and communicates with customers about security practices.
Top Skills:
Amazon Web ServicesAPIsGoogle Cloud PlatformLinuxmacOSAzureMicrosoft Windows ServerPowershellPythonSQL
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
As Director of AI Engineering, you'll lead a global AI Center of Excellence, driving strategy, development, and deployment of AI solutions in cybersecurity, while managing a high-caliber team and collaborating across functions.
Top Skills:
AIData ScienceMachine LearningMlops
Artificial Intelligence • Cloud • Information Technology • Sales • Security • Software • Cybersecurity
Manage a team of researchers, lead vulnerability disclosure programs, prioritize vulnerability analyses, and advise on threat detection strategies.
Top Skills:
Code AnalysisExploit DevelopmentPatch DiffingThreat DetectionVulnerability Research
What you need to know about the Edinburgh Tech Scene
From traditional pubs and centuries-old universities to sleek shopping malls and glass-paneled office buildings, Edinburgh's architecture reflects its unique blend of history and modernity. But the fusion of past and future isn't just visible in its buildings; it's also shaping the city's economy. Named the United Kingdom's leading technology ecosystem outside of London, Edinburgh plays host to major global companies like Apple and Adobe, as well as a growing number of innovative startups in fields like cybersecurity, finance and healthcare.