Cybersecurity Compliance Engineer
Our Mission
iSeatz drives enduring brand loyalty through exceptional, connected experiences. Our digital commerce and technology solutions enable travel and lifestyle bookings for the world’s leading brands in financial services, travel, and hospitality, including American Express, IHG Hotels & Resorts, Qantas, and more.
What We Do
We have a history of long-term trusted relationships and innovation that drives tangible value to our customers through a customizable, scalable, and secure platform, a global third-party marketplace, and loyalty integration. Our proprietary platform processes over $9B per year in transactions.
We aspire to put our customers at the heart of every decision and exceed their expectations with best-in-class solutions and business-value innovations.
What You’ll Do
The Cybersecurity Compliance Engineer reports to the Information Security Manager and supports the Governance, Risk, and Compliance function, partnering with team leads, directors, and compliance auditors to maintain and enhance our compliance initiatives, focusing on data protection and security.
In this role, you will ensure our products, systems, and processes meet applicable regulatory, security, and compliance requirements.
Your Impact
- Ensure day-to-day compliance activities across applicable frameworks and requirements with a focus on PCI DSS but including SOC 2, NIST, GDPR, ISO, and customer-specific security and compliance obligations.
- Lead the preparation and execution of internal and external audits, including evidence collection, control validation, auditor coordination, issue tracking, and remediation follow-up.
- Perform technical security and compliance reviews of third-party vendors and service providers, evaluating security controls, architecture, data handling practices, compliance posture, and associated risks.
- Support customer and partner security assessments, including security questionnaires, evidence requests, technical discussions, and validation of contractual security and compliance requirements.
- Evaluate new technologies and services for security and compliance risk, and provide practical recommendations before implementation or adoption.
- Translate compliance and regulatory requirements into clear technical and operational requirements for Engineering, DevOps, Product, and other teams.
- Support remediation of Pen Test and external audit findings.
- Review and validate technical security controls related to identity and access management, logging and monitoring, vulnerability management, encryption, network security, secrets management, data protection, and secure development practices.
- Manage compliance controls and evidence within compliance automation and GRC platforms, ensuring controls are properly implemented, tested, documented, and supported by appropriate evidence.
- Identify compliance and security gaps through control testing, technical reviews, risk assessments, and monitoring, and work with control owners to develop and track remediation plans through completion.
- Conduct and support periodic risk assessments, access reviews, vendor reviews, policy reviews, and other recurring compliance activities.
- Maintain policies, standards, procedures, control documentation, risk records, exceptions, and other compliance artifacts to ensure they remain accurate and aligned with current business and technical environments.
- Partner with Information Security and technical teams to improve compliance processes through automation, improved monitoring, and more efficient evidence collection and validation.
What You Bring To The Table
- Experience working in information security, audit, compliance, GRC, or a closely related technical field.
- Strong working knowledge of PCI-DSS assessments, including experience supporting assessments, control testing, evidence collection, and remediation activities.
- Understanding of common security concepts and controls, including IAM, encr