Security Risk & Compliance Analyst
At Jamf , we believe in an open, flexible culture based on respect and trust. Our track record and thriving work environment all stem from the freedom we grant ourselves to get the job done right. We take pride in helping tens of thousands of customers around the globe succeed with Apple.
The secret to our success lies in our connectivity, while operating with a high degree of flexibility. Work-life balance remains our priority while feeling connected is important to maintain our strong culture, achieve our goals, and thrive as #One Jamf .
What you'll do at Jamf :
The Security Risk & Compliance Analyst (Analyst) is responsible for ensuring that Jamf โs security controls, policies, and procedures are implemented in accordance with applicable laws, regulations, and industry standards. Reporting to the Director of Security Risk & Compliance, the Analyst will support the activities and improvements across the entire scope of Jamf โs Security Risk & Compliance program.
You may be required to work periodically at a Jamf office or collaborative work location with other Jamf employees in your area for certain events or moments that matter.
What you can expect to do in this role :
- Conduct risk assessments in accordance with established methodology.
- Collaborate with team members to evaluate cyber risk and treatment plans, and follow up to ensure appropriate action is taken to mitigate risk.
- Support maintenance of security policies to ensure compliance with relevant laws, regulations, and industry standards.
- Collaborate with teams across Jamf to ensure security policies are consistently implemented.
- Participate in monitoring efforts to ensure compliance with the security-related policies and procedures.
- Participate in external audits to ensure Jamf โs ongoing maintenance of its security certifications (i.e., ISO 27001, ISO 27701, SOC2 Type 2, StateRAMP).
- Support the vendor risk management function for evaluating Jamf โs vendors and partners to identify potential risks.
- Review security terms in vendor and partner contracts for consistency with Jamf โs standard annex.
- Support the customer assurance process for responding to questions and questionnaires from customers, potential customers, and partners regarding security and compliance.
- Review security terms in customer contracts and collaborate with security teams to ensure control requirements are implemented.
- Support the security awareness training program.
- Support preparation of periodic reporting for Senior Management.
- Support implementation of program improvement initiatives.
- #LIRemote
What we are looking for:
- Minimum of 1 year of relevant experience (e.g. security operations, governance, risk management, compliance) (Required)
- Familiarity with risk management methodologies, cybersecurity frameworks, and regulatory compliance (e.g. NIST, ISO 27001, ISO 27701, SOC2; StateRAMP and FedRAMP a plus) (Preferred)
- Working knowledge of operating systems, networking, cloud technology, security tools
- Experience in use of GRC applications a plus
- Strong analytical and problem-solving skills
- Excellent written/verbal communication and interpersonal skills
- Ability to work collaboratively and independently, participating in multiple projects simultaneously
- A practical mindset that can balance compliance and business needs
- 4 year / Bachelor's Degree in Computer Science or related field (Required)
- Actively pursuing one or more of the following:
- CGRC, CISA, CISSP, CISM, CompTIA Security+
- Amazon Web Services (AWS) experience
- Knowledge or security training from ISACA
- A combination of relevant experience and education may be considered
SECURITY AND PRIVACY REQUIREMENTS
- Participation in ongoing security training is mandatory
- Established security protocols will be adhered to, sensitive data will be handled responsibly, and data protection practices are followed, including understanding relevant priva