Aprio PH - Senior Compliance Analyst
Clark, Pampanga
Aprio
Future-focused business advisory and accounting services for entrepreneurs, businesses, investors and families.Join Aprio's Cybersecurity team and you will help clients maximize their opportunities. Aprio is a progressive, fast-growing firm looking for a Senior Compliance Analyst to join their dynamic team.
Position Responsibilities:
- Governance & Compliance:
- Assist in developing, maintaining, and updating security policies, standards, and procedures to align with industry frameworks (e.g., NIST, ISO 27001, SOC 2, PCI-DSS).
- Monitor compliance with regulatory requirements (e.g., GDPR, CCPA, HIPAA) and support audits by gathering evidence and preparing reports.
- Support internal and external security assessments, including gap analyses and control testing.
- Risk Management:
- Conduct security risk assessments to identify vulnerabilities and recommend mitigation strategies.
- Assist in the development of risk treatment plans and track remediation efforts.
- Work with business units to identify potential security risks and implement appropriate controls.
- Security Audits & Assessments:
- Support security audits by collecting and reviewing evidence, documenting findings, and tracking corrective actions.
- Assist in vendor risk management by evaluating third-party security postures and ensuring compliance with security requirements.
- Maintain documentation and reports related to security risks, compliance activities, and control effectiveness.
- Security Awareness & Training:
- Help develop and deliver cybersecurity awareness training programs for employees.
- Promote best practices for data protection, incident response, and regulatory compliance.
Qualifications & Skills:
- Education: Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Business, or a related field. Relevant certifications (CISA, CISSP, CRISC, or CISM) are a plus.
- Experience: 2-5 years of experience in cybersecurity, GRC, risk management, or IT compliance.
- Knowledge of Frameworks & Regulations: Familiarity with industry standards such as NIST, ISO 27001, SOC 2, PCI-DSS, GDPR, and HIPAA is a plus.
- Technical Skills: Understanding of cybersecurity principles, risk assessment methodologies, and security controls.
- Analytical & Communication Skills: Strong problem-solving abilities, attention to detail, and ability to communicate security concepts to technical and non-technical stakeholders.
- Tools & Technologies: Experience with GRC tools, security auditing software, risk assessment platforms, and OneTrust is a plus.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits CCPA CISA CISM CISSP Compliance Computer Science CRISC GDPR Governance HIPAA Incident response ISO 27001 NIST Risk assessment Risk management Security assessment SOC SOC 2 Vulnerabilities
Perks/benefits: Career development Competitive pay Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.