Search jobs > Durham, NC > Security specialist

Sr. Security Governance Specialist

Avalara
Durham
Full-time

What You'll Do Avalara is looking for someone to support a growing team building on the security compliance function. You will be reporting to a Manager of Security Compliance and you will work hybrid out of the Durham, NC area.

LI-Hybrid This role is not eligible for visa sponsorship.* You will : Coordinate security compliance external assessments such as SOC 1, SOC 2, ISO 27001.

Handle coordination of quality control of assigned compliance controls such as access reviews, change reviews, terminated user analysis.

Ensure controls are performed by all partners within defined Service level agreements. Perform compliance assessments and work with system owners to fix.

Help enhance Avalara's common controls framework. Help collect and migrate control information into Avalara's GRC platform.

Be the contact for go-to-market related security inquiries. Partner with Sales organization to support the sales engagement lifecycle, including customer meetings and customer security inquiries.

Develop customer-facing security documentation. Identify areas for automation and business process improvements. Partner with internal and external groups on multiple simultaneous projects.

Job Duties Coordination of security compliance external assessments such as SOC 1, SOC 2, ISO 27001. Coordination, execution, and quality control of assigned compliance controls such as access reviews, change reviews, terminated user analysis.

Ensure controls are appropriately performed by all stakeholders within defined SLAs. Perform compliance assessments and work closely with system owners to remediate.

Help enhance Avalara’s common controls framework. Assist in collecting and migrating control information into Avalara’s GRC platform.

Act as a point of contact for go-to-market related security inquiries. Partner closely with Sales organization to support the sales engagement lifecycle, including customer meetings and customer security inquiries.

Develop customer facing security documentation. Identify areas for automation and / or business process improvements. Work strategically and independently with internal and external groups on multiple simultaneous projects.

Perform other duties as assigned. What You'll Need to be Successful You have a Bachelor's degree in computer science, or equivalent experience.

You have 3+ years of security, governance, compliance, or risk management experience, in FinTech or SaaS environment. You have 3+ years of professional experience working with ISO 27001, SOC 1, SOC 2, SOX, NIST and other similar frameworks.

You have experience with global corporate security, risk management, or governance roles You have 3+ years working with security governance frameworks, regulatory requirements, and industry best practices (, ISO 27001, NIST, GDPR, CCPA).

You are familiar with security technologies, GRC tools (eg : ServiceNow), and methodologies. You are experienced in security and privacy risk management principles.

You excel in communicating across multiple partners and customers verbally and in writing. About the Team Avalara's Organizational Risk, Resilience, Compliance and Audit team (ORRCA) manages multiple risk and compliance projects.

How We'll Take Care of You Total Rewards In addition to a great compensation package, paid time off, and paid parental leave, many Avalara employees are eligible for bonuses.

Health & Wellness Benefits vary by location but generally include private medical, life, and disability insurance. Inclusive culture and diversity Avalara strongly supports diversity, equity, and inclusion, and is committed to integrating them into our business practices and our organizational culture.

We also have a total of 8 employee-run resource groups, each with senior leadership and exec sponsorship. Flexible hybrid working We support hybrid work and flexible schedules for our employees.

Learn more about our benefits by region here : About Avalara We’re Avalara. We’re defining the relationship between tax and tech.

We’ve already built an industry-leading cloud compliance platform, processing nearly 40 billion customer API calls and over 5 million tax returns a year.

Last year, we became a billion-dollar business, and our tribe expanded by a cool thousand people - there’s nearly 5,000 of us now.

Our growth is real, and we’re not slowing down - not until we’ve achieved our mission - to be part of every transaction in the world.

We’re bright, innovative and disruptive, like the orange we love to wear. It captures our quirky spirit and optimistic mindset.

It shows off the culture we’ve designed, that empowers our people to win. Ownership and achievement go hand in hand here.

We instill passion in our people through the trust we place in them. We’ve been different from day one. Join us, and your career will be too.

EEO Statement We’re an Equal Opportunity Employer. Supporting diversity and inclusion is a cornerstone of our company we don’t want people to fit into our culture, but to enrich it.

All qualified candidates will receive consideration for employment without regard to race, color, creed, religion, age, gender, national orientation, disability, sexual orientation, US Veteran status, or any other factor protected by law.

If you require any reasonable adjustments during the recruitment process, please let us know.Coordination of security compliance external assessments such as SOC 1, SOC 2, ISO 27001.

Coordination, execution, and quality control of assigned compliance controls such as access reviews, change reviews, terminated user analysis.

Ensure controls are appropriately performed by all stakeholders within defined SLAs. Perform compliance assessments and work closely with system owners to remediate.

Help enhance Avalara’s common controls framework. Assist in collecting and migrating control information into Avalara’s GRC platform.

Act as a point of contact for go-to-market related security inquiries. Partner closely with Sales organization to support the sales engagement lifecycle, including customer meetings and customer security inquiries.

Develop customer facing security documentation. Identify areas for automation and / or business process improvements. Work strategically and independently with internal and external groups on multiple simultaneous projects.

Perform other duties as assigned.

3 days ago
Related jobs
Promoted
V2X
New River, North Carolina

We bring 120 years of successful mission support to improve security, streamline logistics, and enhance readiness. ...

Avalara
Durham, North Carolina

You have experience with global corporate security, risk management, or governance roles You have 3+ years working with security governance frameworks, regulatory requirements, and industry best practices (, ISO 27001, NIST, GDPR, CCPA). You have 3+ years of security, governance, compliance, or risk...

Promoted
UNC Health
Durham, North Carolina

Serves a principal role in designing, implementing and managing pharmacy business systems for a centralized business function of UNC Health Care. The Business Application Analyst-Pharmacy works with stakeholders across the health system to implement, maintain, standardize, and advance pharmacy syste...

Promoted
Cisco Systems, Inc.
Raleigh, North Carolina

The Customer Success Specialist (CSS) role is a critical, strategic advisor and technical expert that engages with customers to accelerate their adoption of Cisco products & solutions that transform their business and drive business outcomes. This highly technical role supports customers with adopti...

Promoted
Sequence Systems
Raleigh, North Carolina

Project Manager – Asbestos Abatement / Lead Remediation. Sequence has been exclusively retained and is currently seeking a capable Environmental Project / Branch Manager in Raleigh for North Carolina's most exciting and vibrant asbestos abatement and remediation organiz. ...

Promoted
Novartis Group Companies
Durham, North Carolina

This position will support activities within the Quality Control department, with a focus on technical items for QC, compliance and continuous improvement. Coordinate with Quality to ensure compliance and continuous improvement in the QC labs. ...

Promoted
James River Management Company
Raleigh, North Carolina

Information Security Operations Analyst II (Information Technology). The Information Security Operations Analyst II plays a crucial role in tactical efforts to ensure the security of company systems and data. The Security Operations Analyst II will often partner with IT and business teams to drive c...

Promoted
Allied Universal
Durham, North Carolina

As a Security Officer, you will serve and safeguard clients in a range of industries such as Commercial Real Estate, Healthcare, Education, Government and more. Allied Universal, North America's leading security and facility services company, provides rewarding careers that give you a sense of purpo...

Promoted
VirtualVocations
Durham, North Carolina

A company is looking for a Senior Privacy & Compliance Manager. ...

Promoted
CTC
Durham, North Carolina

Minimum 5 years of experience analyzing information security systems and applications and recommending and developing security measures to protect information against unauthorized modification or loss. Computer Technologies Consultants (CTC) is seeking a Systems Security Lead to support our clients ...