Information Security Compliance Manager

MED-1 Solutions, LLCGreenwood, IN
1h$100,000 - $150,000Onsite

About The Position

The Information Security Compliance Manager is responsible for developing, implementing, and maintaining an enterprise-wide compliance program for PCI DSS, SOC 2 Type II, FISMA, and other compliance expectations as needed. This role bridges technical security controls with regulatory requirements, ensuring that systems and processes protecting cardholder data, customer data, patient data and federal information are secure and auditable.

Requirements

  • 5+ years of experience in IT compliance, information security, or auditing, with specific experience managing PCI and SOC 2/FISMA.
  • Deep understanding of NIST 800-53, PCI-DSS, and SOC 2 Trust Service Criteria (Security, Confidentiality, Availability).

Nice To Haves

  • CISA (Certified Information Systems Auditor), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), or PCIP/ISA (PCI Internal Security Assessor).
  • Knowledge of AWS and serverless architecture helpful
  • Exceptional analytical, organizational, and project management skills, with the ability to articulate technical security concepts to non-technical stakeholders.

Responsibilities

  • Own and lead the overall compliance roadmap for PCI, SOC 2, HIPAA, and FISMA.
  • Develop, update, and implement comprehensive information security policies, standards, and procedures.
  • Translate complex regulatory requirements (NIST 800-53 for FISMA, PCI DSS Council standards) into actionable technical and operational controls.
  • Provide regular compliance status reports, risk dashboards, and metrics to senior management and stakeholders.
  • Act as the primary point of contact for external auditors (QSAs, CPA firms) during PCI audits, SOC 2 examinations, and federal assessments.
  • Facilitate end-to-end audits, including scoping, walkthroughs, documentation gathering, and remediation tracking.
  • Perform internal gap analyses to identify vulnerabilities in security controls and initiate corrective action plans (CAPAs).
  • Monitor daily adherence to security policies (e.g., firewall configuration, access controls, log management).
  • Oversee third-party vendor risk management to ensure vendors handling data are compliant.
  • Coordinate penetration testing and vulnerability scanning (ASV scans) to identify compliance gaps.
  • Assist in development and management of training programs to ensure employees understand PCI, SOC 2, FISMA, HIPAA, and other requirements.
  • Foster a culture of security awareness, ensuring that compliance by design is integrated into development and IT operations.

Benefits

  • Competitive benefits package (details provided during interview process)
  • Paid time off and holidays
  • Professional growth opportunities within RevOne Companies
  • Collaborative, team-oriented, in-office work environment
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service