Information Security Operations Specialist

QuantifindPalo Alto, CA
Hybrid

About The Position

Quantifind is seeking an Information Security Operations Specialist to join our Information Security Operations Team in Palo Alto, California. This role involves supporting risk assessments of business and technical processes and systems within a fast-paced, Agile environment with regular compliance milestones. The specialist will work on a SaaS platform that helps financial institutions and government agencies combat money laundering, fraud, and criminal networks. The company utilizes AI and data science to uncover risk signals from various data sources, offering a consumer-grade user experience. The role requires collaboration with engineers and data scientists to translate technical expertise into auditor-understandable content, and contributing to the internal control environment for technology risk management and regulatory compliance.

Requirements

  • Bachelor’s degree in a technical field
  • 3+ years of experience in a security compliance role
  • Professional audit and/or information security certification (CISA, CISSP, CRISC, CISM)
  • Outstanding technical writing and verbal communication skills
  • Great interpersonal skills for mapping between business and technical stakeholders, both inside and outside of your organization
  • Thorough understanding of IT security principles and procedures
  • Professional experience evaluating the various risks and requisite controls associated with multi-tenant SaaS architectures
  • Professional experience with SOC 2 or PCI controls and evidence submission to auditors
  • Professional experience using NIST frameworks and ISO 27001
  • Professional experience with Data Privacy compliance concepts and requirements including GDPR, CCPA, and CPRA
  • Familiar with the risk assessment process from intake to completion
  • Professional experience creating, reviewing and making necessary updates to technical security policies and procedures
  • Professional experience interviewing technical subject matter experts to generate the content for responding to complex security compliance questionnaires
  • Professional experience in technical writing about network architecture, including writing narratives and annotations
  • Professional experience with customer and vendor management
  • Conversant with evolving cybersecurity best practices
  • Professional experience with formal SDLC and change control policies
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future

Nice To Haves

  • Experience with JIRA and Confluence is strongly preferred
  • Familiarity with Drata or another security assurance platform is a plus
  • Some exposure to CMMC and FISMA is a plus
  • A team player who succeeds in a collaborative environment
  • Able to work independently and can self-prioritize across multiple ongoing initiatives

Responsibilities

  • Support risk assessments of business and technical processes and systems.
  • Ask Engineers and Data Scientists questions and convert their subject matter expertise into technical content an auditor will understand.
  • Annotate diagrams showing Layer 2 switching and Layer 3 routing, network segmentation using VLANs, or secure data transfer and storage.
  • Add to and maintain an internal control environment which enables us to manage our technology risk and comply with our regulatory obligations while supporting the rapid growth and development objectives of the business.
  • Evaluate the various risks and requisite controls associated with multi-tenant SaaS architectures.
  • Submit evidence for SOC 2 or PCI controls to auditors.
  • Use NIST frameworks and ISO 27001.
  • Understand Data Privacy compliance concepts and requirements including GDPR, CCPA, and CPRA.
  • Participate in the risk assessment process from intake to completion.
  • Create, review, and make necessary updates to technical security policies and procedures.
  • Interview technical subject matter experts to generate content for responding to complex security compliance questionnaires.
  • Write technical documentation about network architecture, including narratives and annotations.
  • Manage customer and vendor relationships.
  • Stay conversant with evolving cybersecurity best practices.
  • Adhere to formal SDLC and change control policies.

Benefits

  • Competitive salary
  • Company Equity
  • Exceptional benefits package
  • Flexible Vacation & Paid Time Off
  • Employer-matched 401(k) plan
  • A fun environment where work-life balance is valued
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service