HashiCorp Logo

HashiCorp

Sr. Compliance Specialist

Posted 5 Days Ago
Be an Early Applicant
Bengaluru, Karnataka
Expert/Leader
Bengaluru, Karnataka
Expert/Leader
The Senior Compliance Specialist will lead compliance efforts by executing controls, conducting audits, facilitating user access reviews, and tracking remediation plans. Responsibilities include monitoring compliance frameworks, documenting processes, and overseeing security training and controls testing.
The summary above was generated by AI

Senior Compliance Specialist (Security GRC) 

About the Role 

We are looking for a Senior Compliance Specialist (Security GRC) to join the Security GRC team at HashiCorp. In this role you will focus on leading efforts to execute/facilitate ongoing compliance controls and processes, including performing user access reviews, tracking gaps and remediation plans, following up on overdue security training, and others. You will also perform controls testing and internal audits, and work with teams on control rollout and validation as needed.

We are looking for a self-motivated individual who thrives in a fast-paced environment, can seamlessly drive efforts across multiple projects, and work with various stakeholders. 

Security at Hashicorp is a remote team. While prior experience working remotely isn’t required, we are looking for team members who can perform well given a high level of independence and autonomy. 


In this role, your responsibilities will include: 

  • Monitoring and tracking of control exceptions, if applicable, for timeliness of remediation 
  • Monitoring and tracking of approved policy exceptions, if applicable, for upcoming expiration dates, performing outreach 30-60 dates before expiration. 
  • Perform internal audits, including the annual ISO internal audit
  • Perform targeted and ongoing controls testing, and identifying opportunities for automation
  • Document the scope/boundaries of the compliance program (cloud accounts, repositories, Github teams, etc.) including updates, removals and additions. 
  • Help drive the maturity of HashiCorp’s Common Controls Framework
  • Identify opportunities to automate manual tasks, including continuous monitor of controls and audit evidence collection
  • Drive the initiation and completion of User Access Reviews (UARs) on a quarterly basis 
  • Collect and report on metrics and data related to GRC processes, including access reviews and exceptions
  • Monitoring of Security Awareness Training (SAT) and Secure Development Training for completion, and following up on incomplete and overdue training
  • Support making changes to the controls framework using Github
  • Help develop and document minimum control test procedures for each control in the controls framework
  • Perform reviews of mappings in the controls framework to associated materials, such as the Security Policy, Security Exhibit, etc. upon changes being made to those materials 
  • Support the development of audit documentation such as prep agendas, walkthrough agendas, etc.
  • Support and perform other GRC work and initiatives as assigned and needed


Must have qualifications

  • Minimum of 8 years of related professional security, risk and compliance experience
  • Previous experience in a cloud environment, preferably AWS and/or Azure
  • Advanced level knowledge either SOC 2 or ISO 27001
  • Comfortable working with both deeply technical and non-technical people 
  • Flexible in daily hours (e.g., willingness to work longer hours during end of quarter and peak periods, and audit) 
  • Highly responsive 
  • Ability to prioritize and track multiple projects and tasks in parallel

Desired Qualifications

  • Experience working in a large, multi-cloud environment
  • Deep understanding of common security compliance frameworks, attestations and certifications
  • Previous experience at a technology or SaaS company in a similar role 
  • Experience working with OSCAL 

    LI-AD1

    #LI-Hybrid

Top Skills

AWS
Azure

Similar Jobs

Be an Early Applicant
18 Days Ago
Bengaluru, Karnataka, IND
6,000 Employees
Senior level
6,000 Employees
Senior level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
The Regulatory Compliance & Documentation Specialist will focus on developing and maintaining documentation for retail risk models, ensuring compliance with Basel III/IV regulations, and addressing regulatory compliance issues. The role requires expertise in regulatory guidelines and strong documentation skills to support audits and reviews.
Be an Early Applicant
15 Days Ago
South, Lingarajapura, Bangalore, Karnataka, IND
3,753 Employees
Senior level
3,753 Employees
Senior level
Consulting
The Lead Compliance Specialist will design and maintain a data governance framework, ensuring compliance with various regulations and standards. Responsibilities include monitoring data quality, collaborating with cross-functional teams, and assisting with compliance audits and contract reviews.
Be an Early Applicant
16 Days Ago
Karpura, Bangalore, Karnataka, IND
6,539 Employees
Senior level
6,539 Employees
Senior level
Healthtech • Pharmaceutical • Manufacturing
As a Trade Compliance IT Specialist, you will work on exiting TSA’s, engage in blueprinting for an ERP system, support Go-Live activities, and ensure global standardization of business processes, leveraging your SAP GTS expertise.

What you need to know about the Bengaluru Tech Scene

Dubbed the "Silicon Valley of India," Bengaluru has emerged as the nation's leading hub for information technology and a go-to destination for startups. Home to tech giants like ISRO, Infosys, Wipro and HAL, the city attracts and cultivates a rich pool of tech talent, supported by numerous educational and research institutions including the Indian Institute of Science, Bangalore Institute of Technology, and the International Institute of Information Technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account