Senior Security & Compliance Analyst

Salesloft Salesloft · Enterprise · Mexico · IT/Security

This role is for a Senior Security and Compliance Analyst at Salesloft, a company that uses AI to build an enterprise revenue system. The analyst will be responsible for customer-facing security and compliance matters, including responding to customer requests, managing compliance attestations, and collaborating with legal and IT teams. They will also maintain security policies, conduct third-party risk assessments, and participate in security reviews during the software development lifecycle. The role requires experience with information security controls, knowledge of standards like ISO 27001 and SOC 2, and strong documentation and analytical skills.

What you'd actually do

  1. Customer requests for information (e.g. questionnaires)
  2. Customer inquiries about compliance attestations and certifications for Clari + Salesloft and its subprocessors
  3. Customer questions regarding product functionality and the impact of that functionality on the customer environment
  4. Maintenance of the public facing Clari + Salesloft trust portal
  5. Collaborating with the legal team to address contractual issues surrounding security and privacy

Skills

Required

  • 4-6 years of experience with auditing and/or maintaining information security controls
  • Comfortable joining customer calls and speaking authoritatively without more senior team member
  • Working knowledge of ISO 27001, SOC 2 Trust Services Principles, GDPR and other common security standards
  • Experience with "defense-in-depth" principles and technology
  • Strong attention to detail and quality
  • Self-driven, autonomous and can contribute to the strategy and roadmap of the team
  • Advanced documentation, prioritization and change management skills
  • Ability to handle proprietary and sensitive information in a confidential manner
  • CISA or similar certification

What the JD emphasized

  • customer-facing security and compliance matters
  • security, privacy, and compliance concerns
  • security, privacy and compliance reviews
  • security and privacy risks
  • customer calls and speaking authoritatively
  • ISO 27001, SOC 2 Trust Services Principles, GDPR and other common security standards
  • CISA or similar certification