
Sr Compliance Specialist
- Pawtucket, RI
- $82,200-123,200 per year
- Permanent
- Full-time
- Develop, document, and maintain information security policies, procedures, and standards in alignment with regulatory frameworks (e.g., ISO 27001, NIST, SOX, GDPR, HIPAA).
- Collaborate with multi-functional teams (HR, Legal, IT, Risk Management, etc.) to ensure policies are practical, comprehensive, and aligned with business operations.
- Conduct regular reviews and updates to policies based on new compliance requirements, audit findings, or emerging risks.
- Support internal and external audit processes related to IT security compliance.
- Supervise regulatory changes and provide recommendations for policy adjustments.
- Design, complete, and be responsible for phishing simulation campaigns to proactively test and improve employee awareness and resilience against social engineering attacks.
- Analyze phishing simulation results and report findings to leadership with actionable insights and improvement strategies.
- Develop and deliver cybersecurity awareness content (emails, trainings, presentations) to promote a security-first culture across the organization.
- Develop informative materials tailored to different audiences (technical and non-technical employees).
- Assist in security risk assessments and gap analyses related to vendors.
- Maintain documentation of compliance activities, incidents, training records, and risk assessments.
- Produce clear, executive-ready reports and dashboards showing compliance status, phishing test outcomes, and awareness program efficiency.
- Bachelor’s degree in Computer Science, Information Systems, or a related field (or equivalent work experience).
- Minimum 5 years of professional experience in information security, IT compliance, risk management, or related roles.
- Solid grasp of regulatory requirements and frameworks (such as ISO 27001, NIST CSF, SOX, GDPR, HIPAA).
- Experience developing, writing, and maintaining information security policies and procedures.
- Hands-on experience crafting and running phishing simulation campaigns using security awareness platforms (e.g., KnowBe4, Proofpoint).
- Proficient in analyzing security events and human risk metrics to drive improvements.
- Good understanding of common cybersecurity threats, particularly phishing, social engineering, and insider threats.
- Excellent written and verbal communication skills, including the ability to build clear policies, training materials, and reports.
- Highly organized, diligent, and able to manage multiple initiatives simultaneously.
- Certified Information Security Auditor (CISA) or equivalent certification preferred.
- Health & Wellness: Medical, Dental, and Vision Insurance
- Time Off to Recharge: Paid Vacation & Holidays
- Financial Well-being: Generous 401(k) Match
- Life & Family Support: Paid Parental Leave
- Giving Back: Volunteer & Employee Giving Programs
- Level Up Your Skills: Tuition Reimbursement
- Exclusive Perks: Product Discounts & More!