Because you belong at Twilio
The Who, What, Why & Where
The Senior Information Security Compliance Analyst will be a key member of the Security Compliance Assurance program at Twilio focused primarily on engagement & compliance activities related to enhancing Twilios Compliance posture & supporting internal assessments & certification activities.
This individual will be responsible for working effectively with numerous cross-functional stakeholders across the company (Legal, Finance, IT, HR, Security, Product groups etc.) to engage on all aspects of control & process design, testing, implementation, monitoring, project management, documentation & remediation activities as needed.
Twilio is looking for a leader who lives the Twilio Magic & has a broad knowledge of IT controls & compliance activities. They also have:
- 3+ years of Compliance or Audit experience working with Industry regulations & standards with a focus on (PCI, GDPR, ISO/IEC 27001, HIPAA, FEDRAMP).
- Minimum of 2 years of relevant FedRAMP Compliance working experience.
- Familiarity with compliance & risk management frameworks, such as FedRAMP, SOC2, SOX, ISO/IEC 27001, PCI, GDPR, Cloud Computing Security Requirements Guide (SRG)
- Experience & familiarity with HITRUST implementation & certification
- Experience & familiarity with cloud data security & working with public cloud solutions (AWS)
- Demonstrate strong project management skills with experience managing & reporting on multiple inflight projects at any one given time
- Demonstrate strong verbal & written communication skills as well as strong analytical & problem solving abilities
- Strong ability to represent data in graphical form
- CISA, CISM, GIAC, CISSP or other Information Security related designation required
As a Senior Information Security Compliance Analyst, you will live the Twilio Magic values:
- NO SHENANIGANS: Serve as a key member of the companys Information Security Compliance program by supporting ongoing compliance activities & monitoring efforts across different regulations (GDPR, PCI, SOC 2, ISO/IEC, HIPAA, FedRAMP, etc.).
- WRITE IT DOWN: Create & maintain technical documentation related to FIPS 199, NIST SP 800-37, NIST SP 800-53 REV 4, FISMA A&A, & continuous monitoring, & POA&M management.
- EMPOWER OTHERS: Support evidence collection, & documentation in support of internal & external audits.
- WRITE IT DOWN: Engage with subject matter experts in order to develop, edit, & revise documentation including standard operating procedures, system security plans, & policies & procedures.
- BE AN OWNER: Manage timelines, project plans, status reports & statistics to ensure milestones, goals & commitments are met.
- Manage internal & external assessment against Twilios information systems, services, & teams.
- Review existing IT compliance controls for regulatory updates against FSSC, FFIEC, GLBA, & NIST frameworks.
This role will play a very important part in helping to establish & mature the control environment at Twilio resulting in an enhanced Security Compliance posture, greater Customer Trust & increased revenue for the company.
Twilio is a company that is empowering the worlds developers with modern communication in order to build better applications. Twilio is truly unique; we are a company committed to your growth, your learning, your development & your entire employee experience. We only win when our employees succeed & we're dedicated to helping you develop your strengths. We invest in weeks dedicated to tackling hard problems & creating your own ideas. We have a cultural foundation built on diversity, inclusion & innovation & we want you & your ideas to thrive at Twilio.
We employ diverse talent from all over the world & we believe great work can be done anywhere. Around the world, Twilio offers benefits & perks to support the physical, financial, & emotional well being of you & your loved ones. No matter where you are based, you will experience a company that believes in small teams for maximum impact; seeks well-rounded talent to ensure a full perspective on our customers experience, understands that this is a marathon, not a sprint; that continuously & purposefully builds an inclusive culture that empowers everyone to do their best work & be the best version of themselves.
Millions of developers around the world have used Twilio to unlock the magic of communications to improve any human experience. Twilio has democratized communications channels like voice, text, chat, video & email by virtualizing the worlds communications infrastructure through APIs that are simple enough for any developer to use, yet robust enough to power the worlds most demanding applications. By making communications a part of every software developers toolkit, Twilio is enabling innovators across every industry from emerging leaders to the worlds largest organizations to reinvent how companies engage with their customers.