Security Risk & Compliance Analyst
What you'll do at Jamf:
The Security Risk & Compliance Analyst (Analyst) is responsible for ensuring that Jamf ‘s security controls, policies, and procedures are implemented in accordance with applicable laws, regulations, and industry standards. Reporting to the Director of Security Risk & Compliance, the Analyst will support the activities and improvements across the entire scope of Jamf’s Security Risk & Compliance program.
You may be required to work periodically at a Jamf office or collaborative work location with other Jamf employees in your area for certain events or moments that matter.
What you can expect to do in this role:
Conduct risk assessments in accordance with established methodology.
Collaborate with team members to evaluate cyber risk and treatment plans, and follow up to ensure appropriate action is taken to mitigate risk.
Support maintenance of security policies to ensure compliance with relevant laws, regulations, and industry standards.
Collaborate with teams across Jamf to ensure security policies are consistently implemented.
Participate in monitoring efforts to ensure compliance with the security-related policies and procedures.
Participate in external audits to ensure Jamf’s ongoing maintenance of its security certifications (i.e., ISO 27001, ISO 27701, SOC2 Type 2, StateRAMP).
Support the vendor risk management function for evaluating Jamf’s vendors and partners to identify potential risks.
Review security terms in vendor and partner contracts for consistency with Jamf’s standard annex.
Support the customer assurance process for responding to questions and questionnaires from customers, potential customers, and partners regarding security and compliance.
Review security terms in customer contracts and collaborate with security teams to ensure control requirements are implemented.
Support the security awareness training program.
Support preparation of periodic reporting for Senior Management.
Support implementation of program improvement initiatives.
#LIRemote
What we are looking for:
Minimum of 1 year of relevant experience (e.g. security operations, governance, risk management, compliance) (Required)
Familiarity with risk management methodologies, cybersecurity frameworks, and regulatory compliance (e.g. NIST, ISO 27001, ISO 27701, SOC2; StateRAMP and FedRAMP a plus) (Preferred)
Working knowledge of operating systems, networking, cloud technology, security tools
Experience in use of GRC applications a plus
Strong analytical and problem-solving skills
Excellent written/verbal communication and interpersonal skills
Ability to work collaboratively and independently, participating in multiple projects simultaneously
A practical mindset that can balance compliance and business needs
4 year / Bachelor's Degree in Computer Science or related field (Required)
Actively pursuing one or more of the following:
CGRC, CISA, CISSP, CISM, CompTIA Security+
Amazon Web Services (AWS) experience
Knowledge or security training from ISACA
A combination of relevant experience and education may be considered
SECURITY AND PRIVACY REQUIREMENTS
Participation in ongoing security training is mandatory
Established security protocols will be adhered to, sensitive data will be handled responsibly, and data protection practices are followed, including understanding relevant privacy regulations and reporting breaches
Acknowledging the Jamf Code of Conduct, where applicable security and privacy policies can be found, is a requirement of all roles at Jamf
How we help you reach your best potential:
Named a 2025 Best Companies to Work For by U.S. News
Named a 2024 Best Technology Company to Work For by U.S. News
Named one of Forbes Most Trusted Companies in 2024
Named a 2024 Best Companies to Work For by U.S. News
Our developers work in agile delivery teams to produce new features, improve software components, and are the subject matter experts for our Jamf product offerings.
You will have the opportunity to make a real and meaningful impact for more than 75,000 global customers with the best Apple device management solution in the world.
We constantly push the boundaries of technology, our developers support new innovations and OS releases the moment they are made available by Apple.
Several Jamf engineers are named in patents and with team names like CatDog, ThunderSnow and Dalek you can expect to have some fun while building cutting-edge software.
You will have the opportunity to work with a small and empowered team where the culture is based on trust, ownership, and respect.
We offer a clear career path that enables you to grow under supportive leadership and management
Visit our Jamf Engineering blog to learn more about the innovative projects our team is working on and what we learn from each challenge we solve. A blog written by engineers, for engineers at medium.com/jamf-engineering
22 of 25 world’s most valuable brands rely on Jamf to do their best work (as ranked by Forbes).
Over 100,000 Jamf Nation users, the largest online IT community in the world.
Pay Transparency
At Jamf, base pay is one part of our total compensation package and is set within a defined range. These ranges can vary based on hiring location. Where an individual's pay falls within that range depends on several factors, including role scope, location, budget, skills, experience, and qualifications. This approach helps ensure fair, competitive pay and provides room to grow as you develop in your role.
The national pay transparency range below represents all U.S. locations and accounts for geographic differences in pay, resulting in a broader range.
National Pay Transparency Range
$85,100—$154,420 USD