Hiring.Camp

Information Security & Compliance Associate

Jobs at

·

1 week ago

Location
Cordoba
Workplace
Onsite
Department
Legal
Seniority
Entry
Source
Personio

Description

Your mission

Indivi is a TechBio company enabling precision and personalised medicine to become a reality in neuroscience research and development. We are going through significant growth and looking for new team members who want to contribute to making our vision — making measurable what is not so — a reality.


Your profile

As an Information Security & Compliance Associate, you will be responsible for the day-to-day maintenance and continuous improvement of Indivi's Information Security Management System (ISMS) in accordance with ISO 27001, while also supporting the management and ongoing development of our Quality Management System (QMS) under ISO 13485. You will play a key role in executing the ISMS Annual Compliance Plan, maintaining security and compliance documentation within Jira and Confluence, coordinating evidence collection for audits, and supporting the identification, tracking, and remediation of security risks, vulnerabilities, and compliance actions in a fast-paced TechBio environment.


This is an onsite position that will initially be offered on a part-time basis (20 hours per week) for the first six months. Subject to satisfactory performance and business needs, the role may transition to a full-time position thereafter.


Key Responsibilities


ISMS Operations & Compliance:


  • ISMS Operations: Lead the execution of regular ISMS tasks in Jira. You will ensure that monthly controls (access reviews, backup verifications, log monitoring, etc.) are executed on time and documented.

  • Continuous Improvement (NC & CAPA): Identify process gaps, document Non-Conformities (NC), and track Corrective and Preventive Actions (CAPA) until closure.

  • Risk & Vulnerability Management: Assist the ISO in updating the Risk Register (scenario-based Risk Model). Coordinate with technical departments for the remediation of vulnerabilities identified in security scans.

  • Audit Readiness: Act as a key contributor during Internal Audits and External ISO 27001/13485 surveillance audits.

  • Documentation Governance: Manage policies and SOPs in Confluence, ensuring compliance with FDA 21 CFR Part 11 (electronic signatures).

  • Data Privacy & Governance: Support the DPO in maintaining the RoPA and coordinating DPIAs/BIAs.


Necessary Competence (education qualification):


  • Experience: 1-2 years in Information Security, IT Audit, or Quality Assurance roles.

  • Education: Degree in Computer Science, Cybersecurity, or related technical field.



Needed skills:


  • Industry-Specific Skills:

    • Solid understanding of ISO 27001:2022. and GDPR/HIPAA compliance in a TechBio environment.

    • Basic understanding of ISO 13485:2016, ICH-E6 (GCP), CSV (Computerised System Validation) and SBOM management.

  • Technical Stack:

    • Proficiency in Atlassian Suite (Jira, JSM & Confluence).

    • Familiarity with SIEM tools (Wazuh) and Vulnerability Scanners.

    • Basic knowledge of AWS Cloud security and MDM (Mosyle).

  • Soft Skills: High attention to detail (documentation rigour), analytical mindset, and ability to work in a regulated environment (GCP).

  • Languages:

    • Spanish: Native/Bilingual (for local office collaboration).

    • English: Professional working proficiency (B2/C1) for all documentation and international stakeholder communication.


What to Expect:


Your Learning & Development Path


We do not expect you to master all these responsibilities from day one. This role is designed with a long-term learning roadmap to help you build a solid foundation in TechBio compliance. You will be continuously mentored by the Information Security Manager, who will provide personalised, 1-on-1 training sessions and ongoing guidance to ensure your success and professional growth within our dual ISO 27001 and ISO 13485 environment.


Role Roadmap & Key Priorities


  • First 3 Months (Immediate Priority): Your primary focus will be driving the transition and adaptation of our ISMS documentation to align with our Quality Management System (QMS). This will involve heavy use of SoftComply Document Manager (an Atlassian Confluence add-on) to ensure all policies and procedures meet strict regulatory standards.

  • Beyond 3 Months (Long-Term Focus): Once the documentation transition is established, your core focus will shift to the operational execution of the ISMS Annual Compliance Plan, managing regular security tasks, and ensuring continuous audit readiness.

Skills

AWSGCPJiraConfluenceCybersecuritySIEMFDAComplianceHIPAAGDPRISO 27001

Similar Jobs

30

Information Security

Caci · 229 HANOVER MD, United States of America · Onsite

4 weeks ago

Sr Information Security Analyst

ServiceNow · Dublin, Ireland · Hybrid

Today

Staff Information Security Engineer - Threat Detection & Response

Visier Solutions Inc · Vancouver, BC, Canada

2 days ago

Information Security Awareness Lead

Uniphar · CityWest Office, Ireland

2 days ago

Information Security Analyst

OUCU Financial · Athens, OH · Hybrid

2 days ago

Manager, Information Security

ClickHouse · United States

2 days ago

Director of Information Security

Accertify · Itasca, IL

2 days ago

Fractional Chief Information Security Officer (Advisor Network)

Arootah · Remote · Remote

2 days ago

SR Information Security Analyst - IS-Mod

Mayo Clinic · Rochester, MN, United States, US

2 days ago

Information Security Analyst - IS-Mod

Mayo Clinic · Rochester, MN, United States, US

2 days ago

Information Security Engineer

Mayo Clinic · Rochester, MN, United States, US

2 days ago

Associate Information Security Specialist

Dept · Skopje, Zagreb, Split · Hybrid

2 days ago

Information Security Analyst

Jadin Tech · Colorado Springs, CO

2 days ago

Information Security Analyst

OUCU Financial · Athens, OH

2 days ago

Lead Information Security Analyst - BISO

Wells Fargo · 111432-TX-Las Colinas Bldg A, Irving Campus, United States of America +1

3 days ago

Information Security Engineer

Candescent · US - Georgia - Atlanta Office, United States of America

3 days ago

Information Security Analyst - Hybrid

Njm · NJM - Trenton, United States of America · Hybrid, Onsite

3 days ago

Lead Information Security Analyst Cryptography and PKI

Wells Fargo · 142019-NC-300 South Brevard, Charlotte, United States of America +3

3 days ago

Military Veteran - Tour of Duty Associate - Information Security Program Manager

Quickenloans · Detroit - One Campus Martius, United States of America

3 days ago

Information Security Analyst

Banknewport · Middletown, RI, US

3 days ago

Manager, Information Security Risk and Consulting (REMOTE)

Career Opportunities · Livonia, MI, United States of America

3 days ago

Information Security Analyst II (US)

Td · Mt Laurel - Technology Center - 17000 Horizon Way, Mount Laurel, New Jersey, United States of America +1 · Hybrid

3 days ago

Information Security Specialist - Technology Asset Governance and Risk Management (US)

Td · Mt Laurel - Technology Center - 17000 Horizon Way, Mount Laurel, New Jersey, United States of America +2 · Hybrid

3 days ago

Chief Information Security Officer

RELX Jobs · USA - Raleigh, NC (RDU), United States of America

3 days ago

Lead Information Security Analyst

Wells Fargo · 142019-NC-300 South Brevard, Charlotte, United States of America +2 · Remote, Hybrid

3 days ago

Information Security Architect

Statestreet · Quincy, Massachusetts, United States of America +4

3 days ago

Manager, Information Security Risk

FCT Careers · Oakville, ON, Canada

3 days ago

Lead Information Security Engineer - Vulnerability Management

Fifththird · Virtual - Ohio, United States of America · Remote

3 days ago

Chief Information Security Officer

Totara Learning Solutions · London, GB · Remote

3 days ago

Information Security Centre of Competence / Industrial Cyber Security and Risk Manager (m/f)

Airbus · Blagnac - Wings Campus, France

3 days ago