Senior Cybersecurity / GRC Professional
- Remote (Latin America-based)
- Compensation: To be defined based on experience
- Full-time contractor
- Schedule: Flexible, with overlap preferred with Central Time
- Tech Stack: SOC 2, NIST, Microsoft Defender, security policies and compliance documentation
At Near, we connect top talent in Latin America with exciting remote opportunities at U.S.-based companies. Our mission is to create better lives by fostering a remote work culture that transcends borders.
About the Company:
Our client, NovaSpect, is a U.S.-based company seeking to strengthen its cybersecurity compliance and governance capabilities. The company is focused on maintaining a strong security posture, supporting customer security requirements, and improving documentation and audit readiness.
About the Role:
We’re looking for a senior, hands-on Cybersecurity / GRC Professional to support SOC 2 compliance, audit readiness, security documentation, and customer cybersecurity questionnaires. This role requires someone who can take ownership, work independently, communicate clearly with internal stakeholders, and produce polished customer- and executive-facing materials.
You Will:
- Support the active SOC 2 audit through evidence collection, audit support, and remediation tracking.
- Organize, update, and maintain security policies, standards, procedures, and compliance documentation.
- Prepare and respond to customer cybersecurity questionnaires and technical due-diligence requests.
- Coordinate with internal stakeholders to gather accurate technical and security information.
- Conduct risk assessments and support third-party/vendor security reviews.
- Create and maintain cybersecurity metrics, KPIs, and reporting.
- Support incident-response documentation and related governance activities.
- Help improve Microsoft Defender security posture.
- Support phishing campaigns, cybersecurity awareness initiatives, and internal security communications.
About You:
Your Background:
- 5+ years of experience in cybersecurity, GRC, security compliance, audit support, or a related field.
- Strong hands-on SOC 2 experience, including evidence collection, audit support, and compliance documentation.
- Strong knowledge of the NIST framework and cybersecurity controls.
- Experience with customer security questionnaires and technical due diligence.
- Experience creating and maintaining security policies, procedures, and standards.
- Strong understanding of cybersecurity risks, risk assessments, and vendor security reviews.
- Excellent written communication skills, including drafting customer-facing and executive-facing responses.
- Clear English communication skills, both written and verbal.
- Self-directed and proactive, with the ability to manage priorities and work through ambiguity.
- Detail-oriented and able to deliver high-quality documentation under time-sensitive conditions.
Nice to Have:
- ISO 27001 awareness or experience.
- Experience in IT/OT environments.
- Experience with Microsoft Defender.
- Experience running phishing simulations or cybersecurity awareness training.
- Experience with cybersecurity metrics, KPIs, and reporting.
- Experience with incident-response governance documentation.
Compensation & Benefits:
- Compensation: To be defined based on experience.
- Benefits: Managed through Near, including PTO, payroll, and applicable benefits.
- Flexible work schedule with autonomy and reasonable overlap with Central Time.
Ready to apply?
Sign in or create your near profile in under a minute.