Sr. Security Analyst – Control Design and Implementation Assurance

July 21, 2026

República Dominicana

Computrabajo

Sewn Products, INC. Logo Apply
Descripción

Job Description

Modality: Remote – Dominican Republic
Hours: Monday to Friday | 9:00 a.m. m. – 6:00 p.m. m.
Overview
The Sr. Security Analyst – Controls Design and Implementation Assurance is responsible for independently assessing Jostens' security posture and ensuring that security controls for systems, applications, cloud services, operational technology (OT), and physical security are properly designed, implemented, and operating effectively.
This position is part of the Governance, Risk and Compliance (GRC) team, collaborating with the IT, Engineering, Operational Technology (OT), Facilities and business teams throughout the project lifecycle to ensure that security requirements are incorporated from the initial stages. Its goal is to identify risks, validate controls, support compliance initiatives, and ensure solutions meet the organization's security standards and regulatory requirements.
Main responsibilities
Security Assurance (30%)
•\ Perform independent risk-based assessments on IT systems, applications, cloud services, OT environments, and physical security controls.
•\ Evaluate the design, implementation, and effectiveness of security controls in accordance with frameworks such as NIST, ISO 27001, PCI DSS, SOC 2, and SOX.
•\ Execute controls reviews, interviews and evidence analysis for internal and external audits.
•\ Identify security gaps, document risks, recommend remediation plans, and validate the implementation of corrective actions.
Security Design and Implementation Assurance (30%)
•\ Review security requirements during the planning, design, implementation and post-production phases of projects.
•\ Work alongside multidisciplinary teams to assess risks and confirm that security controls are implemented correctly.
•\ Verify configurations related to identity and access management, network segmentation, secure configurations, data protection and encryption, monitoring, incident response preparedness, and physical access controls.
Risk Management and GRC (20%)
•\ Perform risk assessments for new systems, major changes and technological improvements.
•\ Document risks, control gaps and remediation plans within the corporate GRC platform.
•\ Support risk treatment and acceptance processes, maintaining traceability between risks, controls, findings and corrective actions.
Regulatory Compliance (10%)
•\ Support compliance initiatives related to SOC 2, PCI DSS, SOX, and other regulatory or customer requirements.
•\ Maintain documentation and evidence ready for audits.
•\ Act as a liaison between Information Security, IT, business areas and external auditors.
Reports and Continuous Improvement (10%)
•\ Prepare executive reports, audit reports and risk assessments.
•\ Translate technical security concepts into business-oriented recommendations.
•\ Propose improvements in standards, governance processes and security assurance practices.
Requirements
•\ Bachelor's degree in Information Systems, Information Security, Business Administration, Accounting or a related area, or equivalent experience.
•\ Minimum 5 years of experience in Information Security, GRC, Technology Risk, IT Audit, Security Assurance or Risk Management.
•\ Experience performing IT controls assessments in applications, infrastructure, and cloud environments.
•\ Knowledge of frameworks and standards such as NIST, ISO 27001, PCI DSS, SOC 2 and SOX.
•\ Experience collaborating with technical teams to evaluate the design and implementation of security controls.
•\ Ability to document findings, risks and recommendations with an audit approach.
•\ Management of GRC tools for risk management, controls and incidents.
Desirable requirements
•\ Experience in security assurance, regulatory compliance, auditing or consulting.
•\ Previous experience as a Business Analyst or Systems Analyst.
•\ Knowledge of Operational Technology (OT) and physical security controls.
•\ Certifications such as CISA, CISSP, CRISC or equivalent.
•\ Experience supporting PCI DSS, SOX and SOC 2 regulated environments.
Competencies
•\ Analytical and risk management-oriented approach.
•\ Ability to work independently and influence multidisciplinary teams.
•\ Excellent written and verbal communication skills.
•\ Organization, attention to detail and focus on auditing.
•\ Ability to evaluate complex technological environments from a security assurance perspective.
Travel
•\ Availability to travel occasionally, with less than 5% of trips requiring an overnight stay.",