Governance & Compliance Security Analyst
Confidential
Posted: January 30, 2026
Interested in this position?
Create a free account to apply with AI-powered matching
Required Skills
Job Description
About EdgeUno
EdgeUno empowers the next era of digital connectivity across Latin America. With one of the region’s most interconnected data centers and network platforms, we support mission-critical workloads for enterprises, ISPs, hyperscalers, and digital platforms. Our culture is built on ownership, agility, technical excellence, and accountability.
Role Summary
The Governance & Compliance Security Analyst is responsible for maintaining and improving the company’s information security governance, ISO 27001 compliance, policies and procedures, and thirdparty risk management. This role supports audits and certifications, ensures alignment with regulatory and contractual requirements, and works closely with technical and business teams to keep the Information Security Management System (ISMS) effective and up to date.
Location & Language
Based in Quito
Advanced English required
Key Responsibilities
ISO 27001 & ISMS Management
Maintain and update the Information Security Management System (ISMS) in line with ISO/IEC 27001.
Coordinate periodic risk assessments, Statement of Applicability (SoA) updates, and treatment plans.
Support internal and external audits (preparation, evidence collection, tracking of nonconformities and corrective actions).
Policies, Standards & Procedures
Develop, review, and maintain information security policies, standards, and procedures.
Coordinate periodic reviews and approvals with management and relevant stakeholders.
Ensure documentation is aligned with ISO 27001, regulatory requirements, and business needs.
Compliance & Regulatory Support
Monitor and support compliance with applicable laws, regulations, and contractual security requirements (telecom, data protection, client demands).
Prepare and maintain evidence repositories for certifications, audits, and customer due diligence.
Support responses to security questionnaires, RFPs, and client audits.
ThirdParty Risk Management
Support the thirdparty risk management process: security assessments of vendors, service providers, and partners.
Review certifications and security documentation from third parties (e.g., ISO 27001, SOC 2).
Track identified risks and remediation actions for critical third parties and maintain an uptodate thirdparty inventory.
Documentation, Reporting & Metrics
Keep ISMS and governance documentation well organized and current.
Produce reports and dashboards on compliance status, audit results, and ISMS performance for management.
Help define and track security KPIs/KRIs related to governance and compliance.
Awareness & Support to the Business
Contribute to security awareness initiatives, especially around policies, acceptable use, and data protection.
Act as a point of contact for questions related to policies, compliance, and thirdparty security requirements.
Work closely with IT, Security Operations, Legal, HR, Procurement, and business units to ensure controls are understood and applied.
Requirements
Bachelor’s degree in Information Security, Systems Engineering, Law, Business, or related field (or equivalent experience).
2–5+ years of experience in information security, GRC (Governance, Risk & Good understanding of ISO/IEC 27001 and related standards.
Experience with security policies, procedures, and audit processes.
Familiarity with basic risk management concepts and methods.
Ability to review and interpret contracts, SLAs, and security clauses (desirable).
Strong documentation, organization, and reporting skills.
Ability to work collaboratively with technical and nontechnical teams.
Attention to detail, structured thinking, and a proactive mindset.
Nice to Have
Experience in telecom, ISP, hosting, or cloud environments.
Knowledge of data protection regulations (e.g., local privacy laws, GDPR exposure).
Certifications such as ISO 27001 Lead Implementer/Auditor, CISA, or similar.
What We Offer
Competitive compensation aligned with senior technical roles in the region
Opportunity to influence software quality standards across the organization
Strong engineering culture focused on ownership, automation, and continuous improvement
Collaborative, multicultural, execution-driven environment
A critical role in a fast-growing digital infrastructure company operating across Latin America
Note: Please submit your resume in English.