1. External client due diligence
- Personally respond to security questionnaires/DDQs received from clients.
- Experience with custom DDQs, SIG, CAIQ, RFPs or RFIs.
- End-to-end response ownership
- Draft responses, coordinate SME inputs, obtain approvals and complete final submissions.
- Not limited to formatting documents or collecting evidence.
- Security evidence coordination
- Provide approved SOC reports, ISO certificates, penetration-test summaries and related compliance evidence.
- Understand NDA, confidentiality and approval requirements.
- Direct client service
- Solid written and verbal communication.
- Handle client questions, clarifications, deadlines and escalations professionally.
- Cross-functional coordination
- Work with Information Security, Compliance, Legal, Privacy, Technology, Sales and business teams.
- Experience level
- Approximately 5 to 8 years.
- Comfortable in a hands-on individual-contributor/specialist role.