Security Analyst (Part-Time)
IT
Amman Governorate, Jordan
The Company
wi-Q is a hospitality-tech company, leading digital guest engagement. Our technology puts the power to order and pay back into the hands of the customer. Weāre currently processing hundreds of thousands of orders a week for leading hospitality brands in over 60+ countries. Being a scaling company, weāre not burdened by a complicated company structure as such thereās ample opportunity to progress and impress. Nothing is off-limits, if thereās something that you wish to be involved in, within the business, it is welcomed. Our companyās philosophy is that the best ideas should prevail. We're looking for the most innovative and passionate people to work for an award-winning, mobile ordering software company like no other.
How We Work
We've created a culture of trust which allows us to work autonomously without fear of failure, to challenge decisions, and be heard. It empowers us to drive our own careers and to move at unparalleled speed. And because we're treading new ground, we're all mastering new skills along the way.
The Role
As a part-time Security Analyst, youāll own the recurring security, governance and compliance work that keeps wi-Qās certifications strong and our platform trustworthy as we scale. This is a half-time role, working alongside our Engineering and DevOps teams and our senior security leadership.
This isnāt a helpdesk role and it isnāt a 24/7 monitoring desk. Youāll be the driving force behind our ISO 27001, PCI DSS and Cyber Essentials Plus programmes, keeping our controls running like clockwork and our evidence audit-ready. Itās proactive,
autonomous work with a direct impact on the certifications we hold and the enterprise trust we earn.
Key Responsibilities
⢠Identity and access governance: oversee access and privileged-access reviews, and help keep our identity and credential management robust as the business grows.
⢠Third-party and supplier security: run our supplier security review programme and maintain the compliance evidence our certifications and enterprise customers require.
⢠Customer and enterprise assurance: support our sales and account teams by completing security questionnaires and responding to customer due diligence.
⢠Vulnerability and patch assurance: oversee vulnerability management, making sure findings are prioritised and driven through to resolution.⢠Secure-by-design: review new features and changes (including AI functionality) for security and data-protection impact before release, helping embed secure-by-design across product and engineering.
⢠Compliance operations: help maintain and evidence our ISO 27001, PCI DSS and Cyber Essentials Plus certifications, and keep us ahead of relevant regulatory change.
⢠Risk management: carry out security risk assessments and help maintain our risk register, working with teams across the business to manage and reduce risk.
⢠Security awareness and training: coordinate our security awareness programme and support secure-development training across the team.
⢠Resilience and incident readiness: support our incident-response exercises, business continuity and backup assurance.
⢠Documentation and governance: help keep our security policies and documentation accurate, relevant and aligned with how we operate.
⢠Data protection: support our data-protection obligations, including day-to-day data-handling practices and our responsibilities under GDPR.
⢠Reporting: provide leadership with clear visibility of our security and compliance posture, flagging risks early.
What Youāll Bring
⢠Hands-on experience running ISO 27001 ISMS operations and PCI DSS compliance, ideally in a SaaS or technology environment.
⢠A relevant qualification: ISO 27001 Lead Implementer is the strongest signal for this role (Lead Auditor a bonus), alongside something like CRISC or CompTIA Security+ at mid level, and PCIP for the PCI-specific work.
⢠Familiarity with Cyber Essentials Plus, access recertification, supplier security reviews and evidence collection.
⢠A self-starter who works autonomously, chases things to closure, and enjoys turning ad hoc controls into scheduled, evidenced ones.
⢠A clear communicator who can work well with engineers, HR and an external virtual CISO.
⢠A pragmatic, data-driven mindset: you care about the control actually working, not just the paperwork looking right.
⢠Desirable: exposure to GDPR and data-protection operations, GRC tooling, and cloud environments.