About the Role
The role involves overseeing security controls, maintaining compliance frameworks, conducting audits, and supporting risk assessments across systems and processes.
Responsibilities
- Monitor and enforce security control frameworks across internal systems
- Conduct regular audits to verify compliance with regulatory standards
- Maintain documentation for security policies and control implementations
- Support internal and external audit processes with accurate records
- Identify gaps in compliance and recommend corrective actions
- Collaborate with IT teams to ensure secure configuration of infrastructure
- Assist in risk assessment activities for new and existing projects
- Track and report on key security compliance metrics
- Ensure adherence to data protection regulations and privacy laws
- Evaluate third-party vendors for security and compliance posture
- Update control documentation in response to system changes
- Participate in incident response activities related to compliance failures
- Develop training materials on compliance requirements for staff
- Stay current with evolving regulatory requirements and industry standards
- Coordinate with legal and compliance teams on policy alignment
- Perform control testing to validate effectiveness
- Support certification efforts for standards such as ISO or SOC 2
- Manage access review processes for critical systems
- Escalate compliance risks to management when necessary
- Maintain an inventory of compliance-related assets and controls
- Contribute to the development of security awareness programs
- Review change requests for compliance impact
- Ensure logging and monitoring practices meet control requirements
- Work with development teams to integrate compliance into SDLC
- Provide input on compliance aspects of contracts and agreements
Compensation
Competitive salary based on experience
Work Arrangement
Hybrid work model with flexible remote options
Team
Collaborative team within the information security department
Why Join Us
- Opportunities to shape the security compliance program in a growing tech organization
- Supportive culture that values transparency, innovation, and personal development
Technology Stack
- Use of modern GRC platforms for compliance tracking
- Cloud infrastructure with integrated security monitoring tools
- Automation for control testing and reporting workflows
Available for qualified candidates