Maintain and enhance the company’s Information Security Management System (ISMS) aligned to ISO 27001:2022.
Support the planning, execution, and maintenance of SOC 2 Type II controls and evidence collection.
Prepare and maintain compliance documentation (policies, procedures, guidelines, control matrices, risk registers).
Coordinate and track compliance across departments, ensuring timely closure of audit findings and corrective actions.
Act as the point of contact for internal and external audits (ISO 27001, SOC 2, customer and partner audits).
Support and manage Customer Audit activities — including responding to security and compliance questionnaires, coordinating input from multiple departments, collecting, and validating evidence, and ensuring timely and accurate responses.
Prepare structured evidence packages, liaise with control owners, and manage communications with auditors and customers.
Conduct internal control reviews and readiness assessments ahead of certification or customer audits.
Participate in regular risk assessments and reviews of security controls.
Assist in maintaining the risk register, monitoring remediation plans, and validating control effectiveness.
Coordinate and deliver security awareness initiatives for employees (e-learning, workshops, newsletters).
Promote a risk-aware culture and support departmental champions to strengthen overall security posture.
Monitor changes in applicable regulations, standards, and best practices (ISO, SOC, GDPR, etc.) and recommend updates.
Support automation and digitalization of compliance activities through GRC platforms and dashboards.
Contribute to incident and issue management reviews to ensure lessons learned are captured and controls improved.
Requirements
At least 3 years of experience in GRC, Information Security, or Audit roles.
Solid understanding of ISO 27001, SOC 2, and general IT security control frameworks (NIST, COBIT, etc.).
Strong organizational skills and ability to coordinate across departments.
Excellent written and verbal communication in English.
Experience supporting or participating in audits and compliance assessments.
Strong customer-facing and communication skills, with the ability to interact confidently with clients, auditors, and internal stakeholders.
Conceptual understanding of key security technologies such as EDR, UTM/Firewall, SIEM, and Vulnerability Management systems to evaluate related controls and compliance evidence.
Benefits
💸 Competitive remuneration package
🏝 Extra day off on your birthday
💰 Performance-based bonus scheme
👩🏽⚕️ Comprehensive private healthcare insurance
📲 💻 All the tech gear you need to work smart
🎌 Be a part of a multicultural working environment
🎯 Meet a very unique and promising business and industry
🌌 🌠 Gain insights for tomorrow market’s foreground
🎓 A solid career path within our working family is ready for you
📚 Continuous training and access to online training platforms
🥳 CSR activities and festive events within any possible occasion
🍜 Enjoy comfortable open space restaurant with varied meal options every day
🎾 🧘♀️ Wellbeing activities access such as free on-site yoga classes, plus available squash court on our premises
Manager of Privacy & Data Compliance at Constellation Brands overseeing privacy operations and ensuring data protection across teams. Collaborating with business units to maintain regulatory compliance and manage risks.
Intern assisting in packaging development for major food industry company. Contributing to compliance analysis and audits while collaborating with engineering teams.
Compliance Manager responsible for quality assurance and compliance at Nestlé's Marton Factory. Leading a team to uphold food safety and hygiene standards in a key manufacturing role.
EUDR Compliance Coordinator ensuring Kafea Terra’s compliance with EU Deforestation Regulation. Role involves collaboration across Operations, IT, Legal, Finance, Supply Chain, and Marketing teams.
Compliance Data Specialist role focused on data extraction and analysis for regulatory compliance at Kantox. Collaborating with IT and compliance teams to ensure data accuracy and support regulatory obligations.
Associate role at Kroll supporting research and due diligence in compliance. Focused on onboarding and managing risks associated with clients and third parties.
Senior Director leading AML Network Surveillance Monitoring and Regulatory Strategy for Capital One. Oversee integrated team ensuring compliance with regulatory standards and effective operations across on - shore and off - shore groups.
IT Compliance Specialist ensuring compliance with DORA and other regulations. Collaborating with IT and security teams for a secure digital environment.
Senior Compliance Risk Manager providing independent oversight of business products and compliance with NAIC regulations. Key role in ensuring adherence to legal requirements and influencing business solutions in financial services.
Senior Compliance Officer managing compliance operations for Hex Trust. Overseeing KYC, regulatory communications, and compliance activities for global expansion.