
Compliance Manager
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in United States.
• Take ownership of the company's compliance program encompassing SOC 2, GDPR, ISO 27001, Cyber Essentials Plus, and other security, privacy, and governance frameworks.
• Oversee all stages of external audits, certifications, and annual compliance evaluations.
• Create, sustain, and continually enhance security policies, standards, procedures, and internal controls.
• Collaborate with engineering and security teams to implement, document, and validate technical, administrative, and operational controls.
• Manage evidence gathering, audit preparedness, and ongoing compliance initiatives utilizing GRC platforms and internal tools.
• Organize enterprise risk assessments and monitor remediation efforts until successful completion.
• Handle third-party risk management, which includes vendor security assessments and due diligence.
• Address customer security questionnaires, assist in enterprise procurement procedures, and uphold customer trust documentation.
• Develop and manage customer-facing compliance resources, including trust portals, security documentation, and compliance artifacts.
• Track developments in global privacy and security regulations, suggesting policy and control updates as requirements change.
• Aid in the development and operationalization of AI governance practices in line with emerging regulations and industry frameworks, such as the EU AI Act and NIST AI Risk Management Framework.
• Create compliance metrics, dashboards, and executive reports to convey organizational risk and program maturity.
• Provide security awareness and compliance training throughout the organization.
• Work alongside engineers, analysts, and leadership to integrate compliance into product development, infrastructure, and business operations.
• Act as the primary internal subject matter expert for compliance and governance initiatives.
• Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, Risk Management, Law, or a related discipline.
• Over 5 years of experience in compliance, information security, governance, risk management, or audit.
• Proven experience in owning or managing SOC 2 compliance programs and conducting external audits.
• Strong comprehension of GDPR and contemporary data privacy requirements.
• Experience in implementing and maintaining security controls that align with frameworks such as ISO 27001, NIST CSF, CIS Controls, HIPAA, or similar.
• Familiarity with cloud environments such as Amazon Web Services (AWS) or Google Cloud Platform (GCP).
• Experience utilizing Governance, Risk, and Compliance (GRC) platforms such as Vanta, Drata, Secureframe, or similar tools.
• Background in supporting customer security reviews and enterprise procurement processes.
• Strong project management capabilities with the ability to handle multiple initiatives concurrently.
• Exceptional written and verbal communication skills for both technical and non-technical audiences.
• Outstanding organizational skills and meticulous attention to detail.
• Salary Range: $105K–$125K, based on experience and location.
• Bonus: Performance-based annual bonus.
• Professional Development: Support for attending conferences, continuing education, and obtaining professional certifications.
• Work Environment: Fully remote, U.S.-based.
• Health Benefits: Comprehensive health, dental, and vision coverage.
• Time Off: Generous PTO and paid holiday schedule.
• Retirement: 401(k) plan.
Johnson & Johnson
Johnson & Johnson
Epic Staffing Group
Get handpicked remote jobs straight to your inbox weekly.