
Compliance Manager
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Czechia.
• Take ownership of the Q&A library aligned with ISO 27001, SOC 2, ISO 42001, NIS2, and GDPR.
• Oversee ownership, approval status, evidence links, confidentiality classifications, and review dates for the Q&A library.
• Ensure consistency throughout the Q&A library, trust center, Trust Center portal, policies, and engineering practices.
• Manage customer security reviews from the intake of questionnaires to final delivery.
• Verify unconfirmed answers in collaboration with Security, Engineering, or Product teams.
• Keep the public trust center and NDA-gated Trust portal document sets up to date.
• Conduct the annual audit and certification program, which includes SOC 2 Type II renewal, ISO 27001 and ISO 42001 surveillance, NIS2 assessment, penetration testing and retesting, as well as managing customer right-to-audit requests.
• Collect evidence and coordinate with the DPO and auditors.
• Handle audit findings, remediation efforts, and management assertions.
• Collaborate with the Security Lead to operate the ISMS and AIMS, including managing the risk register, statement of applicability, policy lifecycle, access reviews, internal audits, management reviews, and security steering cadence.
• Manage vendor policy and third-party risk processes, encompassing intake, tiering, due diligence, DPA terms, AI-provider data retention and no-training commitments, approvals, re-reviews, and offboarding.
• Oversee subprocessor reviews, customer notifications, DPA updates, and portal updates.
• Report to the Head of Engineering while collaborating daily with the Security Lead.
• Proven experience in managing a certification program from start to finish through an actual audit cycle, including SOC 2, ISO 27001, or an equivalent standard.
• Ability to craft precise, evidence-based, and truthful responses to security questionnaires.
• Experience in establishing or managing a third-party/vendor review process.
• Proficiency in maintaining an accurate subprocessor list in accordance with contractual notice obligations.
• Strong evidence-gathering discipline and audit preparedness.
• Good judgment regarding when to escalate issues to Engineering, Security, or Legal teams.
• Openness and capability to utilize AI tools and agents.
• Excellent plain writing skills.
• Prior experience with financial services or telecommunications buyers is advantageous.
• Familiarity with AI governance or ISO 42001 is a plus.
• Experience with GRC platforms such as Vanta, Drata, Mycroft, Segregato, or similar is beneficial.
• Experience working on the vendor side as a processor responding to controllers is an asset.
• Unlimited AI budget.
• Autonomy to perform at your best.
• Freedom for professional development and mentoring.
• Opportunity to travel and engage with key customers.
• Involvement with a real AI product serving genuine enterprise clients.
Voyager Technologies
Laboratorios Médicos Colonia del Valle - Olab
Insight IT
White Hat Gaming
Get handpicked remote jobs straight to your inbox weekly.