Compliance Manager

atduvo.aiRemoteCZ flagCzechiaFull-timeComplianceMid-levelSenior

Posted 3 days ago

This is a fully remote position, open to applicants in Czechia.

📋 Description

• Take ownership of the Q&A library aligned with ISO 27001, SOC 2, ISO 42001, NIS2, and GDPR.

• Oversee ownership, approval status, evidence links, confidentiality classifications, and review dates for the Q&A library.

• Ensure consistency throughout the Q&A library, trust center, Trust Center portal, policies, and engineering practices.

• Manage customer security reviews from the intake of questionnaires to final delivery.

• Verify unconfirmed answers in collaboration with Security, Engineering, or Product teams.

• Keep the public trust center and NDA-gated Trust portal document sets up to date.

• Conduct the annual audit and certification program, which includes SOC 2 Type II renewal, ISO 27001 and ISO 42001 surveillance, NIS2 assessment, penetration testing and retesting, as well as managing customer right-to-audit requests.

• Collect evidence and coordinate with the DPO and auditors.

• Handle audit findings, remediation efforts, and management assertions.

• Collaborate with the Security Lead to operate the ISMS and AIMS, including managing the risk register, statement of applicability, policy lifecycle, access reviews, internal audits, management reviews, and security steering cadence.

• Manage vendor policy and third-party risk processes, encompassing intake, tiering, due diligence, DPA terms, AI-provider data retention and no-training commitments, approvals, re-reviews, and offboarding.

• Oversee subprocessor reviews, customer notifications, DPA updates, and portal updates.

• Report to the Head of Engineering while collaborating daily with the Security Lead.


⛳️ Requirements

• Proven experience in managing a certification program from start to finish through an actual audit cycle, including SOC 2, ISO 27001, or an equivalent standard.

• Ability to craft precise, evidence-based, and truthful responses to security questionnaires.

• Experience in establishing or managing a third-party/vendor review process.

• Proficiency in maintaining an accurate subprocessor list in accordance with contractual notice obligations.

• Strong evidence-gathering discipline and audit preparedness.

• Good judgment regarding when to escalate issues to Engineering, Security, or Legal teams.

• Openness and capability to utilize AI tools and agents.

• Excellent plain writing skills.

• Prior experience with financial services or telecommunications buyers is advantageous.

• Familiarity with AI governance or ISO 42001 is a plus.

• Experience with GRC platforms such as Vanta, Drata, Mycroft, Segregato, or similar is beneficial.

• Experience working on the vendor side as a processor responding to controllers is an asset.


🏝️ Benefits

• Unlimited AI budget.

• Autonomy to perform at your best.

• Freedom for professional development and mentoring.

• Opportunity to travel and engage with key customers.

• Involvement with a real AI product serving genuine enterprise clients.

People also viewed

Voyager Technologies1 day ago

Director of Global Trade Compliance

US flagUnited States OnlyFull-timeCompliance$200k – $230k/year
ApplyView job
Laboratorios Médicos Colonia del Valle - Olab2 days ago

Associate Regulatory Specialist, Drinking Water

US flagNew York OnlyFull-timeCompliance$57.8k – $86.8k/year
ApplyView job
Insight IT2 days ago

Senior Consultant, Regulatory Audit and Internal Controls

BR flagBrazil OnlyFreelanceCompliance
ApplyView job
White Hat Gaming2 days ago

Compliance Analyst

ZA flagSouth Africa OnlyFull-timeCompliance
ApplyView job
TRM Labs2 days ago

Senior Manager, Contracts & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
Workstreet2 days ago

Senior GRC Engineer, Bilingual Spanish-English

PA flagPanama OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers