
Compliance Program Analyst (Mid-level)
Posted Aug 8

Posted Aug 8
This is a fully remote position, open to applicants in Brazil.
• Collaborate with IT product teams, security and risk management sectors, QMS stakeholders, and both internal and external auditors.
• Aid teams in sustaining compliance and ensuring audit preparedness.
• Execute audits and authenticate evidence from the initial preparation stage through to remediation.
• Assess ITGC controls, which encompass access controls, change management, operations, SDLC, and resilience.
• Evaluate the design and operational effectiveness of controls.
• Assist or conduct QMS control testing across global and territory-specific frameworks.
• Interpret standards, guide teams in implementing information security policies, and validate adherence to compliance.
• Recognize and elevate compliance and operational risks within the scope of a portfolio.
• Bachelor's degree in Business Administration, Information Technology, Information Security, Risk Management, or a related discipline.
• 2–4 years of experience in compliance, IT audit, ITGC testing, QMS evaluation, or risk management.
• Strong knowledge of SOC 2, ISO 27001, and 7216 standards.
• Experience in executing audits and validating evidence from preparation to remediation.
• Demonstrated expertise in validating ITGC controls: access, change management, operations, SDLC, and resilience.
• Background in supporting or conducting QMS control testing.
• Practical understanding of information security policies and control frameworks, ideally PwC ISP.
• Capability to identify and escalate compliance and operational risks.
• Proficiency with control frameworks: SOC 2, ISO 27001, 7216, and ISP.
• Familiarity with ITGC and QMS testing methodologies: walkthroughs, sampling, re-performance, and inspection.
• Knowledge of vulnerability scanning tools, pentest evidence review, and security monitoring systems.
• Skilled in Microsoft Office, evidence-management platforms, GRC tools, and compliance reporting/dashboard tools.
• Understanding of access control systems, identity management, encryption standards, and change management workflows.
• Awareness of global and territory-specific regulatory and quality management standards.
• Preferred certifications include CISA, CRISC, ISO 27001 Lead Auditor, ISO 42001, or other QMS-related certifications, as well as training or certifications specific to ITGC.
• Competitive salary and performance-based bonuses.
• Comprehensive health and wellness benefits.
• Opportunities for professional development and career advancement.
• Flexible work arrangements and a supportive work environment.
Bart & Associates, Inc.
National Registry of Emergency Medical Technicians
Snowbird Agility, Inc.
IronArch Technology
Get handpicked remote jobs straight to your inbox weekly.