
Head of IT Compliance
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Poland.
• Lead and sustain the organization's ISO 27001 Information Security Management System (ISMS) and SOC 2 Trust Services Criteria certification initiatives.
• Act as the main liaison for both internal and external auditors during the ISO 27001 certification and SOC 2 attestation processes.
• Organize and manage compliance audits, gather evidence, and deliver thorough audit responses.
• Oversee risk assessments, control testing, and remediation efforts.
• Create, maintain, and enforce IT security and compliance policies, procedures, and standards.
• Ensure documentation is in accordance with ISO 27001 Annex A controls and SOC 2 requirements.
• Address client security questionnaires.
• Supervise access control, change management, incident management, and vendor risk management.
• Ensure compliance in software development, hosting platforms, and APIs.
• Monitor security controls and suggest enhancements to mitigate emerging risks.
• Serve as a liaison for external auditors, regulators, and certification authorities.
• Perform internal compliance audits, gap assessments, and readiness evaluations.
• Monitor and resolve compliance findings and audit issues.
• Provide guidance on changes to ISO 27001 scope and corporate structure.
• Foster compliance awareness among development, operations, and support teams.
• Conduct training on secure software development, data management, and gaming industry standards.
• Evaluate the compliance of key vendors and ensure alignment of contracts and SLAs with ISO 27001 and SOC 2.
• Offer compliance updates, risk posture reports, client feedback, performance metrics, and KPIs to senior management and stakeholders.
• Bachelor's degree in Information Security, Computer Science, Risk Management, or a related discipline.
• Over 5 years of experience in IT compliance, GRC, risk management, or information security.
• Ideally have experience in gaming, fintech, or other regulated sectors.
• Strong knowledge of ISO 27001:2022 Information Security Management System (ISMS).
• Solid understanding of SOC 2 Trust Services Criteria.
• Proven success in leading certification and audit processes with direct engagement with auditors.
• Experience in responding to client security questionnaires and communicating compliance status effectively.
• Familiarity with SaaS/PaaS environments, APIs, and cloud hosting services.
• Knowledge of secure SDLC, DevOps, and CI/CD compliance integration.
• Preferred professional certifications include CISA, CISM, ISO 27001 Lead Implementer/Auditor, CCSK, or CRISC.
• Strong understanding of IT compliance, audit, and risk management frameworks.
• Excellent communication and stakeholder management abilities.
• Capability to influence development, operations, and support teams to adopt compliance practices.
• Analytical problem-solving skills in addressing compliance challenges.
• Attention to detail in documentation, evidence management, and client questionnaire responses.
• A highly competitive salary.
• Comprehensive training aligned with the highest industry standards.
• A friendly and supportive work culture.
• Significant growth opportunities within a large, rapidly expanding international company.
ICON plc
US Anesthesia Partners
MultiplyMii
Paychex
Get handpicked remote jobs straight to your inbox weekly.