Internal Audit & Compliance Manager

Posted 1 day ago

This is a fully remote position, open to applicants in Colombia.

📋 Description

• Oversee the daily operations of Otonomee’s governance, risk, and compliance programs.

• Ensure a robust and scalable control environment as the organization enhances its technology, data, and AI capabilities.

• Create and manage a structured internal audit program covering ISO 27001, PCI DSS, SOC 2, along with other frameworks such as HIPAA and HITRUST.

• Offer independent assurance regarding control effectiveness and compliance status to the CTO, CEO, and senior leadership.

• Maintain ongoing audit readiness and coordinate external audits and certification processes comprehensively.

• Serve as the primary liaison for auditors.

• Conduct risk assessments utilizing risk-based methodologies; develop and monitor Key Risk Indicators (KRIs) and mitigation strategies.

• Collaborate with business process owners and technical teams to address control deficiencies and audit findings.

• Advise stakeholders and leadership on compliance shortcomings, risks, business implications, and practical remediation strategies.

• Prepare and deliver compliance reports for leadership, the board, auditors, clients, and regulatory bodies.

• Conduct third-party and vendor risk assessments and continuous monitoring.

• Manage security questionnaires and RFP compliance responses, supporting client-facing assurance via the Trust Centre.

• Lead initiatives to raise information security awareness and enhance the compliance culture.

• Act as the ISMS Coordinator, responsible for the ISO/IEC 27001 ISMS and its ongoing enhancement.

• Operate and manage the Drata GRC platform, including integrations, control mapping, automated evidence collection, alerts, and policy management.

• Cross-map controls across ISO 27001, SOC 2, PCI DSS, and other frameworks.

• Manage the roadmap for frameworks being pursued, including HIPAA and HITRUST.

• Oversee the SOC 2 program aligned with the Trust Services Criteria.

• Maintain the lifecycle of policies and procedures, which includes drafting, version control, review schedules, and employee acknowledgments.

• Manage audit evidence and compliance documentation.

• Enforce information security policies and ensure that incidents and control weaknesses are escalated and resolved.

• Report to the CTO regarding security program delivery and technical oversight, while maintaining an independent assurance line to the CEO.


⛳️ Requirements

• Established experience (typically 8+ years) in internal audit, GRC, or information security compliance, particularly in regulated environments.

• Direct experience in implementing and operating an ISO/IEC 27001 ISMS, including gap assessments and remediation strategies.

• Familiarity with SOC 2 and its Trust Services Criteria, along with practical evidence and control operation experience or a clear path toward it.

• Concrete PCI DSS compliance experience: evidence validation, control documentation, and audit follow-up.

• Proven internal audit expertise, preferably with a recognized internal auditor qualification.

• Experience with a GRC or compliance-automation platform (e.g., Drata or similar).

• Strong understanding of risk-based methodologies, KRIs, control effectiveness evaluation, and evidence management.

• Experience working remotely with distributed, cross-functional teams in a global context.

• Data protection/privacy experience (e.g., GDPR or similar) and awareness of financial crime/AML-CTF contexts is a plus.

• Familiarity with HIPAA, HITRUST, NIST CSF/RMF, or other security and healthcare frameworks is beneficial.

• Capability to act as the primary accountable owner of a cross-framework compliance program.

• Ability to exercise objective, independent judgment and provide straightforward assurance.

• Proficient in conveying compliance status clearly to leadership, auditors, and clients.

• Skillful in translating framework requirements into practical, operational controls.

• Ability to balance control rigor with the pace and realities of a growing operation.

• Detail-oriented, evidence-driven, and methodical approach.

• Quick to familiarize with new compliance frameworks.

• Proactively enhance skills and stay updated with evolving regulations, controls, and audit expectations.


🏝️ Benefits

• A competitive salary.

• Comprehensive benefits package.

• Equipment provided for work purposes.

• Home office allowance.

• Access to an Online Gym and Wellbeing Studio.

• Opportunities for professional growth.

• Enjoyable company events and team outings.

• Autonomy and responsibility in the role.

People also viewed

Consertus9 hours ago

Construction Compliance Specialist

US flagUnited States OnlyFull-timeCompliance
ApplyView job
Cartpanda11 hours ago

Mid-Level Privacy and Data Protection Analyst

BR flagBrazil OnlyFull-timeCompliance
ApplyView job
Syneos Health13 hours ago

Regulatory Publishing Manager, LATAM

Latin AmericaFull-timeCompliance
ApplyView job
Ardent13 hours ago

Governance, Risk, and Compliance Analyst

US flagFlorida OnlyFull-timeCompliance
ApplyView job
Syneos Health13 hours ago

Senior Regulatory CMC Consultant - Small Molecule, Veeva RIM

AR flagArgentina, +4 more countriesFull-timeCompliance
ApplyView job
TTM Technologies13 hours ago

Export Compliance

US flagCalifornia OnlyFull-timeCompliance$71.8k – $119.6k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers