
Internal Audit & Compliance Manager
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Colombia.
• Oversee the daily operations of Otonomee’s governance, risk, and compliance programs.
• Ensure a robust and scalable control environment as the organization enhances its technology, data, and AI capabilities.
• Create and manage a structured internal audit program covering ISO 27001, PCI DSS, SOC 2, along with other frameworks such as HIPAA and HITRUST.
• Offer independent assurance regarding control effectiveness and compliance status to the CTO, CEO, and senior leadership.
• Maintain ongoing audit readiness and coordinate external audits and certification processes comprehensively.
• Serve as the primary liaison for auditors.
• Conduct risk assessments utilizing risk-based methodologies; develop and monitor Key Risk Indicators (KRIs) and mitigation strategies.
• Collaborate with business process owners and technical teams to address control deficiencies and audit findings.
• Advise stakeholders and leadership on compliance shortcomings, risks, business implications, and practical remediation strategies.
• Prepare and deliver compliance reports for leadership, the board, auditors, clients, and regulatory bodies.
• Conduct third-party and vendor risk assessments and continuous monitoring.
• Manage security questionnaires and RFP compliance responses, supporting client-facing assurance via the Trust Centre.
• Lead initiatives to raise information security awareness and enhance the compliance culture.
• Act as the ISMS Coordinator, responsible for the ISO/IEC 27001 ISMS and its ongoing enhancement.
• Operate and manage the Drata GRC platform, including integrations, control mapping, automated evidence collection, alerts, and policy management.
• Cross-map controls across ISO 27001, SOC 2, PCI DSS, and other frameworks.
• Manage the roadmap for frameworks being pursued, including HIPAA and HITRUST.
• Oversee the SOC 2 program aligned with the Trust Services Criteria.
• Maintain the lifecycle of policies and procedures, which includes drafting, version control, review schedules, and employee acknowledgments.
• Manage audit evidence and compliance documentation.
• Enforce information security policies and ensure that incidents and control weaknesses are escalated and resolved.
• Report to the CTO regarding security program delivery and technical oversight, while maintaining an independent assurance line to the CEO.
• Established experience (typically 8+ years) in internal audit, GRC, or information security compliance, particularly in regulated environments.
• Direct experience in implementing and operating an ISO/IEC 27001 ISMS, including gap assessments and remediation strategies.
• Familiarity with SOC 2 and its Trust Services Criteria, along with practical evidence and control operation experience or a clear path toward it.
• Concrete PCI DSS compliance experience: evidence validation, control documentation, and audit follow-up.
• Proven internal audit expertise, preferably with a recognized internal auditor qualification.
• Experience with a GRC or compliance-automation platform (e.g., Drata or similar).
• Strong understanding of risk-based methodologies, KRIs, control effectiveness evaluation, and evidence management.
• Experience working remotely with distributed, cross-functional teams in a global context.
• Data protection/privacy experience (e.g., GDPR or similar) and awareness of financial crime/AML-CTF contexts is a plus.
• Familiarity with HIPAA, HITRUST, NIST CSF/RMF, or other security and healthcare frameworks is beneficial.
• Capability to act as the primary accountable owner of a cross-framework compliance program.
• Ability to exercise objective, independent judgment and provide straightforward assurance.
• Proficient in conveying compliance status clearly to leadership, auditors, and clients.
• Skillful in translating framework requirements into practical, operational controls.
• Ability to balance control rigor with the pace and realities of a growing operation.
• Detail-oriented, evidence-driven, and methodical approach.
• Quick to familiarize with new compliance frameworks.
• Proactively enhance skills and stay updated with evolving regulations, controls, and audit expectations.
• A competitive salary.
• Comprehensive benefits package.
• Equipment provided for work purposes.
• Home office allowance.
• Access to an Online Gym and Wellbeing Studio.
• Opportunities for professional growth.
• Enjoyable company events and team outings.
• Autonomy and responsibility in the role.
Consertus
Cartpanda
Syneos Health
Ardent
Get handpicked remote jobs straight to your inbox weekly.