
Internal Audit & Compliance Manager
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Colombia.
• Take charge of Otonomee’s daily governance, risk, and compliance operations.
• Ensure a robust and scalable control environment as the organization enhances its technology, data, and AI capabilities.
• Develop and manage a structured internal audit programme covering ISO 27001, PCI DSS, SOC 2, and additional frameworks like HIPAA and HITRUST.
• Provide independent assurance on control effectiveness and compliance status to the CTO, CEO, and senior leadership.
• Maintain readiness for audits and manage external audit processes and certification cycles from start to finish.
• Serve as the main point of contact for auditors.
• Perform risk assessments using risk-based approaches; create and monitor Key Risk Indicators (KRIs) and mitigation strategies.
• Collaborate with business process owners and technical teams to address control deficiencies and audit findings.
• Counsel stakeholders and leadership on compliance issues, risks, business implications, and effective mitigations.
• Prepare and deliver compliance reports for leadership, the board, auditors, clients, and regulatory bodies.
• Conduct third-party and vendor risk evaluations and ongoing assessments.
• Manage security questionnaires and RFP compliance responses and assist client-facing assurance via the Trust Centre.
• Lead initiatives to enhance information security awareness and promote a culture of compliance.
• Function as the ISMS Coordinator, overseeing the ISO/IEC 27001 Information Security Management System and its continuous enhancement.
• Operate and manage the Drata GRC platform, including integrations, control mapping, automated evidence gathering, alerts, and policy management.
• Cross-reference controls across ISO 27001, SOC 2, PCI DSS, and additional frameworks.
• Oversee the roadmap for frameworks being pursued, including HIPAA and HITRUST.
• Direct the SOC 2 programme in alignment with the Trust Services Criteria.
• Manage the lifecycle of policies and procedures, including drafting, version control, review schedules, and employee acknowledgments.
• Handle audit evidence and compliance documentation.
• Enforce information security policies and ensure incidents and control deficiencies are escalated and resolved.
• Report to the CTO on security programme delivery and technical oversight while providing an independent assurance line to the CEO.
• Demonstrated experience (generally 8+ years) in internal audit, GRC, or information security compliance, particularly in regulated settings.
• Hands-on expertise in implementing and managing an ISO/IEC 27001 ISMS, including gap assessments and remediation strategies.
• Familiarity with SOC 2 and its Trust Services Criteria, backed by practical evidence and control operation experience or a clear path towards it.
• Practical experience in PCI DSS compliance: evidence validation, control documentation, and audit follow-up.
• Proven internal audit capabilities, ideally with a recognized internal auditor certification.
• Experience with a GRC or compliance automation platform (e.g., Drata or similar).
• Strong understanding of risk-based methodologies, KRIs, control effectiveness evaluation, and evidence management.
• Experience working remotely with distributed, cross-functional teams in a global context.
• Knowledge of data protection/privacy (e.g., GDPR or equivalent) and awareness of financial crime/AML-CTF contexts is advantageous.
• Exposure to HIPAA, HITRUST, NIST CSF/RMF, or other security and healthcare frameworks is beneficial.
• Capability to serve as the accountable owner of a cross-framework compliance programme.
• Ability to exercise objective, independent judgement and provide honest assurance.
• Skill in communicating compliance status clearly to leadership, auditors, and clients.
• Ability to transform framework requirements into effective operational controls.
• Capacity to balance control rigor with the demands and pace of a growing organization.
• Detail-oriented, evidence-driven, and methodical approach.
• Quick to learn new compliance frameworks.
• Proactive in upskilling and keeping up with evolving regulations, controls, and audit expectations.
• A competitive salary.
• Comprehensive benefits.
• Equipment provided for work.
• Home office allowance.
• Access to an Online Gym and Wellbeing Studio.
• Opportunities for professional development.
• Enjoyable company events and team outings.
• Autonomy and responsibility in your role.
RTX
EnergyHub
Johnson & Johnson
Johnson & Johnson
Get handpicked remote jobs straight to your inbox weekly.