
IT Compliance Manager
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in United States.
• Oversee compliance documentation, evidence repositories, and audit-ready materials across relevant frameworks such as SOC 2, ISO 27001, PCI-DSS, HIPAA, NIST CSF, and specific customer security requirements.
• Manage compliance calendars, assessment timelines, and framework documentation.
• Stay informed on regulatory, contractual, and industry changes, and relay new compliance obligations to stakeholders.
• Monitor remediation plans, corrective actions, and control deficiencies until they are resolved.
• Organize internal and external audit processes, including evidence gathering, auditor requests, and stakeholder involvement.
• Act as the main point of contact for audit coordination and compliance queries.
• Assist with control testing, risk assessments, and compliance evaluations.
• Keep track of audit findings and corrective actions until they are fully addressed.
• Help teams prepare for ongoing compliance assessments and certifications.
• Update and maintain information security policies, standards, procedures, and governance documentation.
• Facilitate regular policy reviews and updates in collaboration with business and technical stakeholders.
• Ensure governance documentation is aligned with organizational needs and compliance responsibilities.
• Promote continuous improvement initiatives concerning compliance and risk management processes.
• Organize periodic access reviews, user access certifications, and validation activities for privileged access.
• Collaborate with IT and Identity Management teams to uphold evidence for access control compliance.
• Assist in documenting, validating, and enhancing identity and access management processes.
• Coordinate responses to security questionnaires from customers, prospects, and partners.
• Support third-party risk assessments and vendor security evaluations.
• Raise identified compliance or security issues to the relevant stakeholders.
• Assist in customer-facing compliance and security assurance efforts.
• Compile compliance metrics, audit status updates, and remediation tracking for leadership review.
• Maintain dashboards and reporting tools related to compliance activities.
• Manage compliance and security awareness training programs and track completion rates.
• Aid in organizational compliance communications and awareness initiatives.
• Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Business, or a related field.
• A minimum of 4 years of experience in IT compliance, information security, governance, risk management, or audit-related roles.
• Proven experience with compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, HIPAA, NIST, or similar standards.
• Experience in coordinating audits and managing compliance documentation and evidence repositories.
• Strong skills in project management, organization, and documentation.
• Ability to prioritize multiple tasks while maintaining a keen attention to detail.
• Excellent written and verbal communication skills, capable of engaging with both technical and non-technical teams.
• Familiarity with cloud infrastructure, managed services, SaaS, web hosting, or data center environments.
• Knowledge of identity and access management concepts, access reviews, and security governance practices.
• Comprehensive benefits package
• Traditional and Roth 401(k) with company matching
• A collaborative, team-oriented culture
• Consistent and predictable work hours
• Engaging, varied work that keeps each day different
• Opportunities to contribute ideas and influence how work gets done
CVS Health
FreedomCare
Northrop Grumman
Get handpicked remote jobs straight to your inbox weekly.