
IT Compliance Manager
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in South Africa.
β’ Take charge of Sendmarc's internal IT operations for its globally distributed, fully remote team.
β’ Provide assistance with helpdesk and device support.
β’ Manage identity and access processes, including onboarding and offboarding provisioning across essential systems.
β’ Administer tools such as 1Password, Microsoft 365, and Entra.
β’ Lead the operational program for ISO 27001 certification and the SOC 2 Type II report via Vanta.
β’ Gather evidence, oversee controls, resolve flagged issues, and collaborate directly with auditors.
β’ Ensure the Trust Centre remains accurate and up-to-date for Sales and prospective clients.
β’ Maintain the security risk register.
β’ Triage and monitor the remediation of penetration test and vulnerability scan findings until resolution.
β’ Manage the information security policy framework.
β’ Oversee access reviews and sharing permissions across key systems.
β’ Assist in third-party/vendor risk evaluations alongside the Finance team.
β’ Lead the security awareness training and phishing simulation program in collaboration with the Chief People Officer.
β’ Must reside in South Africa.
β’ Hands-on experience in IT administration: device management, identity and access management, and helpdesk/ticketing.
β’ Proficient in administering SaaS platform security settings.
β’ Working knowledge of SOC 2 and ISO 27001 frameworks and their evidence requirements.
β’ Familiarity with compliance automation tools such as Vanta, Drata, Secureframe, or similar platforms.
β’ Basic understanding of infrastructure and network security principles.
β’ Previous experience in preparing for a SOC 2 and/or ISO 27001 audit.
β’ Comfortable managing a risk register and tracking remediation items to completion.
β’ Ability to translate audit and regulatory requirements into practical internal procedures.
β’ Experience in drafting or maintaining information security policy documentation.
β’ Familiarity with the ISO 27001 clause 9 cycle, including internal audits and management reviews.
β’ Proactive in communication and issue resolution.
β’ Comfortable serving as the primary point of contact.
β’ Ownership mentality regarding IT and compliance.
β’ 3β5+ years of experience in IT management, information security, or compliance-oriented roles.
β’ Hands-on experience with SOC 2 Type II and/or ISO 27001 audits.
β’ Experience supporting a distributed, multi-country remote workforce is highly advantageous.
β’ Background in the cybersecurity industry is a plus but not mandatory.
β’ Fully remote work arrangement.
β’ Permanent employment.
LabConnect
Ripple Effect
Binance
biBerk Business Insurance
Get handpicked remote jobs straight to your inbox weekly.