
IT Compliance Specialist
Posted Jun 24

Posted Jun 24
This is a fully remote position, open to applicants in Brazil.
• Take charge of the SOC 2 compliance program, focusing on continuous monitoring, audit preparation, evidence collection, and control tracking.
• Manage Vanta as the principal compliance automation tool, which requires some refinement; you will receive support from the CTO and a part-time consultant to assist you in this process.
• Perform regular access reviews across all systems, ensuring that all documentation is thorough and accurate.
• Organize tabletop exercises and scenario-based drills that address potential events such as AWS regional outages, cyber incidents, or availability failures, including planning, execution, and outcome documentation.
• Oversee vendor relationships, including the Vanta contract, pentester engagements, and third-party security assessments.
• Create, maintain, and enhance information security policies, procedures, and documentation.
• Assume responsibility for corporate device management across a diverse fleet of macOS, Linux, and Windows machines.
• Implement centralized MDM controls such as encryption, anti-malware, endpoint detection, and remote management for all corporate devices.
• Establish and enforce a BYOD policy for employees and contractors utilizing personal hardware for work-related tasks.
• Ensure all devices are properly enrolled and compliant before an employee's first day on the job.
• Develop repeatable onboarding and offboarding processes to ensure access and device controls are prioritized.
• Maintain security hygiene in AWS, including IAM roles, Identity Center, GuardDuty, AWS Config, and access reviews.
• Identify and address overly permissive roles, outdated credentials, and misconfigured controls.
• Collaborate with engineers to fix vulnerabilities and apply patches, fostering strong working relationships with the technical team in Caxias do Sul.
• Assist with cloud-related evidence collection for SOC 2 controls.
• Manage IT onboarding and offboarding processes, including provisioning, deprovisioning, and access controls to ensure nothing is overlooked.
• Control access across Google Workspace, Slack, GitHub, Rippling, AWS Identity Center, and other essential tools.
• Act as the primary internal IT resource and address urgent issues as they arise.
• A minimum of 3 years of experience in IT, Security, Compliance, or related fields within a SaaS company, startup, or rapidly growing technology environment.
• Demonstrated hands-on experience in managing SOC 2 Type I and/or Type II compliance programs.
• Direct experience with Vanta specifically, not just compliance platforms in a general sense, including the ability to interpret findings and drive remediation efforts.
• Experience managing devices across macOS, Linux, and Windows using MDM solutions such as JumpCloud, Jamf, Kandji, or similar tools.
• Solid understanding of AWS security and governance, encompassing IAM, Identity Center, GuardDuty, AWS Config, and best practices for access management.
• Strong grasp of identity and access management, MFA, encryption, endpoint security, and audit controls.
• Exceptionally detail-oriented; if a control is slightly incomplete or an access review has any gaps, you will identify it before the auditor does.
• Proficient English communication skills (C1 or higher) for effective collaboration with the US-based CTO and leadership team.
• Focused on execution and detail-oriented; while the CTO and a part-time consultant will support you, the daily compliance tasks require someone who is proactive and self-sufficient.
• Comfortable working in a fast-paced startup environment where you are the sole individual primarily focused on compliance.
• Equity package
• Flexible PTO policy
• Mental health benefits
• Fitness allowance
• Budget for learning and professional development
• Home office and workspace allowance
Swissquote
US Pharmacopeia
Crum & Forster
Centene Corporation
Get handpicked remote jobs straight to your inbox weekly.