
Principal Security Compliance Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Poland.
• Develop and take ownership of a strategic vision, roadmap, and maturity model for Hyland's enterprise ISO governance and certification initiative.
• Design governance controls that support an Integrated Management System encompassing multiple certifications, product lines, and business units on an enterprise scale.
• Oversee certification and surveillance audit processes, including audit planning, evidence management, corrective action tracking, and maintenance of certifications.
• Collaborate with external auditors and assessors to manage audit schedules, address findings, and implement corrective action plans.
• Propel the expansion of ISO scope and pursue advanced certifications such as TISAX and C5.
• Identify necessary requirements, enhance organizational capability, and coordinate implementation efforts across various teams.
• Create governance models and assign control ownership throughout teams.
• Convert ISO requirements into actionable control implementations that are integrated into business processes.
• Develop metrics, dashboards, and reporting systems to assess the health of the ISO program, IMS objectives, control effectiveness, completeness of evidence, and audit readiness.
• Counsel leadership on the compliance implications of strategic decisions.
• Provide guidance and mentorship to compliance specialists.
• Work in conjunction with product, engineering, legal, and HR teams to weave ISO requirements into business operations.
• A minimum of 8 years of progressive experience in information security compliance.
• At least 5 years serving as the primary owner or lead for ISO certification programs.
• In-depth hands-on expertise in ISO/IEC 27001, 27002, 27017, 27018, and 27701 (privacy).
• Proven experience in implementing controls across various product lines and business units.
• Direct involvement with ISO 42001 (AI governance) implementation or similar AI security governance frameworks.
• Demonstrated success in building and scaling compliance programs.
• Experience in mentoring and developing compliance teams.
• Strong comprehension of SaaS, cloud infrastructure, and product security models.
• Excellent data analysis capabilities using tools like Excel, SQL, or statistical software.
• Certifications such as CISSP, CISA, CCAK, ISO 27001 LA, LI, IA, or equivalent, along with experience in TISAX and C5 certifications.
• Ability to articulate technical security controls in business terms, foster stakeholder alignment, and influence, motivate, and mobilize team members and business partners.
• Exceptional critical thinking, analytical, and problem-solving skills.
• Strong oral and written communication abilities with an executive presence.
• Capability to develop and deliver engaging, informative, and persuasive presentations.
• Outstanding organizational, facilitation, and project management skills.
• Ability to excel in a fast-paced, deadline-oriented environment while managing sensitive information with discretion and tact.
• Fully remote work.
• Flexible working hours.
• 5 additional days off per year.
• Employee Appreciation Day.
• Floating holiday.
• Volunteer Time Off – 24 hours per year.
• Private healthcare.
• Life insurance.
• Employee Assistance Program.
• Online wellness sessions.
• Learning Management System.
• Tuition Assistance.
• Employee Development Program.
• Multisport / Lifestyle Spending Account.
• Eyeglasses reimbursement.
• Birthday gift card.
• Baby gift.
• Recognition programs.
• PPK & PPE pension schemes.
EnableComp
Transaction Network Services (TNS)
Munson Healthcare
Get handpicked remote jobs straight to your inbox weekly.