
Senior Manager, Compliance & Audit
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Take ownership and expand mpathic’s compliance and auditing initiatives.
• Organize and manage the yearly audit and certification processes for SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 42001, and Part 11 preparedness.
• Choose auditors, define the scope, gather evidence, oversee fieldwork and management responses, and produce final reports or certificates.
• Be responsible for Part 11 compliance regarding systems that create, modify, or store regulated records.
• Keep system inventories and GxP impact evaluations up to date.
• Lead risk-based validation efforts and ensure validation documentation is current with releases and system modifications.
• Maintain a consolidated control set mapped across relevant frameworks.
• Conduct risk-based internal audits, ISO-mandated internal audits, and management reviews; monitor nonconformities and CAPAs until resolution.
• Collaborate with engineering and delivery teams on change management, code reviews, access evaluations, release validations, and data management.
• Automate evidence collection where feasible and oversee control health.
• Manage mpathic’s ISO/IEC 42001 AI management system, including AI risk and impact assessments and model lifecycle control documentation.
• Handle security questionnaires, quality audits from customers and sponsors, compliance-related RFPs, contract responses, and maintain the trust center.
• Oversee the GRC platform and its integrations, including control mappings, automated evidence collection, and policy workflows.
• Maintain certification and regulatory policies along with standard operating procedures (SOPs).
• Provide compliance training, encompassing Part 11 and GxP training.
• Keep abreast of FDA guidelines, AI governance requirements, and relevant data privacy laws, translating updates into actionable recommendations.
• A minimum of 7 years' experience in IT compliance, GRC, auditing, or computerized systems validation, with direct responsibility for external audits from scoping to final report or certification.
• Practical experience applying FDA 21 CFR Part 11 and GxP data integrity standards to software or SaaS systems, including audit trails, electronic signatures, access controls, record retention, and ALCOA+ principles.
• Familiarity with FDA Computer Software Assurance (CSA) guidance, GAMP 5, and EU Annex 11 is highly advantageous.
• Experience in drafting or leading validation plans, requirements traceability, risk-based test evidence (IQ/OQ/PQ or CSA-style), and validation summary reports.
• Proven experience in supporting customer or sponsor audits of validated systems.
• Experience in leading or assisting with SOC 1 and SOC 2 Type II examinations and ISO/IEC 27001 certification or surveillance audits.
• Knowledge of ISO/IEC 42001 or other AI governance frameworks, including NIST AI RMF or the EU AI Act, is a strong advantage.
• Comfortable reviewing cloud configurations across AWS, GCP, or Azure; IAM policies; CI/CD and change management documentation; logging; and infrastructure as code.
• Capable of planning and conducting internal audits, sampling and assessing evidence, documenting clear findings, and driving CAPAs to resolution.
• Comfortable representing mpathic in interactions with external auditors, certification bodies, customers, and sponsor quality teams.
• Proficient in writing policies, findings, and responses for customers.
• Certifications such as CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, ISO/IEC 42001 Lead Auditor, ASQ CQA, or CISSP are considered a plus.
• Competitive salary and performance-based incentives.
• Comprehensive health, dental, and vision insurance.
• Flexible work arrangements and a supportive work environment.
• Opportunities for professional development and certifications.
• A chance to work with a dynamic and innovative team.
Yordas Group
Yordas Group
Get handpicked remote jobs straight to your inbox weekly.