Назад
Company hidden
7 часов назад

IT & Compliance Manager

Тип работы
fulltime
Грейд
middle
Английский
c1
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
IT & Compliance Manager (SaaS/Security): Owning internal IT, information security, privacy, and compliance programs across SOC 2, ISO 27001, ISO 27701, PCI DSS, and GDPR with an accent on audit readiness, identity management, and enterprise security requirements. Focus on managing external audits, strengthening access and endpoint operations, coordinating privacy and incident response processes, and automating recurring compliance work.

Company

hirify.global provides a SaaS environment requiring secure, scalable internal IT operations and enterprise-grade security and compliance support.

What you will do

  • Own and continuously improve information security and privacy management programs, including policies, controls, evidence, risk management, and corrective actions.
  • Lead compliance and certification activities across SOC 2 Type II, ISO 27001, ISO 27701, PCI DSS, and GDPR.
  • Manage external audits end-to-end, including preparation, evidence collection, auditor coordination, findings, and remediation.
  • Manage identity, access, endpoint, asset, device security, office IT, onboarding, offboarding, MFA, permissions, and access reviews.
  • Own privacy operations, vendor security risk, enterprise security questionnaires, incident response, vulnerability management, security awareness, and business continuity.
  • Partner with R&D and DevOps on infrastructure risks, security controls, remediation, logging, monitoring, and automation of recurring IT and compliance processes.

Requirements

  • 4+ years of experience in IT, information security, compliance/GRC, or a similar role.
  • Hands-on ownership of at least one SOC 2 or ISO 27001 audit or certification cycle.
  • Experience with identity and endpoint management tools such as JumpCloud, Okta, Google Workspace, or Entra ID.
  • Working knowledge of AWS security fundamentals, including IAM, logging, network boundaries, and encryption.
  • Practical experience with GDPR and privacy operations, including DSRs, ROPA, and DPAs.
  • Fluency in English and Hebrew, with strong communication skills for working with technical teams and enterprise customers.

Nice to have

  • Experience with Vanta, Drata, ISO 27701, PCI DSS, NIST CSF, or relevant security and privacy certifications.
  • Familiarity with Kubernetes, CI/CD security, vulnerability management, dependency scanning, scripting, or automation.
  • Experience in a B2B SaaS environment with enterprise customers.
  • Familiarity with AI governance and emerging enterprise security requirements around AI.

Culture & Benefits

  • Individual contributor role with end-to-end ownership and direct reporting to the CTO.
  • Cross-functional collaboration with R&D, DevOps, HR, Legal, Sales, Customer Success, and external vendors.
  • Responsibility for managing external vendors and partners supporting IT, security, privacy, and compliance operations.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →