Назад
Company hidden
3 дня назад

Compliance Analyst (AI)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Compliance Analyst (AI): Supporting the operation and continuous improvement of information security compliance programmes with an accent on maintaining audit defensibility and ensuring proportionate, scalable processes aligned with business growth. Focus on embedding structured, pragmatic, and repeatable compliance practices across the organisation.

Company

hirify.global is a pioneer of Legal-Grade™ AI for enterprise, disrupting the legal profession globally with its award-winning AI technology.

What you will do

  • Maintain and operate the ISO/IEC 27001:2022 ISMS and support ongoing SOC 2 (Type II) and CMMC Level 1 compliance programmes.
  • Manage compliance calendars, testing cycles, control monitoring activities, and coordinate external audits.
  • Perform periodic control checks, collect, validate, and organise audit evidence, and track nonconformities and corrective actions.
  • Define and operate a proportionate, tiered supplier due diligence model and perform contextual risk assessments.
  • Formalise structured, repeatable compliance workflows, identify automation opportunities, and evolve risk register processes.
  • Support awareness and training initiatives to improve organisational compliance maturity.

Requirements

  • Demonstrable experience in information security compliance, IT audit, or Governance, Risk & Compliance (GRC).
  • Working knowledge of ISO/IEC 27001:2022 and/or SOC 2 Trust Services Criteria.
  • Experience supporting audits and managing evidence collection.
  • Strong organisational, documentation, and stakeholder coordination skills.
  • Ability to interpret regulatory and control requirements and translate them into practical business processes.
  • Excellent written and verbal communication skills.

Nice to have

  • ISO 27001 Internal Auditor certification.
  • Experience in SaaS or cloud-based environments.
  • Familiarity with CMMC and NIST SP 800 frameworks.
  • Working knowledge of risk management frameworks (ISO 31000, NIST RMF, FAIR).
  • Experience with GRC platforms (e.g., Drata, Vanta, Secureframe).

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →

Текст вакансии взят без изменений

Источник - загрузка...