Project Manager, Compliance and Security
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Project Manager, Compliance and Security (SOC 2/ISO 27001/GDPR): Managing compliance and security workstreams for a complex telecom transformation program with an accent on audit readiness, evidence collection, control remediation, and cross-functional governance. Focus on structuring incomplete or evolving requirements into delivery plans, resolving evidence and ownership gaps, and coordinating remediation across security, IT, engineering, network operations, and architecture.
Location: Remote work within the United States; listed location is Los Angeles, US
Company
is a global IT services and consulting company supporting digital transformation for enterprise and startup clients across more than 25 countries and five continents.
What you will do
- Build and maintain the Compliance and Security workstream plan with milestones, owners, dependencies, risks, assumptions, and acceptance criteria.
- Coordinate SOC 2, ISO/IEC 27001, GDPR, and related audit-readiness activities across business and technical stakeholders.
- Track compliance tasks, evidence requests, control gaps, remediation actions, and ownership through completion.
- Coordinate remediation across change, incident, access, vulnerability, asset, logging, backup, business continuity, disaster recovery, and security architecture areas.
- Facilitate workshops, control reviews, evidence sessions, and stakeholder checkpoints while maintaining RAID logs, decision logs, and issue registers.
- Escalate risks, blockers, missing ownership, evidence gaps, and scope changes, coordinating with adjacent transformation and governance streams.
Requirements
- 7+ years of project or program management experience in compliance, security, IT governance, infrastructure, telecom, cloud, or enterprise technology environments.
- Experience managing SOC 2, ISO/IEC 27001, GDPR, or comparable audit-readiness and control-remediation initiatives.
- Practical understanding of security controls, evidence collection, audit preparation, control ownership, and remediation tracking.
- Experience coordinating cross-functional teams across Security, Compliance, IT, Engineering, Network Operations, Architecture, and business functions.
- Strong skills in RAID management, executive reporting, stakeholder coordination, dependency management, and driving closure.
- Familiarity with Jira, Confluence, ServiceNow, SharePoint, Microsoft Project, Smartsheet, Azure DevOps, GRC platforms, or similar tools.
Nice to have
- Certifications such as PMP, PRINCE2, Agile, CISA, CISM, CRISC, CISSP, ISO 27001 Lead Implementer, or ISO 27001 Lead Auditor.
- Experience coordinating evidence across fragmented platforms, acquired entities, or distributed operational teams.
- Understanding of ITSM, CMDB, observability, security architecture, and operational governance.
Culture & Benefits
- Remote work culture with a relocation program and comprehensive health and benefits coverage.
- Professional development through certification programs, mentorship, talent investment, and internal mobility opportunities.
- Work on impactful projects for major global clients in a multicultural and inclusive environment.
- Open communication, team-building events, and a culture focused on performance and continuous growth.
- Commitment to social sustainability, fair operating practices, environmental sustainability, and gender equality.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →