Remotely
auditrisk managementgrcpolicyismsiso 27001soc 2soa
Also available on
Job Description
📋 Description
- Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans
- Support ISO 27001 and SOC 2 Type 2 audit execution—scope definition, evidence gathering, auditor
- Contribute to SOC 2 System Description and other audit-specific narrative documentation reflecting
- Track gaps and remediation efforts from readiness assessments and audits.
- Lead policy program: create, revise, and review security policies with cross-functional teams to
- Support scaling of compliance as products/business units pursue readiness and certification.
🎯 Requirements
- 5 years of experience in information security, GRC, or compliance-focused roles.
- Deep familiarity with ISO 27001 and SOC 2 Trust Services Criteria through involvement in audits
- Experience with ISMS scope, SoA maintenance, Management Review Meetings, and System Description
- Proven ability to write and revise security policies with cross-functional buy-in and adoption.
- Experience tracking gaps and remediation plans and aligning with broader compliance and risk
- Excellent cross-functional collaboration with engineers, product managers, legal, and executives
🎁 Benefits
- Generous performance-based bonus plans; shared success as one team.
- Rich medical, dental, and vision coverage.
- Generous retirement contributions with immediate vesting.
- Wellness days, holidays, and birthday day off.
- Home office stipend and annual professional development budget.
- Parental leave, employee referral bonus, and other country-specific benefits.