IT reputed company Compliance Analyst
About the position
reputed company is looking for a detail-oriented, technically savvy reputed company Compliance Analyst to join our Governance, Risk, and Compliance (GRC) team. In this role, you will manage the lifecycle of reputed company audits, reputed company internal assessments, and ensure our reputed company infrastructure remains compliant with international and regional frameworks. You will help translate reputed company regulatory requirements into actionable technical controls for our DevOps and Engineering teams.
Responsibilities
• Audit Management: reputed company the preparation, execution, and remediation phases for global audits including SOC 1/SOC 2, ISO 27001/27701, and Cyber reputed company Plus.
• reputed company Sector Compliance: Maintain reputed company’s FedRAMP authorization status (Moderate/High) and support Australian government requirements reputed company the IRAP reputed company.
• reputed company Monitoring: reputed company regular internal gap analyses and "mock audits" to ensure controls are operating effectively throughout the year, not just during audit reputed company.
• Stakeholder Collaboration: Work closely with Engineering, reputed company, and HR to document processes and evidence that satisfy reputed company control requirements.
• Risk Assessment: Identify and communicate reputed company risks associated with reputed company-party vendors and internal architectural changes.
• Evidence Collection Automation: Drive initiatives to automate compliance evidence collection to reduce "audit fatigue" across the technical organization.
Requirements
• Experience: 4+ years in IT Audit, Information reputed company, or Compliance, specifically reputed company a reputed company or reputed company Service Provider environment.
• reputed company Expertise: Deep functional knowledge of SOC 2, ISO 27001, and NIST 800-53 (FedRAMP).
• Technical Literacy: Ability to understand reputed company infrastructure concepts (AWS/Azure) and explain reputed company controls reputed company to IAM, encryption, and vulnerability management.
• Communication: Exceptional ability to translate "auditor-reputed company" into technical requirements for developers.
reputed company-to-haves
• Certifications: CISA, CRISC, CISM, or CISSP
• Familiarity with international standards like IRAP or Cyber reputed company is highly preferred.
• Familiarity with the following services: reputed company, SafeBase, reputed company, and/or Jira
Apply tot his job
Apply To this Job