Remote · worldwide, UTC+4 acceptedSalary not disclosedfull-timeVerified 1w agoHimalayas
To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu. To learn more about our Hiring Range System, please click this link.
Responsibilities
Maintain and mature the ISMS, including the Statement of Applicability (SoA), risk treatment plans, and the Management Review Meeting (MRM) process and cadence.
Support ISO 27001 and SOC 2 Type 2 audit execution—helping determine scope, preparing evidence and narrative artifacts, participating in auditor interviews and walkthroughs, and resolving auditor findings.
Contribute to the SOC 2 System Description and other audit-specific narrative documentation, ensuring they accurately reflect the organization's actual control environment.
Track gaps and remediation efforts arising from readiness assessments and audits.
Lead the policy program—driving policy creation, revision, and cross-functional review cycles to keep the security policy set current, enforceable, and audit-ready.
Support compliance scaling as additional products or business units pursue readiness assessments and certification.
Support the internal audit function, partnering with internal or third-party resources as needed to meet ISO 27001's internal audit requirements.
Partner closely with Engineering, IT, Legal, Privacy, People teams, and product leadership to gather evidence, drive control ownership, and translate compliance requirements into practical, adoptable practices.
Advise the GRC manager and broader Security leadership on audit risk, certification readiness, and compliance program strategy.