We are seeking an experienced and highly motivated Compliance Officer with a strong background in SOC I and SOC II Type I audits. They will play a crucial role in ensuring that our organization meets the highest standards of security, privacy, and regulatory compliance. They will be responsible for maintaining and enhancing our compliance programs, conducting risk assessments, and leading SOC audits.
The ideal candidate will have a thorough understanding of SOC compliance frameworks, information security, and regulatory requirements to drive our efforts in safeguarding sensitive data.
Key Responsibilities:
1. SOC I & II Audits:
- Lead the planning, execution, and management of SOC I and SOC II Type I audits.
- Collaborate with external auditors, internal departments, and stakeholders to ensure audits are conducted smoothly and all compliance gaps are addressed.
- Prepare and present audit reports to senior management, outlining findings, risks, and remediation plans.
- Maintain up-to-date knowledge of SOC auditing standards and procedures, ensuring the organization remains compliant.
2. Compliance Management:
- Develop, implement, and maintain comprehensive compliance programs to ensure alignment with SOC I & II standards.
- Conduct internal assessments to evaluate compliance with SOC frameworks and address any deficiencies.
- Work cross-functionally with IT, HR, and Legal teams to ensure compliance across all business operations.
- Act as the primary point of contact for compliance inquiries, audits, and regulatory matters.
3. Risk Assessment & Mitigation:
- Identify, assess, and document potential risks related to security, operations, and compliance.
- Implement risk mitigation strategies and corrective action plans to address audit findings or compliance gaps.
- Monitor and evaluate the effectiveness of risk controls, making recommendations for continuous improvement.
4. Policies and Procedures:
- Develop, review, and update compliance policies and procedures to meet SOC I & II requirements and other applicable regulations.
- Ensure that all staff, particularly those in IT and security, are trained on compliance policies and standards.
- Provide clear guidance on how to comply with regulatory requirements and industry best practices.
5. Stakeholder Communication:
- Engage with external and internal stakeholders to ensure clear communication about compliance obligations and initiatives.
- Liaise with legal counsel, regulatory bodies, and external auditors on compliance-related matters.
- Provide regular reports and updates to senior leadership on compliance status, audit findings, and mitigation e-orts.
6. Monitoring & Reporting:
- Establish continuous monitoring mechanisms to ensure compliance with SOC I & II Type I controls.
- Develop dashboards and reporting tools to provide insights into compliance metrics and performance.
- Report on key compliance indicators, trends, and emerging risks to senior leadership
Qualifications:
• Bachelor’s degree in Information Security, Business Administration, or a related field (Master’s degree preferred).
• 5+ years of experience in compliance management, with a specific focus on SOC I and SOC II Type I audits.
• Deep understanding of SOC 1/SSAE 18 and SOC 2/AT-C 105 standards, as well as regulatory requirements such as GDPR, HIPAA, and ISO 27001.
• Strong experience in risk assessment, auditing, and remediation of compliance issues.
• Proven ability to lead cross-functional teams and manage external audit engagements.
• Certification in relevant compliance and auditing disciplines (e.g., CISA, CISM, CISSP, CRISC) is a plus.
• Excellent organizational skills, with the ability to prioritize tasks and work independently in a fast-paced environment.
• Strong communication and interpersonal skills, capable of working with technical and non-technical teams.
• Attention to detail and a proactive approach to problem-solving and risk management.
Preferred Skills:
• Experience working with cloud environments (e.g., AWS, Azure) and understanding how to apply SOC standards to cloud infrastructure.
• Familiarity with GRC tools (Governance, Risk, and Compliance) to track and manage compliance requirements.
• Experience in developing compliance frameworks for organizations that process large volumes of sensitive data.
Department: Compliance
Reports to: Director of Development
To apply for this job email your details to bhaskar.patel@primeroedge.com