Company
Technology
Compliance&GovernanceSpecialist
Neural analysis suggests this role is
optimal for Senior candidates.
“Compliance & Governance Specialist. Skills: Compliance programs, Governance frameworks, Audit execution, Risk assessment. Own enterprise security programs. Evolve enterprise security programs”
What You'll Achieve.
Support leadership decision-making; Support risk visibility
Industry & Context.
Assess control design; Assess control effectiveness; Identify gaps; Drive remediation
What They're Looking For.
Must Have
5+ years information security, 5+ years compliance, 5+ years audit, 5+ years risk management, Hands-on SOC 2 Type II exposure, Deep understanding SOC 2 Trust Services Criteria, Experience with ISO 27001 frameworks, ISMS operation experience, CAPA management experience, Certification maintenance experience, Assess control design effectiveness, Assess control operational effectiveness, Identify control gaps, Drive control remediation, Familiarity with cloud environments, Familiarity with Azure, Communication skills
Nice to Have
ISO 42001 exposure, AI/ML governance exposure, Responsible AI frameworks exposure, Model risk management exposure, Experience in regulated sectors, CISSP certification, CISA certification, CRISC certification, ISO 27001 Lead Implementer certification, ISO 27001 Lead Auditor certification
What You'll Do.
Own enterprise security programs
Evolve enterprise security programs
Own compliance programs
Evolve compliance programs
Lead audit readiness activities
Perform gap assessments
Perform control mapping
Translate requirements into controls
Implement scalable controls
Drive automation of compliance evidence
Support continuous audit readiness
Maintain ISMS governance
Maintain AIMS governance
Manage policy lifecycle
Oversee internal audits
Maintain certifications
Evaluate control effectiveness
Collaborate with engineering teams
Collaborate with security teams
Collaborate with legal teams
Collaborate with AI teams
Embed compliance into SDLC
Embed compliance into operational processes
Manage vendor risk assessments
Manage third-party risk assessments
Produce compliance dashboards
Produce executive reporting
How You'll Work.
Team & Collaboration
Cross-functionally; Engineering teams; Security teams; Legal teams; AI teams
Communication Scope
Audit documentation; Risk reports; Compliance dashboards; Executive reporting
Full Job Description
## Accountabilities Own and evolve enterprise security and compliance programs, including SOC 2 Type II, ISO 27001, ISO 42001, and related governance frameworks. Lead end-to-end audit readiness activities, including gap assessments, control mapping, auditor coordination, evidence collection, and remediation tracking. Translate regulatory and framework requirements into practical, scalable controls that can be implemented across engineering and product teams. Drive automation of compliance evidence collection and support continuous audit readiness in collaboration with engineering teams. Maintain ISMS and AIMS governance structures, including policy lifecycle management, scope definition, and control documentation. Oversee internal audits, CAPA management, and ongoing certification maintenance while evaluating control effectiveness. Collaborate cross-functionally with engineering, security, legal, and AI teams to embed compliance into SDLC and operational processes. Manage vendor and third-party risk assessments, including due diligence, contractual alignment, and residual risk evaluation. Produce compliance dashboards, KPIs, and executive reporting to support leadership decision-making and risk visibility. Requirements: 5+ years of experience in information security, compliance, audit, or risk management, with strong hands-on SOC 2 Type II exposure. Deep understanding of SOC 2 Trust Services Criteria and audit execution practices. Experience working with ISO 27001 frameworks, ISMS operation, CAPA management, and certification maintenance. Ability to assess control design and operational effectiveness, identify gaps, and drive remediation across teams without direct authority. Strong communication skills with experience producing audit documentation, risk reports, and compliance dashboards. Familiarity with cloud environments (especially Azure) and how infrastructure decisions impact compliance controls. Nice to have: exposure to ISO 42001, AI/ML governance, responsi
Applying for this Compliance & Governance Specialist role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Lever
- Lever uses a streamlined one-page form — apply in under 5 minutes.
- LinkedIn import works well; review parsed data before submitting.
- The cover letter field is optional but visible to reviewers — use it to differentiate.
- Referral codes from employees can significantly boost visibility of your application.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.