Otonomee·6 days ago
6 days ago
Internal Audit & Compliance Manager ( Remote in Colombia )
Sign up free to see how well your resume matches this role.
What you'll do
- Establish and run a planned internal audit programme across ISO 27001, PCI DSS, SOC 2, and additional frameworks in scope (e.g. HIPAA, HITRUST), including control testing, findings, and remediation tracking to closure.
- Provide independent assurance to the CTO, CEO, and senior leadership on control effectiveness and compliance status.
- Maintain continuous audit readiness and coordinate external audits and certification cycles end to end, acting as the primary point of contact for auditors.
- Conduct risk assessments using risk-based methodologies; develop and track key risk indicators (KRIs) and mitigation plans.
- Liaise with business process owners and technical teams to drive and track remediation of control gaps and audit findings.
- Advise stakeholders and leadership on compliance gaps, risks, and their business impact, recommending pragmatic mitigations.
- Prepare and present compliance reports for internal stakeholders (leadership and board) and external parties (auditors, clients, and regulators).
- Run third-party and vendor risk reviews and ongoing monitoring.
- Own security questionnaires and RFP compliance responses, and support client-facing assurance (Trust Centre).
- Lead information-security awareness initiatives and strengthen the organisation's compliance culture.
- Act as ISMS Coordinator, owning the day-to-day operation and continuous improvement of the ISO/IEC 27001 Information Security Management System, and safeguarding the confidentiality, integrity, and availability of company and client information as the programme's central objective.
- Operate and administer the Drata GRC platform: integrations, control mapping, automated evidence collection, alerts, and the policy centre.
What they're looking for
- Proven experience (typically 8+ years) in internal audit, GRC, or information-security compliance, including in regulated environments.
- Hands-on experience implementing and operating an ISO/IEC 27001 ISMS, including gap assessments and remediation roadmaps.
- Working knowledge of SOC 2 and its Trust Services Criteria, with practical evidence and control-operation experience or a clear trajectory towards it.
- Practical PCI DSS compliance experience: evidence validation, control documentation, and audit follow-up.
- Demonstrated internal audit capability, ideally with a recognised internal-auditor qualification.
- Experience with a GRC or compliance-automation platform (e.g. Drata or equivalent).
- Strong command of risk-based methodologies, KRIs, control-effectiveness evaluation, and evidence management.
- Experience working remotely with distributed, cross-functional teams in a global environment.
Nice to have
- Data-protection / privacy experience (e.g. GDPR or equivalent) and awareness of financial-crime / AML-CTF contexts desirable.
- Exposure to HIPAA, HITRUST, NIST CSF/RMF, or other security and healthcare frameworks desirable.
Summarised by NextRaise from the employer’s description, which follows in full below.
Full description from employer
About The Role
Your profile
Why us?
Company
Otonomee
Colombia
Company facts come from this company's own listings. We only show what the postings themselves carry.