Google Chrome
Microsoft Edge
Apple Safari
Mozilla Firefox
Compliance ConsultantFull-timeCompany DescriptionSigma Software is looking for a Compliance Consultant to strengthen our governance, risk, and compliance practices. In this role, you will work with a wide range of international standards and regulations (such as ISO 27001, SOC 2, GDPR, and others), translating them into clear, practical controls, policies, and processes. You will conduct audits and assessments, advise stakeholders on compliance risks, support certification and customer due diligence activities, and contribute to awareness and training initiatives. This position is a great fit for a specialist who enjoys working at the intersection of information security, regulations, and business needs, and who is ready to drive tangible improvements in a dynamic IT environment.Job DescriptionLead and oversee compliance projects in accordance with relevant standards and frameworks (e.g., ISO 27001, ISO 27701, ISO 22301, ISO 13485, SOC2, NIST CSF, PCI DSS, GDPR, HIPAA, DORA, OWASP SAMM)Develop, implement, and maintain comprehensive compliance policies, procedures, and guidelines aligned with regulatory and framework requirementsConduct comprehensive internal audits and assessments to ensure regulatory and framework compliance, documenting findings and non-conformitiesProvide clear, actionable recommendations for corrective and preventive actions and support stakeholders in implementing themCollaborate with stakeholders to perform risk assessments and define appropriate controlsDevelop, update, and implement advanced compliance training programs for employeesSupport and enhance the compliance awareness program, promoting a strong compliance and security culture across the organizationInvestigate, resolve, and provide guidance on complex compliance-related requests, incidents, and complaintsQualifications3+ years of experience in compliance management and implementation, preferably in IT, consulting, or related fieldsProficiency in some of the following standards and regulations: IISO 27001, ISO 27701, ISO 22301, ISO 13485, SOC2, NIST CSF, PCI DSS, GDPR, HIPAA, DORAProven ability to interpret compliance regulations and framework requirements and translate them into practical policies and controlsExperience in conducting compliance or security audits and assessments, including planning, execution, reporting, and follow-upExperience in drafting and maintaining compliance policies, procedures, and related documentationExperience in security consulting for multiple industriesSolid understanding of information security, risk management, and data protection principlesUpper-Intermediate English (spoken and written) and proficiency in UkrainianStrong documentation, presentation, and communication skills, with the ability to explain complex topics in a clear and structured way
WILL BE A PLUSKnowledge of OWASP frameworksHands-on experience with OWASP SAMM implementation in real projectsProfessional certifications such as CISA, CISM, CISSP, or similarAdditional InformationPERSONAL PROFILEStrong analytical and problem-solving skills, able to structure and prioritize complex tasksExcellent communication and stakeholder management abilitiesDetail-oriented with a strong commitment to accuracy and quality in documentation and processesAbility to work independently, take ownership of initiatives, and drive them to completionComfortable working in cross-functional, distributed teams and managing multiple tasks in parallelProactive, responsible, and oriented toward continuous improvement of processes and controlsBy clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy applyI'm interestedI'm interestedI'm interestedRefer a friendshare this jobShare to WeChat×Copy the link and open WeChat to share.Copy to clipboardOpen WeChatShare to...
Want jobs like this matched to you?
Swoopd scores fresh postings against your résumé so you only see the matches that matter.