

Search by job, company or skills

The Information Security Compliance Officer is responsible for ensuring overall organizational adherence to all applicable information security standards, laws, regulations and policies.
1. Key Responsibilities
· Develop, implement, and maintain the organization's information security compliance framework.
· Develop documented information in compliance with ISO 27001, SOC, ITGC and other relevant standards.
· Assist internal stakeholders in implementing the requirements of ISO 27001, SOC, ITGC and other relevant standards.
· Conduct regular compliance check to evaluate adherence to security policies and regulations.
· Collaborate with internal stakeholders to identify and remediate compliance gaps.
· Manage and report compliance risks to the management and recommend corrective actions.
· Maintain documentation and records of compliance activities and audit findings.
· Act as the liaison for internal and external audits.
· Provide compliance training to employees and management.
· Stay updated on emerging regulations, trends, and technologies affecting information security compliance.
2. Key Result Areas
· Compliance Framework Development & Maintenance
o Percentage of compliance framework completed and updated annually.
o Number of improvements/enhancements implemented in framework.
· Documentation & Record Management
o Percentage of documentation updated on schedule.
o Accuracy and completeness of compliance records.
· Internal Stakeholder Engagement
o Percentage of compliance gaps resolved within agreed timelines.
· Compliance Monitoring & Checks
o Number of compliance checks completed vs. planned.
o Percentage of compliance findings remediated within agreed timelines.
· Audit & Regulatory Coordination
o Percentage of audit findings closed within target timelines.
o Number of repeat findings.
· Training & Awareness
o Percentage of employees trained on compliance topics annually.
o Post-training assessment results
3. Qualifications and Experience
· Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field; relevant certifications (e.g., ISO/IEC 27001 Lead Implementer, CISA, CISSP) are highly desirable.
· Minimum 3–5 years of experience in information security compliance, IT audit, or risk management roles.
· Proven experience in developing, implementing, and maintaining compliance frameworks based on international standards such as ISO/IEC 27001, SOC 2, and IT General Controls (ITGC).
· Solid understanding of regulatory requirements and information security best practices, including policy development, audit readiness, and control testing.
· Demonstrated ability to conduct compliance checks, identify non-conformities, and recommend or drive remediation efforts in collaboration with internal teams.
4. Key Competencies and Skills
· Strong understanding of information security principles, risk management, and control frameworks.
· Analytical and problem-solving skills.
· Excellent communication and documentation skills.
· Ability to work independently and collaboratively with cross-functional teams.
· Attention to detail and commitment to continual improvement.
Job ID: 152345537
Skills:
Gdpr, Iso 27001, Microsoft Azure, Cism, nist, Data privacy regulations, PCI-DSS