Project Manager - Compliance at Booth | Torre

Project Manager - Compliance

You'll drive client compliance and cybersecurity success at Eden Data.
Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Base compensation
COP7M - 10M/month
~USD1.83k - 2.62k/month

+ Health insurance

Negotiable
location_on
Remote (for Colombia residents)
skeleton-gauges
You have opted out of job matches in .
To undo this, go to the 'Skills and Interests' section of your preferences.
Review preferences
Posted about 1 year ago

Requirements and responsibilities


✨ Join Eden Data as a Compliance Support Specialist and Make a Real Impact! πŸš€ As a Compliance Support Specialist at Eden Data, you will play a critical role πŸ”‘ in helping our clients achieve and maintain compliance with SOC 2 Type II, ISO 27001, and other framework standards. πŸ›‘οΈ You will maintain clear client communications via Slack πŸ’¬ and email πŸ“§, oversee clients' Drata instances βš™οΈ to ensure all compliance requirements are met, and create and manage project plans in Asana πŸ—“οΈ as needed. You will collaborate closely with the internal cybersecurity team πŸ§‘β€πŸ’» to implement security controls, conduct risk assessments πŸ€”, maintain security documentation πŸ“„, and continuously enhance compliance initiatives to protect sensitive information. You will also be answering client questions daily via Slack πŸ’¬ and email πŸ“§. Key Responsibilities: Technical Support: -Provide technical support πŸ› οΈ for cybersecurity tools and technologies, ensuring operational effectiveness and timely issue resolution. βœ… -Maintain security awareness training documentation πŸ“š for internal and client-facing audiences to promote cybersecurity best practices. πŸ’‘ -Support clients' audit readiness βœ… by assisting with evidence collection, control testing, and remediation tracking. πŸ“Š -Assist clients with the setup and maintenance of GRC (Governance, Risk, and Compliance) tools, particularly Drata βš™οΈ, including data migration, vendor module configuration, user management, and policy updates. πŸ§‘β€πŸ”§ Security Documentation: -Create, maintain, and update security policies, procedures, and compliance documentation πŸ“ to align with industry standards. 🎯 -Develop and maintain trackers πŸ“ˆ for client purposes according to their internal policy requirements. πŸ“Œ -Assist clients in completing Self-Assessment Questionnaires (SAQs) ✍️, leveraging existing onboarding information, historical SAQs, and data housed within GRC platforms. πŸ” -Conduct periodic user access reviews πŸ•΅οΈ across clients' systems and applications. Assist in preparing reports πŸ“Š and documenting response actions. πŸ“„ Collaboration: -Partner with cybersecurity team members 🀝 and cross-functional departments to implement and sustain security measures. πŸ§‘β€πŸ€β€πŸ§‘ -Research and respond to clients' ad-hoc security inquiries πŸ€”, providing clear and actionable findings. πŸ’‘ -Leverage internal tools βš™οΈ to optimize workflows and drive efficiency in daily operations. πŸš€ Exercise Self-Direction: -Regularly assess and enhance client security postures πŸ›‘οΈ, leveraging GRC platform features for control management, task assignment, and audit readiness activities. 🎯 -Operate autonomously 🧘, taking ownership of work πŸ’ͺ and executing tasks ahead of deadlines with minimal oversight. ⏰ Requirements: -Education: Bachelor's degree πŸŽ“ in Information Security, Computer Science, or a related field. -Relevant certifications SEC+, CISA, or equivalent may be required. (CISSP, CISM, CRISC are a plus πŸ‘). -Experience: Minimum of 2–4 years of experience ⏳ in cybersecurity, with a focus on compliance management and project management. -Technical Skills: Proficiency in using Asana (or equivalent) πŸ—“οΈ for project management and Slack πŸ’¬ for effective communication. -Familiarity with Drata βš™οΈ or similar compliance management tools is highly desirable ✨. -Compliance Knowledge: Strong understanding πŸ’ͺ of SOC 2 Type I and II, and ISO 27001 standards, controls, and assessment methodologies. -Experience with other compliance frameworks (e.g., HIPAA, GDPR, NIST) is nice to have 😊. -Analytical Thinking πŸ€”: Ability to analyze and identify security risks, providing practical recommendations for mitigating those risks. πŸ’‘ -Communication Skills: Excellent verbal and written communication skills πŸ—£οΈ in English, with the ability to convey technical concepts to both technical and non-technical stakeholders effectively. -Collaboration 🀝: Proven ability to work collaboratively in a team environment, interacting with clients, internal teams, and third-party auditors or assessors (as needed). -This role would not need to take external calls with clients (via Zoom etc.) but does need to be externally facing via Slack πŸ’¬ and email πŸ“§ correspondence. -Ability to work independently 🧘, remotely πŸ’», with assigned tasks and deadlines ⏰, with minimal oversight. -Attention to Detail πŸ‘€: Meticulous and thorough approach to work, ensuring accuracy in documentation, reporting, and compliance activities. -Adaptability πŸš€: Ability to thrive in a fast-paced and rapidly changing environment πŸŒͺ️, managing multiple projects simultaneously and meeting deadlines. Benefits: -Competitive salary πŸ’°. -Prepaid medical plan πŸ₯. -Life insurance πŸ›‘οΈ. -Your birthday off! πŸŽ‰ -Indefinite-term contract πŸ“œ with full legal benefits.
Optionally, you can add more information later (benefits, pre-screening questions, etc.)
check_circle

Payment confirmed

A member of the Torre team will contact you shortly

In the meantime, continue adding information to your job opening.