name

[8PP] Compliance Specialist

Remote, United States remote Entry Salary not listed
remote Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

We are looking for an experienced Information Security Governance, Risk, and Compliance Specialist to support our security and compliance initiatives. The primary focus of this role will be facilitating the organization’s 2026 SOC 1 and SOC 2 audits, along with supporting policy management, enterprise risk, and vendor risk activities.
This role involves working across Security, IT, Operations, Finance, Legal, and Procurement to coordinate external audits, maintain security policies, manage enterprise and vendor risks, and strengthen the organization’s overall compliance program.
Information Security Policy Management

Manage the lifecycle of Information Security policies, including reviews, updates, approvals, publication, and version control.

Coordinate urgent policy changes and annual policy review cycles.

Maintain policy records and approval documentation to support governance and audit readiness.

Track outstanding actions and improve policy management workflows, templates, and review processes.

External Audit Coordination

Coordinate the annual SOC 1 and SOC 2 attestation processes and other external audits.

Manage audit timelines, evidence collection, documentation, stakeholder coordination, and auditor requests.

Partner with control owners to validate control performance and address findings, exceptions, and remediation activities.

Maintain audit evidence repositories and support the preparation of control descriptions, management narratives, and responses.

Escalate significant risks, control gaps, and audit blockers to the CISO and relevant leadership.

Security Risk Management

Support risk intake, assessment, documentation, tracking, and reporting.

Maintain risk registers and workflows within Full Circle, UpGuard, Drata, Vanta, or similar GRC platforms.

Track remediation plans, target dates, control gaps, and overdue actions.

Prepare risk dashboards, metrics, and status reports for leadership.

Improve risk scoring, reporting, workflows, and platform utilization.

Vendor Risk Management

Manage third-party risk assessments, due diligence, and ongoing vendor monitoring.

Review vendor security documentation and track remediation activities.

Collaborate with Procurement, Legal, IT, and business teams on onboarding and renewal decisions.

Escalate critical vendor risks, exceptions, and unresolved concerns.

Experience supporting SOC 1 and SOC 2 audits, including evidence collection, control validation, and auditor coordination.

Experience with information security policies, enterprise risk management, and vendor risk assessments.

Background working in software-driven environments involving cloud applications and SaaS platforms.

Experience with GRC platforms such as Full Circle, UpGuard, Drata, or Vanta.

Strong organizational, communication, and stakeholder-management skills.

Ability to manage multiple priorities independently and handle sensitive information with discretion.

CISSP, CRISC, or CISA certification.

Nice to Have

Hands-on experience with Full Circle or UpGuard, particularly for risk assessments.

SaaS, cloud security, or compliance certifications.

This is expected to be a short-term engagement through the end of 2026
We are Software Mind, an awesome team of engineers who are ready to ramp up any top-notch company’s projects! Our aim? To always be one step ahead. Become part of a multicultural company in constant growth with an excellent work environment certified by Great Place To Work!
Originally posted on Himalayas

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Role
Technology & IT Data Analysis Finance Operations Writing remote

Likely questions

  1. Tell us about work you have done that is close to the [8PP] Compliance Specialist role.
  2. How would you approach your first 30 days at name?
  3. Which of Data Analysis, Finance and Operations have you used recently, and what did it help you achieve?
  4. Describe a time you solved a problem without waiting to be told exactly what to do.
  5. How do you stay organised and communicate clearly when working remotely?

Prepare before the call

  • A recent example that proves your experience with Data Analysis, Finance and Operations.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the [8PP] Compliance Specialist role because I can bring practical experience in Data Analysis, Finance and Operations, learn the team quickly, and contribute to the outcomes name needs from this hire.

Related jobs.

More roles from this company or category.