This one is closed
Live roles like this one
-
B
1h ago
Payment Integrity Analytics Specialist
PacificSource Health Plans United States $57k - $97k/yr
-
B
9h ago
Director of Brand and Marketing Strategy
Google Fiber United States $350k - $375k/yr
-
C
16h ago
General Accounting Specialist (US GAAP)
SupportNinja Philippines
-
B
18h ago
Member & Provider Care Specialist
Oscar United States $22/hr
See every "Compliance Specialist" role →
Get new “Compliance Specialist” roles by email
One email a day with what is new in "Compliance Specialist". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 27/100, which is an F. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Remote clarity 8 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Corroboration 5 / 10 Whether more than one source carries this listing.
- Freshness 4 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Role specificity 0 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Pay transparency 0 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
-10 Ghost-job penalty — Deducted for signals that this posting may not be a real, currently-open role — staleness, repeated relisting, or talent-pool language.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
We are looking for an experienced Information Security Governance, Risk, and Compliance Specialist to support our security and compliance initiatives. The primary focus of this role will be facilitating the organization’s 2026 SOC 1 and SOC 2 audits, along with supporting policy management, enterprise risk, and vendor risk activities.
This role involves working across Security, IT, Operations, Finance, Legal, and Procurement to coordinate external audits, maintain security policies, manage enterprise and vendor risks, and strengthen the organization’s overall compliance program.
Information Security Policy Management
- Manage the lifecycle of Information Security policies, including reviews, updates, approvals, publication, and version control.
- Coordinate urgent policy changes and annual policy review cycles.
- Maintain policy records and approval documentation to support governance and audit readiness.
- Track outstanding actions and improve policy management workflows, templates, and review processes.
External Audit Coordination
- Coordinate the annual SOC 1 and SOC 2 attestation processes and other external audits.
- Manage audit timelines, evidence collection, documentation, stakeholder coordination, and auditor requests.
- Partner with control owners to validate control performance and address findings, exceptions, and remediation activities.
- Maintain audit evidence repositories and support the preparation of control descriptions, management narratives, and responses.
- Escalate significant risks, control gaps, and audit blockers to the CISO and relevant leadership.
Security Risk Management
- Support risk intake, assessment, documentation, tracking, and reporting.
- Maintain risk registers and workflows within Full Circle, UpGuard, Drata, Vanta, or similar GRC platforms.
- Track remediation plans, target dates, control gaps, and overdue actions.
- Prepare risk dashboards, metrics, and status reports for leadership.
- Improve risk scoring, reporting, workflows, and platform utilization.
Vendor Risk Management
- Manage third-party risk assessments, due diligence, and ongoing vendor monitoring.
- Review vendor security documentation and track remediation activities.
- Collaborate with Procurement, Legal, IT, and business teams on onboarding and renewal decisions.
- Escalate critical vendor risks, exceptions, and unresolved concerns.
- Experience supporting SOC 1 and SOC 2 audits, including evidence collection, control validation, and auditor coordination.
- Experience with information security policies, enterprise risk management, and vendor risk assessments.
- Background working in software-driven environments involving cloud applications and SaaS platforms.
- Experience with GRC platforms such as Full Circle, UpGuard, Drata, or Vanta.
- Strong organizational, communication, and stakeholder-management skills.
- Ability to manage multiple priorities independently and handle sensitive information with discretion.
- CISSP, CRISC, or CISA certification.
Nice to Have
- Hands-on experience with Full Circle or UpGuard, particularly for risk assessments.
- SaaS, cloud security, or compliance certifications.
This is expected to be a short-term engagement through the end of 2026
We are Software Mind, an awesome team of engineers who are ready to ramp up any top-notch company’s projects! Our aim? To always be one step ahead. Become part of a multicultural company in constant growth with an excellent work environment certified by Great Place To Work!
Originally posted on Himalayas
Apply for this role Opens himalayas.app — the link as listed; we have not yet verified it is the employer's own page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 31 Jul 2026 Himalayas first sighting
Seen on 1 board over 0 days.