Information Security Compliance Manager - ref. q52528023
Calling all tech enthusiasts! Are you a problem-solving, curious, and strategic Information Security Compliance Manager? Join us at Sidetrade, the leading global SaaS provider recognized by Gartner.(https://go.sidetrade.com/GartnerMagicQuadrant22.ht)
About Sidetrade and its amazing R&D team
Sidetrade is a fast-growing international software company that is transforming the Order-to-Cash process for global enterprises. Its AI-powered SaaS platform digitizes the financial customer journey, empowering CFOs to secure and accelerate cash flow generation.Recognized as a Leader in Gartner's Magic Quadrant for two consecutive years, Sidetrade fosters a culture of innovation, collaboration, and customer-centricity from its headquarters in Europe and North America.
The R&D team comprises experienced tech professionals who share a deep passion for technology. Together, they are dedicated to developing cutting-edge software solutions that drive the transformation of our customers' work processes. We provide comprehensive training, coaching, resources, and mentorship to empower every team member's growth and nurture their success.
Requirements
Mission
The Information Security Compliance Manager is responsible for ensuring that the organization adheres to regulatory requirements and internal policies related to information security. This role emphasizes managing audits imposed on the organization, handling external requests, and contributing to global compliance improvements by supporting strategy definition and roadmaps.Work hand in hand as a team with operational security, the compliance manager addresses non-conformities, guides remediation efforts, and ensures compliance with industry standards, laws, and regulations while collaborating closely with various departments.
What you’ll be doing:
- Assist with the development, implementation, and maintenance of information security policies, procedures, and processes in alignment with ISO 27001, SOC 1 and 2, and PCI DSS requirements.
- Contribute to setting up and ramp up usage of our GRC (Governance, Risk, and Compliance) platform to streamline compliance management, action plan, risk analysis, policy implementation, validations and reporting.
- Manage and coordinate the remediation of identified gaps, issues, non-conformities or incidents related to information security compliance and audits.
- Provide guidance and support to other departments and stakeholders on how to mitigate, remediate issues and improve proof management.
- Handle and oversee external requests such as RFIs/RFPs, customer due diligence, and ad-hoc requests.
- Create and deliver reports and presentations based on security status, including key performance indicators (KPIs), Key goal indicators (KGIs) and ISMS continual improvement.
- Engage in risk management processes, including risk identification, assessment, mitigation, and monitoring to ensure regulatory compliance and safeguard company assets.
- Conduct regular internal assessments against external regulations, frameworks, and best practices and identify with internal teams the right path to improve.
What you’ll need to be successful:
- A bachelor’s degree in information security, Computer Science, or a related field.
- At least five years of experience in an information security compliance-related role.
- Security and Compliance related certification such as: CISM or CISSP or ISO 27001 Lead Implementer, etc.
- Strong working knowledge of information security compliance frameworks, standards, and best practices, including ISO 27001, SOC 1/2, PCI DSS, and NIST.
- Excellent communication, analytical, and problem-solving skills.
- High attention to detail and accuracy.
- Ability to work independently and collaboratively with cross-functional teams.
- Experience in managing a global Information Security Management System.
- Knowledge and experience in implementing and managing ISO 27001 certification or SOC 1/2 compliance.
Your unique contributions are celebrated, driving collective success in our inclusive workplace.
Discover more on www.sidetrade.com
Agencies
Only applications from invited agencies through the Workable portal will be accepted. Unsolicited CVs sent directly to managers or HR will not incur any fees.