Lead and oversee compliance projects in accordance with relevant standards and frameworks (e.g., ISO 27001, ISO 27701, ISO 22301, ISO 13485, SOC2, NIST CSF, PCI DSS, GDPR, HIPAA, DORA, OWASP SAMM)
Develop, implement, and maintain comprehensive compliance policies, procedures, and guidelines aligned with regulatory and framework requirements
Conduct comprehensive internal audits and assessments to ensure regulatory and framework compliance, documenting findings and non-conformities
Provide clear, actionable recommendations for corrective and preventive actions and support stakeholders in implementing them
Collaborate with stakeholders to perform risk assessments and define appropriate controls
Develop, update, and implement advanced compliance training programs for employees
Support and enhance the compliance awareness program, promoting a strong compliance and security culture across the organization
Investigate, resolve, and provide guidance on complex compliance-related requests, incidents, and complaints
3+ years of experience in compliance management and implementation, preferably in IT, consulting, or related fields
Proficiency in some of the following standards and regulations: ISO 27001, ISO 27701, ISO 22301, ISO 13485, SOC2, NIST CSF, PCI DSS, GDPR, HIPAA, DORA
Proven ability to interpret compliance regulations and framework requirements and translate them into practical policies and controls
Experience in conducting compliance or security audits and assessments, including planning, execution, reporting, and follow-up
Experience in drafting and maintaining compliance policies, procedures, and related documentation
Experience in security consulting for multiple industries
Solid understanding of information security, risk management, and data protection principles
Upper-Intermediate English (spoken and written) and proficiency in Ukrainian
Strong documentation, presentation, and communication skills, with the ability to explain complex topics in a clear and structured way WILL BE A PLUS
Knowledge of OWASP frameworks
Hands-on experience with OWASP SAMM implementation in real projects
Professional certifications such as CISA, CISM, CISSP, or similar
PERSONAL PROFILE
Strong analytical and problem-solving skills, able to structure and prioritize complex tasks
Excellent communication and stakeholder management abilities
Detail-oriented with a strong commitment to accuracy and quality in documentation and processes
Ability to work independently, take ownership of initiatives, and drive them to completion
Comfortable working in cross-functional, distributed teams and managing multiple tasks in parallel
Proactive, responsible, and oriented toward continuous improvement of processes and controls