IT - IT Compliance Specialist

IT - IT Compliance Specialist

IT Compliance Specialist is responsible for ensuring that the organization‘s IT systems, processes, and controls comply with applicable regulatory requirements, industry standards, and internal policies. This role supports risk management, security governance, audits, and compliance initiatives to protect information assets and maintain business continuity.

Key Responsibilities

Compliance Management

  • Develop, implement, and maintain IT compliance programs, policies, standards, and procedures.
  • Ensure compliance with relevant regulations and standards such as ISO 27001, SOC 2, GDPR, PCI-DSS, HIPAA, SOX, and local regulatory requirements.
  • Monitor changes in regulatory requirements and assess their impact on the organization.

Audit & Assessment Support

  • Coordinate internal and external IT audits.
  • Prepare audit documentation, evidence, and reports.
  • Track audit findings and ensure timely remediation of identified gaps.
  • Conduct compliance assessments and control reviews.

Risk Management

  • Identify and evaluate IT compliance risks.
  • Perform risk assessments on IT systems, applications, and processes.
  • Recommend and monitor corrective actions to mitigate identified risks.

Policy & Control Governance

  • Develop and maintain IT policies, standards, and control frameworks.
  • Review and assess effectiveness of security and compliance controls.
  • Collaborate with IT and business teams to ensure controls are properly implemented.

Training & Awareness

  • Conduct compliance awareness training for employees.
  • Promote best practices related to information security and regulatory compliance.
  • Support compliance culture initiatives across the organization.

Documentation & Reporting

  • Maintain compliance records, risk registers, and audit documentation.
  • Generate regular compliance status reports for management.
  • Track compliance metrics and key performance indicators (KPIs).

Stakeholder Collaboration

  • Work closely with Information Security, IT Operations, Legal, Risk Management, and Business Units.
  • Support third-party/vendor compliance assessments.
  • Assist management in responding to regulatory inquiries and audits.

Required Qualifications

Education

  • Bachelor‘s degree in Information Technology, Information Security, Computer Science, Business Administration, or related field.

Experience

  • At least 3 years of experience in IT compliance, information security, IT audit, governance, risk management, or related areas.
  • Experience working with regulatory frameworks and compliance standards.

Technical Knowledge

  • Understanding of:
    • ISO 27001
    • NIST Cybersecurity Framework
    • COBIT
    • SOC 2
    • PCI-DSS
    • GDPR and data privacy regulations
    • IT General Controls (ITGC)

Skills

  • Strong analytical and problem-solving skills.
  • Excellent documentation and report-writing abilities.
  • Knowledge of risk assessment methodologies.
  • Strong communication and stakeholder management skills.
  • Ability to manage multiple projects and deadlines.

Preferred Certifications

  • CISA (Certified Information Systems Auditor)
  • CISM (Certified Information Security Manager)
  • CRISC (Certified in Risk and Information Systems Control)
  • CISSP (Certified Information Systems Security Professional)
  • ISO 27001 Lead Implementer or Lead Auditor
  • Certified Compliance & Ethics Professional (CCEP)

Nộp đơn ứng tuyển công việc này

Họ & tên bạn *
Địa chỉ email *
Số điện thoại *
Ngày tháng năm sinh *
Trình độ học vấn (Education)  *
Bạn biết đến cơ hội ứng tuyển này qua kênh nào?  *
CV của bạn *
Click để chọn & tải lên CV của bạn
Nộp đơn ứng tuyển