Internal Audit & Compliance Manager ( Remote in Colombia )

Otonomee

Colombia

A distancia

COP 120.000.000 - 180.000.000

Jornada completa

Hace 8 días
Generador de candidaturas

Consigue una respuesta de este empleador — un currículum y una carta de presentación adaptados exactamente a lo que busca para contratar.

Supera los filtros ATS

Descripción de la vacante

Otonomee is seeking an experienced Internal Audit & Compliance Manager to own governance, risk and compliance programmes across ISO 27001, PCI DSS and SOC 2. You will manage audits, controls, and evidence to enable continuous certification and client assurance.

The role reports to the CTO with an independent line to the CEO, coordinating across technology, operations and corporate functions to translate requirements into practical controls and timely remediation.

Formación

  • 8+ years in internal audit, GRC, or information-security compliance.
  • Hands-on ISO/IEC 27001 ISMS implementation and remediation roadmaps.
  • Practical PCI DSS and SOC 2 experience.
  • Experience with a GRC/automation platform (Drata or equivalent).

Responsabilidades

  • Establish and run a planned internal audit programme across ISO 27001, PCI DSS, SOC 2.
  • Provide independent assurance to CTO, CEO, and senior leadership on control effectiveness.
  • Maintain audit readiness and coordinate external audits end to end.
  • Conduct risk assessments; develop and track KRIs and mitigation plans.
  • Drive remediation of control gaps with process owners and tech teams.
  • Prepare compliance reports for leadership, board, auditors and clients.
  • Run third-party and vendor risk reviews and ongoing monitoring.
  • Own security questionnaires and RFP compliance responses.

Conocimientos

Internal audit
GRC
Information security
ISO 27001
SOC 2
PCI DSS
Risk assessment

Educación

Internal-auditor qualification

Herramientas

Drata

Descripción del empleo

We are seeking an experienced Internal Audit & Compliance Manager to own the day-to-day operation of Otonomee's governance, risk and compliance programmes. This role will be central to maintaining a strong, scalable control environment as the business continues to grow and expand its technology, data and AI capabilities. The successful candidate will manage our established ISO/IEC 27001 ISMS, maintain continuous audit readiness across PCI DSS and SOC 2, and support additional frameworks on our roadmap. The role will establish a risk-based internal audit programme, coordinate internal and external audits, operate the GRC platform, and ensure that controls, policies, risks, findings and supporting evidence are actively managed. Working across technology, operations and corporate functions, the role will translate compliance requirements into practical controls and provide clear, objective assurance to senior leadership. It will also support client assurance through security questionnaires, RFP responses, vendor reviews and compliance reporting. Success will be measured through sustained certification and attestation outcomes, effective control operation, timely remediation of findings and improved visibility of organisational risk. This is a high-impact opportunity for an experienced compliance professional who combines independent judgement with a pragmatic understanding of a fast-growing international business .

Reporting Line

The role reports to the CTO for security programme delivery and technical oversight, with an independent assurance line to the CEO.

What you will do
  • Establish and run a planned internal audit programme across ISO 27001, PCI DSS, SOC 2, and additional frameworks in scope (e.g. HIPAA, HITRUST), including control testing, findings, and remediation tracking to closure.
  • Provide independent assurance to the CTO, CEO, and senior leadership on control effectiveness and compliance status.
  • Maintain continuous audit readiness and coordinate external audits and certification cycles end to end, acting as the primary point of contact for auditors.
  • Conduct risk assessments using risk-based methodologies; develop and track key risk indicators (KRIs) and mitigation plans.
  • Liaise with business process owners and technical teams to drive and track remediation of control gaps and audit findings.
  • Advise stakeholders and leadership on compliance gaps, risks, and their business impact, recommending pragmatic mitigations.
  • Prepare and present compliance reports for internal stakeholders (leadership and board) and external parties (auditors, clients, and regulators).
  • Run third-party and vendor risk reviews and ongoing monitoring.
  • Own security questionnaires and RFP compliance responses, and support client-facing assurance (Trust Centre).
  • Lead information-security awareness initiatives and strengthen the organisation's compliance culture.
  • Act as ISMS Coordinator, owning the day-to-day operation and continuous improvement of the ISO/IEC 27001 Information Security Management System, and safeguarding the confidentiality, integrity, and availability of company and client information as the programme's central objective.
  • Operate and administer the Drata GRC platform: integrations, control mapping, automated evidence collection, alerts, and the policy centre.
  • Cross-map controls across ISO 27001, SOC 2, PCI DSS, and additional frameworks to eliminate duplicated effort, and manage the roadmap for frameworks in pursuit (HIPAA, HITRUST, and any further standards adopted).
  • Own the SOC 2 programme against the Trust Services Criteria (security, availability, confidentiality, processing integrity, and privacy), maintaining evidence and control operation to an audit-grade standard.
  • Maintain the policy and procedure lifecycle: drafting, version control, review cadence, and employee acknowledgements.
  • Manage audit evidence and compliance documentation so that control operation is demonstrable at any point in the audit period.
  • As owner of the ISMS and compliance programme, uphold and enforce Otonomee's information security policies, lead the organisation's security-awareness and compliance culture, and ensure security incidents and control weaknesses are managed, escalated, and remediated to closure.
Requirements & Experience
  • Proven experience (typically 8+ years) in internal audit, GRC, or information-security compliance, including in regulated environments.
  • Hands-on experience implementing and operating an ISO/IEC 27001 ISMS, including gap assessments and remediation roadmaps.
  • Working knowledge of SOC 2 and its Trust Services Criteria, with practical evidence and control-operation experience or a clear trajectory towards it.
  • Practical PCI DSS compliance experience: evidence validation, control documentation, and audit follow-up.
  • Demonstrated internal audit capability, ideally with a recognised internal-auditor qualification.
  • Experience with a GRC or compliance-automation platform (e.g. Drata or equivalent).
  • Strong command of ri
Consigue la evaluación confidencial y gratuita de tu currículum.

o arrastra y suelta tu archivo aquí

Similar jobs

Puestos de trabajo similares que vale la pena comparar

Remote Internal Audit & Compliance Leader (ISO 27001, SOC 2)
Remote Internal Audit & Compliance Leader (ISO 27001, SOC 2)

INGEPSY • Bogotá ciudad

A distancia
COP 120.000.000 - 190.000.000
Fully remote role
Equipment provided
Home office allowance
+3
Remote Internal Audit & Compliance Lead - ISO 27001 & SOC 2
Remote Internal Audit & Compliance Lead - ISO 27001 & SOC 2

Otonomee • Colombia

A distancia
COP 120.000.000 - 180.000.000
Sr Associate, Information Security Governance, Policy & Control
Sr Associate, Information Security Governance, Policy & Control

Auxis • Bogotá ciudad

Presencial
COP 200.880.000 - 334.800.000
INTERNAL CONTROL SPECIALIST RBS
INTERNAL CONTROL SPECIALIST RBS

SGS • Colombia

Presencial
COP 120.000.000 - 180.000.000
Third Party Risk Management Manager
Third Party Risk Management Manager

Auxis • Bogotá ciudad

Presencial
COP 90.000.000 - 140.000.000
Internal Security & Security Operations Engineer
Internal Security & Security Operations Engineer

UltaHost • La Guajira

Presencial
COP 120.000.000 - 240.000.000
AX-14 Sr. Associate, Information Security Governance, Policy & Control
AX-14 Sr. Associate, Information Security Governance, Policy & Control

Oceans Code Experts • Colombia

Presencial
COP 100.440.000 - 178.560.000
Compliance Admn. Assist
Compliance Admn. Assist

OP360 (OfficePartners360) • Perímetro Urbano Barranquilla

Presencial
COP 15.000.000 - 25.000.000
SOX Internal Control Coordinator
SOX Internal Control Coordinator

Amrize • Medellín

Presencial
COP 90.000.000 - 120.000.000
CyberSecurity Manager
CyberSecurity Manager

Lean Solutions Group • Colombia

Presencial
COP 120.000.000 - 200.000.000