About the job
About the Role
- We are seeking a Senior Security Compliance Engineer to strengthen the governance, risk, and compliance framework at UniUni. Your role will be pivotal in maintaining our ISO 27001 certification and SOC 2 Type II attestation, ensuring our policies are up-to-date, instilling confidence in our customers, and fulfilling our regulatory requirements.
- This role is hands-on and crucial to our operations. While the Information Security Officer designs the compliance program, you will be responsible for its execution. This includes managing audit cycles, overseeing evidence collection, driving policy updates, leading customer security assessments, executing our third-party risk management program, and supporting privacy and compliance initiatives. We're looking for an individual who embraces automation, communicates clearly, and approaches compliance as a significant engineering challenge.
What You'll Do
- Core GRC Responsibilities: Oversee the operations of the ISO 27001 program, including preparation for surveillance audits, conducting internal audits, performing annual risk assessments, managing review meetings, and tracking corrective actions.
- Manage the SOC 2 Type II program operations, which entails continuous control monitoring, collecting evidence, and preparing for audits.

