Senior Compliance Analyst

You will manage the day-to-day execution of ISO 27001 and ISO 42001 compliance programs, including evidence collection, control testing, and audit coordination. You will work with third-party auditors and European regulators, maintain policies and control documentation, identify compliance gaps, and drive remediation. You will conduct vendor risk assessments, prepare customer security questionnaire responses, translate European regulations into actionable controls, monitor regulatory changes, advise stakeholders, educate colleagues, and help shape the international compliance roadmap.

Responsibilities

  • Own day-to-day execution of ISO 27001 and ISO 42001 compliance programs
  • Collect evidence, test controls, and coordinate audits
  • Manage audit timelines, requests, and remediation tracking with third-party auditors and European regulators
  • Build and maintain policies, procedures, and control documentation
  • Identify compliance and control gaps and drive remediation with stakeholders
  • Support continuous monitoring and automation of compliance evidence collection
  • Conduct third-party risk assessments for new and existing vendors
  • Draft and maintain responses to customer security questionnaires and due diligence requests
  • Lead compliance efforts against GDPR, DORA, NIS 2.0, and the EU AI Act
  • Monitor European and international regulatory developments
  • Advise stakeholders on the impact of new or amended regulatory requirements
  • Translate regulatory risk into actionable work across engineering, legal, and sales
  • Educate and mentor colleagues on European regulatory requirements
  • Help shape the compliance roadmap as Taxbit expands internationally

Requirements

  • Fluency in English and native fluency in a main European language
  • 5+ years of experience in compliance, information security, audit, or risk management
  • 3+ years of hands-on experience supporting ISO 27001 and ISO 42001 audits and certification maintenance
  • Working knowledge of GDPR, DORA, NIS 2.0, and the EU AI Act
  • Understanding of AI agentic workflows and related risk, control, and governance considerations
  • Experience conducting or supporting third-party and vendor risk assessments
  • Bachelor’s degree in a technical, business, or related field
  • Experience with GRC or compliance automation platforms
  • Knowledge of ISO 27001, ISO 42001, NIST CSF, and/or SOC 2
  • Strong written communication skills and experience drafting policies, procedures, and questionnaire responses
  • Experience with AI governance frameworks such as the NIST AI Risk Management Framework
  • Working knowledge of a scripting language such as Python is a plus
  • Experience in fintech, digital assets, or another highly regulated industry is a plus

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available