Logo for Software Mind

[8PP] Compliance Specialist

Role overview

Qualifications

  • Experience supporting SOC 1 and SOC 2 audits
  • Experience with information security policies and enterprise risk management
  • Background working in software-driven environments involving cloud applications and SaaS platforms
  • CISSP, CRISC, or CISA certification

Responsibilities

  • Manage the lifecycle of Information Security policies
  • Coordinate the annual SOC 1 and SOC 2 attestation processes
  • Support risk intake, assessment, documentation, tracking, and reporting
  • Manage third-party risk assessments and ongoing vendor monitoring

About the company

Software Mind logo

Software Mind

Software Mind is a global digital transformation partner with operations throughout Europe, the US and LATAM. Driven by tech and empowered by people, we provide companies with software engineers and autonomous, cross-functional development teams who manage software life cycles from ideation to release and beyond. For over 20 years we’ve been enriching organizations with the talent they need to boost scalability, drive dynamic growth and bring disruptive ideas to life. Our top-notch engineering teams combine ownership with leading technologies, including cloud, AI, data science and embedded software to accelerate digital transformations and boost software delivery. A culture, driven by trust, that embraces openness, craves more and acts with respect enables our experts to create evolutive solutions that support scale-ups, unicorns and enterprise-level companies around the world.

Company details

Company typeLarge
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Company Description

We are Software Mind, an awesome team of engineers who are ready to ramp up any top-notch company’s projects! Our aim? To always be one step ahead. Become part of a multicultural company in constant growth with an excellent work environment certified by Great Place To Work!

Job Description

We are looking for an experienced Information Security Governance, Risk, and Compliance Specialist to support our security and compliance initiatives. The primary focus of this role will be facilitating the organization’s 2026 SOC 1 and SOC 2 audits, along with supporting policy management, enterprise risk, and vendor risk activities.

This role involves working across Security, IT, Operations, Finance, Legal, and Procurement to coordinate external audits, maintain security policies, manage enterprise and vendor risks, and strengthen the organization’s overall compliance program.

Information Security Policy Management

  • Manage the lifecycle of Information Security policies, including reviews, updates, approvals, publication, and version control.
  • Coordinate urgent policy changes and annual policy review cycles.
  • Maintain policy records and approval documentation to support governance and audit readiness.
  • Track outstanding actions and improve policy management workflows, templates, and review processes.

External Audit Coordination

  • Coordinate the annual SOC 1 and SOC 2 attestation processes and other external audits.
  • Manage audit timelines, evidence collection, documentation, stakeholder coordination, and auditor requests.
  • Partner with control owners to validate control performance and address findings, exceptions, and remediation activities.
  • Maintain audit evidence repositories and support the preparation of control descriptions, management narratives, and responses.
  • Escalate significant risks, control gaps, and audit blockers to the CISO and relevant leadership.

Security Risk Management

  • Support risk intake, assessment, documentation, tracking, and reporting.
  • Maintain risk registers and workflows within Full Circle, UpGuard, Drata, Vanta, or similar GRC platforms.
  • Track remediation plans, target dates, control gaps, and overdue actions.
  • Prepare risk dashboards, metrics, and status reports for leadership.
  • Improve risk scoring, reporting, workflows, and platform utilization.

Vendor Risk Management

  • Manage third-party risk assessments, due diligence, and ongoing vendor monitoring.
  • Review vendor security documentation and track remediation activities.
  • Collaborate with Procurement, Legal, IT, and business teams on onboarding and renewal decisions.
  • Escalate critical vendor risks, exceptions, and unresolved concerns.

Qualifications

  • Experience supporting SOC 1 and SOC 2 audits, including evidence collection, control validation, and auditor coordination.
  • Experience with information security policies, enterprise risk management, and vendor risk assessments.
  • Background working in software-driven environments involving cloud applications and SaaS platforms.
  • Experience with GRC platforms such as Full Circle, UpGuard, Drata, or Vanta.
  • Strong organizational, communication, and stakeholder-management skills.
  • Ability to manage multiple priorities independently and handle sensitive information with discretion.
  • CISSP, CRISC, or CISA certification.

#LI-DNI

Additional Information

Nice to Have

  • Hands-on experience with Full Circle or UpGuard, particularly for risk assessments.
  • SaaS, cloud security, or compliance certifications.

This is expected to be a short-term engagement through the end of 2026

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Compliance Officer Related jobs

Other jobs at Software Mind

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.