Find your next role
Strengthen your profile
SyncEzy
API & Integration Platforms (iPaaS)
See how your profile stacks up against this role.
We compared the job requirements to your profile to show where you're strong and where you fall short.
This is a remote position.
SyncEzy is a growing Integration Company in the B2B SAAS space, with a strong focus on the Construction, Trades, and Service Industries. We are fiercely independent & bootstrapped, NOT VC Funded. This is A TRUE Remote /work-from-home position. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly, easy-going culture.
We are looking for a hands-on Information Security & Compliance Analyst (GRC)
to take ownership of the day-to-day activities required to maintain our security and compliance posture. The role will support and coordinate compliance activities across SOC 2, ISO 27001 and Cyber Essentials, and will work closely with Engineering, DevOps, IT and management to keep controls operating effectively and evidence audit-ready throughout the year.
This is an execution-focused role. The successful candidate should be comfortable moving between policy work, evidence collection, endpoint/software compliance, risk tracking, access reviews and audit coordination. The Senior Engineering Manager will remain the management and escalation point, while the analyst becomes the primary owner of routine compliance operations and follow-up.
· Maintain year-round readiness for SOC 2, ISO 27001 and Cyber Essentials rather than treating compliance as a once-a-year audit exercise.
· Own routine compliance administration, evidence collection, control monitoring and follow-up so engineering leadership can remain focused on product delivery and technical management.
· Translate compliance requirements into practical actions for Engineering, DevOps and IT teams without creating unnecessary operational overhead.
· Identify gaps early, track remediation to closure and maintain clear documentation showing that controls are designed and operating effectively.
· 2–4 years of relevant experience in GRC, information security compliance, security assurance, IT audit or a closely related role.
· Practical exposure to at least one major security/compliance framework such as SOC 2 or ISO 27001; familiarity with Cyber Essentials is strongly preferred.
· Experience collecting, reviewing and organizing audit evidence and working with technical control owners.
· Strong documentation and policy-writing skills with attention to consistency and audibility.
· Working understanding of cloud environments, identity and access management, endpoint security, vulnerability management, logging, backups and change management.
· Ability to read technical evidence and ask the right questions without needing to be a software engineer or DevOps engineer.
· Strong ownership, follow-up and organizational skills; comfortable tracking multiple recurring compliance activities simultaneously.
· Clear written and verbal communication skills and the ability to work with both technical and non-technical stakeholders.
· Experience with compliance automation or GRC platforms such as Vanta, Drata, Sprinto or equivalent tools.
· Experience working in a SaaS, software-development or cloud-first organization.
· Familiarity with MDM / endpoint-management tooling and software inventory reviews.
· Exposure to AWS, Azure or other public-cloud security controls.
· Experience supporting customer security questionnaires or vendor-risk assessments.
· Relevant certifications such as ISO 27001 Internal Auditor / Lead Implementer, Security+, CISA, CRISC or similar are useful but not mandatory.
After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.
Marcus Rivera
Chief Revenue Officer

Defianx

Defianx

Sezzle

agilimo Consulting GmbH

Defianx

SyncEzy

SyncEzy