Back to search
SII Group Romania Linkedin · Posted 7d ago

Compliance Program Analyst

Romania

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Who we are:

Open-minded intellectuals who embrace emerging technologies on our mission to create innovative Software Engineering Solutions that will impact millions of users around the world.


We are looking for:

This role centers on validating that controls are designed and operating effectively across ITGC, ISP, and QMS domains. You'll test controls, review evidence, facilitate audits, field inquiries, support escalations, and contribute to control design conversations — making sure the right standards are understood, applied, and met.


What you will do:

  • Develop a deep understanding of internal Information Security Policy (ISP) and Controls Standard — and help product and technology teams understand and apply the requirements to their environments.
  • Test and validate that ITGC controls are designed effectively and operating as intended across key domains — Access Controls, System Development and Change Management, Cyber Security and Data Protection, Service Management, and Resilience.
  • Identity and access management — confirm that provisioning and de-provisioning, privileged access reviews, segregation of duties, and authentication mechanisms are in place and functioning as required.
  • Change management — verify that SDLC controls, change management procedures, emergency change processes, and application development security controls are designed appropriately and operating effectively.
  • Cyber security operations — validate that incident management, malware protection, vulnerability and patch management, encryption, certificate administration, and logging and monitoring controls meet ISP requirements.
  • Database and network controls — confirm that database configuration and administration, firewall configuration, and system performance monitoring are compliant and evidenced.
  • Validate that application penetration testing has been performed by independent third parties in accordance with ISP requirements. Review and validate the evidence, ensure it's complete and audit-ready, and provide it in support of audit requests. Escalate any gaps or concerns to the CPL.
  • Perform compliance checks to assess adherence against internal ISP, controls, and relevant standards — reviewing vulnerability scans, security control validations, and other evidence to confirm controls are met.
  • Evaluate control design and operating effectiveness. Document test results clearly and escalate deficiencies, gaps, or areas of concern to the CPL with practical recommendations.
  • Support control design conversations with product and technology teams — helping them understand what 'good' looks like and how to meet ISP and ITGC requirements before issues arise.
  • Support QMS control testing for both Global controls and Territory-specific controls (local and regional regulatory and operational requirements).
  • Validate that QMS controls are designed effectively and operating as intended across applicable territories — through walkthroughs, sample testing, re-performance, and inspection.
  • Review and validate QMS evidence for completeness, accuracy, and audit-readiness. Facilitate evidence delivery to auditors and QMS program owners as needed.
  • Coordinate with Global and Territory QMS program owners to understand control requirements, obtain testing populations, and align on timelines and deliverables.
  • Identify control gaps, exceptions, and deficiencies. Escalate findings to the CPL with actionable recommendations for remediation.
  • Track and support remediation of QMS findings across Global and Territory teams. Ensure closure aligns with program deadlines.
  • Stay current on territory-specific regulatory requirements and how they map to Global QMS control frameworks. Flag discrepancies or coverage gaps to the CPL.
  • Support the CPL in preparing QMS testing status reports and deliverables for Global and Territory leadership.
  • Facilitate internal and external audits — SOC 2, ISO 27001, 7216, and internal control reviews — on behalf of the CPL. That means fielding auditor inquiries, coordinating evidence requests, and ensuring smooth execution throughout the audit lifecycle.
  • Collect, review, and validate audit evidence to confirm it's complete, accurate, and aligned to the control requirements being tested. If something's missing or insufficient, follow up with control owners to close the gap.
  • Maintain audit-ready repositories of evidence, policies, control documentation, and test results — covering both ITGC and QMS testing artefacts.
  • Support walkthroughs and access reviews. Ensure teams are prepared, evidence is organized, and auditor questions are addressed promptly.
  • Serve as a responsive point of contact during audits — fielding questions, coordinating across teams, and escalating issues to the CPL when needed.
  • Help teams interpret and apply compliance requirements to their specific environments. Translate standards into practical, actionable guidance that makes sense for the teams implementing them.
  • Support control design conversations — helping teams understand what's required, what evidence they'll need to produce, and how to build controls that will meet testing and audit expectations.

Remediation support and continuous monitoring:

• Document remediation plans for audit findings, ITGC deficiencies, and QMS control gaps. Track progress through closure in coordination with product, control, and QMS owners.

• Follow up with stakeholders to validate that remediation activities have been completed effectively and meet timelines and SLAs. Escalate overdue items or high-risk issues to the CPL.

• Support the CPL in continuously monitoring applications and controls — confirming that compliance is maintained between audit cycles and that emerging risks are identified early.

• Proactively flag potential compliance risks and control weaknesses across ITGC, ISP, and QMS domains. Bring findings and recommendations to the CPL.


Stakeholder engagement and communication:

• Serve as a knowledgeable, approachable point of contact for IT, security, risk management, product teams, and Global and Territory QMS program owners on behalf of the CPL.

• Communicate complex compliance and control topics clearly and concisely.

• Support the CPL in rolling out compliance education and training to ATE stakeholders. Track completions and help drive awareness across the portfolio.

• Respond promptly and accurately to stakeholder inquiries with reliable compliance data.


Reporting, metrics, and data-driven insights:

• Prepare compliance status reports for the CPL and senior management — covering audit findings, ITGC and QMS control testing results, risk posture, and remediation progress.

• Maintain and update compliance dashboards, trackers, and monitoring tools so metrics stay current and actionable.

• Use data-driven metrics to evaluate control testing coverage and compliance program effectiveness. Surface insights and improvement opportunities to the CPL.


Policy, procedure, and access review support

• Help the CPL review and maintain compliance policies and procedures aligned to ISP, QMS, and regulatory frameworks.

• Support and coordinate quarterly and ad-hoc access reviews. Track results, exceptions, and alignment with access control standards.


What you must have:

• Education Bachelor's degree in business, information technology, information security, risk management, or a related field.

• Experience 2–4 years in compliance, IT audit, ITGC testing, QMS testing, or risk management — preferably within a regulated IT or product environment.

• Audit experience - Strong understanding of SOC 2, ISO 27001, and 7216. You've facilitated audits and validated evidence from preparation through remediation.

• ITGC and control testing - Demonstrated experience validating ITGC controls — access controls, change management, operations, SDLC, and resilience. You can assess whether controls are designed and operating effectively.

• QMS testing - Experience supporting or executing QMS control testing across Global and Territory-specific control frameworks. Familiarity with quality management principles and testing methodologies.

• ISP knowledge - Working knowledge of information security policies and control frameworks. You can interpret standards, help teams apply them, and validate compliance.

• Risk awareness - Ability to identify and escalate compliance and operational risks within a portfolio context.

• Proficiency in SOC 2, ISO 27001, 7216, and ISP control frameworks.

• Experience with ITGC and QMS testing methodologies — walkthroughs, sample testing, re-performance, and inspection.

• Familiarity with vulnerability scanning tools, penetration testing evidence review, and security monitoring.

• Proficient in Microsoft Office, evidence management platforms, GRC tools, and compliance reporting and dashboard tools.


Certifications (preferred)

• CISA (Certified Information Systems Auditor) — strongly preferred.

• CRISC (Certified in Risk and Information Systems Control).

• ISO 27001 Lead Auditor.

• ISO 42001 or QMS-related certifications.

• ITGC-specific training or certifications.


We really welcome open-minded and committed people:


• Eager to take on new challenges and learn new things

• Who put their heart, mind, and soul into everything they do

• Who enjoy sharing knowledge and understand the importance of teams.


***Only eligible candidates will be contacted to move forward in the recruitment process.

Join Now Our Team and Start Engineering Your Future!

#LI-AP1

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search