For Employers

Otonomee

Internal Audit & Compliance Manager ( Remote in Colombia )

Posted 7 hours ago
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review
AI Summary

The Internal Audit & Compliance Manager will own the day-to-day operation of governance, risk, and compliance programs, including managing ISO/IEC 27001, SOC 2, and PCI DSS frameworks. They will coordinate internal and external audits, conduct risk assessments, and provide objective assurance to senior leadership regarding control effectiveness.

About The Role

We are seeking an experienced Internal Audit & Compliance Manager to own the day-to-day operation of Otonomee’s governance, risk and compliance programmes. This role will be central to maintaining a strong, scalable control environment as the business continues to grow and expand its technology, data and AI capabilities.

 The successful candidate will manage our established ISO/IEC 27001 ISMS, maintain continuous audit readiness across PCI DSS and SOC 2, and support additional frameworks on our roadmap. The role will establish a risk-based internal audit programme, coordinate internal and external audits, operate the GRC platform, and ensure that controls, policies, risks, findings and supporting evidence are actively managed.

 

Working across technology, operations and corporate functions, the role will translate compliance requirements into practical controls and provide clear, objective assurance to senior leadership. It will also support client assurance through security questionnaires, RFP responses, vendor reviews and compliance reporting.

Success will be measured through sustained certification and attestation outcomes, effective control operation, timely remediation of findings and improved visibility of organisational risk. This is a high-impact opportunity for an experienced compliance professional who combines independent judgement with a pragmatic understanding of a fast-growing international business.

Reporting Line 

The role reports to the CTO for security programme delivery and technical oversight, with an independent assurance line to the CEO.


What you will do


  • Establish and run a planned internal audit programme across ISO 27001, PCI DSS, SOC 2, and additional frameworks in scope (e.g. HIPAA, HITRUST), including control testing, findings, and remediation tracking to closure.
  • Provide independent assurance to the CTO, CEO, and senior leadership on control effectiveness and compliance status.
  • Maintain continuous audit readiness and coordinate external audits and certification cycles end to end, acting as the primary point of contact for auditors.
  • Conduct risk assessments using risk-based methodologies; develop and track key risk indicators (KRIs) and mitigation plans.
  • Liaise with business process owners and technical teams to drive and track remediation of control gaps and audit findings.
  • Advise stakeholders and leadership on compliance gaps, risks, and their business impact, recommending pragmatic mitigations.
  • Prepare and present compliance reports for internal stakeholders (leadership and board) and external parties (auditors, clients, and regulators).
  • Run third-party and vendor risk reviews and ongoing monitoring.
  • Own security questionnaires and RFP compliance responses, and support client-facing assurance (Trust Centre).
  • Lead information-security awareness initiatives and strengthen the organisation's compliance culture.
  • Act as ISMS Coordinator, owning the day-to-day operation and continuous improvement of the ISO/IEC 27001 Information Security Management System, and safeguarding the confidentiality, integrity, and availability of company and client information as the programme's central objective.
  • Operate and administer the Drata GRC platform: integrations, control mapping, automated evidence collection, alerts, and the policy centre.
  • Cross-map controls across ISO 27001, SOC 2, PCI DSS, and additional frameworks to eliminate duplicated effort, and manage the roadmap for frameworks in pursuit (HIPAA, HITRUST, and any further standards adopted).
  • Own the SOC 2 programme against the Trust Services Criteria (security, availability, confidentiality, processing integrity, and privacy), maintaining evidence and control operation to an audit-grade standard.
  • Maintain the policy and procedure lifecycle: drafting, version control, review cadence, and employee acknowledgements.
  • Manage audit evidence and compliance documentation so that control operation is demonstrable at any point in the audit period.
  • As owner of the ISMS and compliance programme, uphold and enforce Otonomee's information security policies, lead the organisation's security-awareness and compliance culture, and ensure security incidents and control weaknesses are managed, escalated, and remediated to closure.

Your profile



Requirements & Experience

  • Proven experience (typically 8+ years) in internal audit, GRC, or information-security compliance, including in regulated environments.
  • Hands-on experience implementing and operating an ISO/IEC 27001 ISMS, including gap assessments and remediation roadmaps.
  • Working knowledge of SOC 2 and its Trust Services Criteria, with practical evidence and control-operation experience or a clear trajectory towards it.
  • Practical PCI DSS compliance experience: evidence validation, control documentation, and audit follow-up.
  • Demonstrated internal audit capability, ideally with a recognised internal-auditor qualification.
  • Experience with a GRC or compliance-automation platform (e.g. Drata or equivalent).
  • Strong command of risk-based methodologies, KRIs, control-effectiveness evaluation, and evidence management.
  • Experience working remotely with distributed, cross-functional teams in a global environment.
  • Data-protection / privacy experience (e.g. GDPR or equivalent) and awareness of financial-crime / AML-CTF contexts desirable.
  • Exposure to HIPAA, HITRUST, NIST CSF/RMF, or other security and healthcare frameworks desirable.

Key Competencies

  • Act as the single accountable owner of a cross-framework compliance programme.
  • Exercise objective, independent judgement and provide candid assurance.
  • Communicate compliance status clearly to leadership, auditors, and clients.
  • Translate framework requirements into practical, operational controls.
  • Balance control rigour with the pace and realities of a growing operation.
  • Be detail-oriented, evidence-driven, and methodical.
  • Quickly familiarise yourself with new compliance frameworks as they are adopted.
  • Proactively upskill and stay current with evolving regulations, controls, and audit expectations.


Why us?

  • Fully work from home role based in Colombia
  • A competitive salary
  • Benefits
  • Equipment provided
  • Home office allowance 
  • Online Gym and Wellbeing Studio
  • The opportunity for professional growth
  • Fun company events and team outings
  • Autonomy and Responsibility


OUR RECRUITMENT PROCESS


  1. 45 min Teams interview with the Recruitment Team
  2. Language test if applicable to the role
  3. Technical test 
  4. 45 min Teams interview with the Hiring Team



 


About us

Otonomee is an award-winning Customer Management Outsourcing business delivering scalable, tech-driven, and people-focused solutions. Over the past year, we were proud to win the CCMA Best Employee Engagement Award and to rank number 10 in the Deloitte Fast 50. Through our remote-first operating model, we help organisations optimise customer interactions, reduce costs, and increase efficiency, combining automation and data-driven insight with a strong human focus.

Founded in 2020 by Aidan and Hilary O’Shea, Otonomee was created to challenge the traditional “big city, big building” BPO model. Instead, we offer a nimble, bespoke service that isn’t limited by contact-centre capacity. Our flexible approach allows us to scale quickly, respond to seasonal or product-led demand, and support clients wherever their markets take them.

Otonomee is built to be better for people, partners, and the planet. We have been a certified B Corp since September 2023 and were recently recognised as an EY Entrepreneur of the Year finalist. In just five years, we have grown to more than 650 employees, representing 55 nationalities across Europe, America and Asia.

We work with leading Irish and major US technology and e-commerce brands with complex global needs, supporting them with high-quality, premium customer experiences.

At Otonomee, equality, diversity, and inclusion are central to how we operate. We foster a culture of dignity, respect, and openness, where different perspectives are valued and everyone is encouraged to be curious, bold, and heard. 
Together, we grow.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Legal jobs →

Remote, Contract-based California Civil & Probate Litigation Paralegal Opportunity

Freelance United States $30 per hour Legal

The Associate Counsel - Contracts

Full Time United States Legal

VP Legal & Regulatory Affairs -ESH(Must Live In New York)

Full Time United States $150K - $300K per year Legal

Compliance Manager

Full Time United States $65000 - $75000 per year Legal

HRPP Regulatory Compliance Analyst

Full Time United States Legal

Senior Contract Specialist (Remote) - Office of the Vice Chancellor for Research

Full Time United States Legal
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 220,782+ Jobs in Compliance Manager

Answer easy questions

Answer easy questions

220,782+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified