You will take over the day-to-day running of Ataccama's security compliance team and GRC program within the Information Security team, reporting to the CISO. You own audits, risk management and the policy library.
Stack
Responsibilities
- ▹Run the security compliance program day to day: own the audit calendar, keep the control framework current, manage security and compliance risks and prepare materials for executive reporting and governance forums
- ▹Coordinate internal and external audits (SOC 1, SOC 2 Type II, ISO 27001:2022 and customer-driven assessments), including evidence collection, auditor logistics and tracking of findings through to remediation with control owners
- ▹Operate the corporate risk management program: maintain the risk register, facilitate periodic risk assessments with control owners, prepare quarterly risk reporting (NIST CSF 2.0 based) and surface cross-departmental risks for treatment decisions
- ▹Maintain the ISMS policy and standards library: author and revise core policies, coordinate scheduled reviews with control owners and keep them current against regulatory obligations (GDPR, NIS2/ZoKB, EU AI Act, CRA) and customer-driven frameworks (GxP, DORA, FFIEC, NERC CIP, PCI DSS)
- ▹Review security terms in customer contracts, security schedules and addenda with enterprise and regulated-industry customers, together with Legal
- ▹Manage the RFx and customer security questionnaire process: operate the workflow against established quality standards, direct the specialists and interns answering questionnaires and act as senior reviewer for high-stakes submissions
- ▹Assess and onboard new compliance standards and regulations: control mappings, gap analyses and remediation plans in coordination with Engineering, Cloud Operations and IT
- ▹Support customer assurance commitments for regulated customers, including GxP validation lifecycle artifacts and Quality and Security Agreements
- ▹Build and maintain internal GRC tooling so the team scales its output without adding headcount
- ▹Provide input into incident response and vendor risk management: vendor due diligence, incident playbooks and cost analysis, and customer notifications
- ▹Manage a small team of compliance specialists and interns, including work supervision, task allocation, quality review, mentoring and hiring
- ▹Help drive security awareness and training initiatives, including secure use of AI tools across the company
- ▹Liaise with Cloud and App Security, Engineering, Legal, Sales and Customer Success on compliance-impacting topics, translating between the audit, technical and business worlds for non-specialist audiences
Requirements
- ▹3+ years of experience in information security, GRC, IT audit or compliance
- ▹Able to grasp both business and technical concepts and distill what matters
- ▹Hands-on with standards and frameworks such as ISO 27001, SOC 2 and NIST CSF, and with at least one customer-driven framework (GxP, DORA, FFIEC, NERC CIP or PCI DSS)
- ▹Capable of reading and interpreting legal and regulatory texts, with working knowledge of data privacy and cybersecurity regulation (GDPR, NIS2/ZoKB, EU AI Act, CRA)
- ▹A builder: when a compliance task comes back for the third time, you script it, automate it or build a scalable workflow, and you use AI tools responsibly and can set guardrails for others
- ▹Technically fluent enough to talk to engineers about how a cloud SaaS platform is built and operated (AWS and Azure, Kubernetes, CI/CD, vulnerabilities, identity and access) and about common security threats
- ▹A strong communicator, comfortable writing policies and documentation, giving presentations and briefing executives, auditors and customers
- ▹Proactive, positive and self-organized; comfortable owning a whole agenda in a small team with few formalities
- ▹Experience supervising or mentoring specialists or interns, including hiring
- ▹Strong written and verbal English communication skills
Nice to have
- ▹Czech for ZoKB and local partners
- ▹Relevant certifications (e.g., ISO 27001 Lead Auditor or Lead Implementer, CISA, CRISC, CISSP, CIPP/E)
- ▹People management skills and experience
- ▹Experience in a tech company
Soft skills
Communication skillsProactivitySelf-organizationLeadership and mentoringTeamwork
What we offer
- ▹Long-Term Incentive Program
- ▹2 sick days and 25 days of vacation, with the option to request additional Flexible Time-Off days
- ▹Global Family Support Program: paid leave for new parents
- ▹Flexible working hours and hybrid work setup
- ▹Benefit Plus flexible benefit platform (incl. Multisport card)
- ▹Annual package for mental health support
- ▹Bring Your Friend referral program
- ▹Shared company cards for free entrance to Prague Zoo and Botanical Garden
- ▹Company bikes, longboards, e-scooters
- ▹Conference tickets to the best industry events of the year
- ▹Online courses and company access to Udemy
- ▹Access to paid AI tools
- ▹Company library where you can suggest books to order
- ▹Kitchens stocked with fresh fruit, juice, teas and coffee
- ▹Company laptop
- ▹Company mobile phone with SIM card and mobile data package
About the company
Ataccama is a data trust company: its Ataccama ONE platform unifies data quality, catalog, lineage, observability and reference data management. Its people are located across the globe, and its core values are Challenging, Fun, ONE Team, Customer Centric, Candid and Caring, and Aim High.
Languages: Angol: erős írásbeli és szóbeli, Cseh: előny
Similar jobs

Job
Cloud Expert
Vodafone
Azure Devops
+8
💰 Salary: not specified
🏢 On-site
Prague

Job
Manager, Technical Services
MongoDB
+1
💰 Salary: not specified
🏢 On-site
Gurugram
🗣️ EN

Job
Customer Reliability Engineer, Infrastructure - Hyderabad, India
Astronomer
+2
💰 Salary: not specified
🔀 Hybrid
Hyderabad
🗣️ EN

Job
AI Platform Architect, Madrid
knowmad mood
Vmware
💰 Salary: not specified
🏢 On-site
Madrid

Job
Cyber Analyst
Accenture Federal Services
Splunk
💰 Salary: not specified
🏢 On-site
Hill AFB
🗣️ EN

Job
Prodops Engineer 3
Black Duck Software, Inc.
ArgocdDatadog
+14
💰 Salary: not specified
🏢 On-site
Bangalore
🗣️ EN
