Develop and execute a comprehensive IT internal audit strategy covering technology, security, privacy, and compliance risks.
Lead end-to-end audit engagements, including planning, risk assessment, fieldwork, reporting, and remediation follow-up.
Manage and enhance IT ICFR/SOX compliance programs, ensuring effective control design and regulatory readiness.
The company is a fast-growing technology organization in the SaaS and fintech sectors. It fosters a culture of innovation, collaboration, and continuous improvement, with a focus on diversity and inclusion.
Design, implement, and maintain a world-class internal controls framework for ICFR.
Serve as the foremost subject matter expert on Internal Control over Financial Reporting.
Build scalable, audit-ready processes to meet SEC/PCAOB standards and support IPO readiness.
Anchorage Digital is a crypto platform that enables institutions to participate in digital assets through custody, staking, trading, governance, settlement, and the industry's leading security infrastructure. The company is funded by leading institutions including Andreessen Horowitz, GIC, Goldman Sachs, KKR, and Visa, with its Series D valuation over $3 billion and employs over 600 people.
Perform testing and validation of ITGC and security controls.
Assess control effectiveness and support remediation efforts.
Support internal and external audits including SOC 2 and ISO 27001.
Marlabs is a global AI and Digital Solutions Consulting firm that delivers intelligent solutions across AI, data, analytics, and product engineering. Since 2000, they have partnered with large organizations worldwide, fostering a culture of innovation and collaboration.
Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.
Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.
You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
You will run the vulnerability management program and remediate security findings across AWS.
You will support security incident response, fraud investigations, and third-party risk assessments.
We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.
Support the design, assessment, and improvement of IT controls to strengthen technology governance and compliance.
Perform testing and validation of ITGC, security controls, and QMS controls, and assist with audit activities.
Collaborate with Engineering, Security, Product, Risk, and Quality teams to drive continuous improvement and risk management.
A global technology organization focused on digital environment and security. They operate with cross-functional teams across engineering, security, risk, and product.
Perform SOX 404 compliance activities including planning, walkthroughs, risk assessments, and control testing.
Conduct walkthroughs with business process owners to evaluate the design and effectiveness of key controls.
Identify control deficiencies, evaluate risk, and recommend practical remediation plans.
Del Playa Group is a U.S.-based professional services firm specializing in accounting, finance, and audit solutions. Headquartered in Orange County, California, the company helps clients expand capacity, strengthen controls, and elevate performance.
Own internal IT, security, and compliance strategy across the organization.
Lead the migration from MSP to an in-house IT function and manage a SecOps team.
Drive enterprise incident response, business continuity, and disaster recovery planning.
Karbon is the global leader in AI-powered practice management software for accounting firms. The company is well-funded, ranked #1 on G2, and has a people-first culture recognized with Great Place To Work certification and on Fortune's Best Small Workplaces list.
Lead the design and evolution of a multi-framework compliance offering for European businesses.
Drive end-to-end ISO 27001 implementations and manage a team of compliance specialists.
Act as a senior security partner to customers, sales, and product teams.
This company provides a security and compliance platform that helps modern businesses achieve certifications across frameworks like ISO 27001 and SOC 2. It is a fast-growing, remote-first technology environment with a strong emphasis on collaboration and team connection.
Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.
Perform ITGC and application control testing across SOC 2, SOC 1, and HIPAA engagements.
Assist in evaluating the design and effectiveness of IT controls.
Communicate with clients to request evidence, conduct walkthroughs, and clarify audit questions.
Insight Assurance is a global audit firm transforming cybersecurity and compliance. Founded by former Big 4 professionals, it is one of the fastest-growing firms with 170+ professionals serving nearly 2,000 clients.
Lead IT governance and risk management, including executive reporting and risk register maintenance.
Develop KPI and KRI dashboards to translate complex data into actionable insights for senior leadership.
Oversee ITSM governance, ServiceNow optimization, and vendor risk management.
Our partner is a global organization operating in a sophisticated Governance, Risk & Compliance environment, connecting technology, cybersecurity, privacy, and operational risk. It fosters a collaborative culture with a focus on work-life balance and professional development.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Act as a regional anchor for security compliance, managing controls and audits.
Develop and maintain security documentation, including policies and metrics.
Implement AI and automation to streamline compliance and security work.
Airwallex provides a unified payments and financial platform for global businesses, empowering over 250,000 companies with integrated solutions. With over 2,300 employees across 27 global offices, the company values innovation and ambitious work.
Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.
RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.
Manage the Compliance and Security workstream, coordinating SOC 2, ISO 27001, GDPR, and related audit-readiness activities.
Build and maintain execution plans with clear owners, milestones, dependencies, risks, and decision points.
Facilitate workshops, track evidence, and escalate risks to keep audits on schedule.
Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1000 full-time professionals across 25+ countries, the company maintains a culture of Relentless Performance and has achieved over 99% project success since 1989.
Perform technical ICFR and IT SOX testing, including IT general controls, access controls, segregation of duties, and program change.
Lead walkthroughs with control owners, document IT architecture, and evaluate control design and operating effectiveness.
Coordinate with management, IT, and external auditors to ensure timely completion of ICFR responsibilities and issue resolution.
Mercury Insurance helps people reduce risk and overcome unexpected events, with over 60 years of industry experience. The company is a midsize employer recognized as one of America's Best Midsize Employers for 2026, fostering a collaborative culture that values diverse perspectives.
Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
Lead external audits, develop security policies, and partner with engineering teams to implement controls.
Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.
10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.
Act as a trusted consultant guiding clients through complex security and compliance challenges.
Develop security strategies aligned with frameworks like CMMC, NIST 800-171, and NIST 800-53.
Design and implement AWS and/or GCP security tools with deep expertise in cloud security.
Aprio is a Top 20 CPA and advisory firm that provides compliance and advisory services to fast-growing industries. With over 3,200 team members across 40 US and international offices, they foster a top-rated culture and collaborative environment.