Head of IT Compliance

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ARRISE

ARRISE

5001 - 10000 employees

🎮 Gaming

🤝 B2B

Gaming • B2B

ARRISE is a global software developer and services company focused on the iGaming industry. With more than 11,000 professionals across 14 locations, they design and build casino products including award-winning slot games, immersive live-casino experiences, and high-performance platform solutions that scale from concept through execution. ARRISE combines creative game design and technical engineering to drive player engagement and support operators and partners in the online gambling sector.

📋 Description

• Lead and maintain the company’s ISO 27001 Information Security Management System (ISMS) and SOC 2 Trust Services Criteria certification programs • Serve as the primary point of contact for external and internal auditors during ISO 27001 certification and SOC 2 attestation processes • Plan and coordinate compliance audits, collect evidence, and provide comprehensive audit responses • Manage risk assessments, control testing, and remediation activities • Develop, maintain, and enforce IT security and compliance policies, procedures, and standards • Ensure documentation aligns with ISO 27001 Annex A controls and SOC 2 requirements • Respond to client security questionnaires • Oversee access control, change management, incident management, and third-party/vendor risk management • Ensure compliance across software development, hosting platforms, and APIs • Monitor security controls and recommend improvements to mitigate emerging risks • Act as liaison for external auditors, regulators, and certification bodies • Conduct internal compliance audits, gap assessments, and readiness reviews • Track and close compliance findings and audit issues • Provide guidance on ISO 27001 scope changes and corporate structure changes • Build compliance awareness across development, operations, and support teams • Deliver training on secure software development, data handling, and gaming industry standards • Assess compliance of key vendors and ensure contractual and SLA alignment with ISO 27001 and SOC 2 • Provide compliance updates, risk posture reports, client responses, performance metrics, and KPIs to senior management and stakeholders

🎯 Requirements

• Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field • 5+ years’ experience in IT compliance, GRC, risk management, or information security • Experience ideally in gaming, fintech, or other regulated industries • Strong understanding of ISO 27001:2022 Information Security Management System (ISMS) • Strong understanding of SOC 2 Trust Services Criteria • Proven track record leading certification and audit processes with direct auditor engagement • Experience responding to client security questionnaires and communicating compliance status • Experience with SaaS/PaaS environments, APIs, and cloud-based hosting services • Knowledge of secure SDLC, DevOps, and CI/CD compliance integration • Professional certifications such as CISA, CISM, ISO 27001 Lead Implementer/Auditor, CCSK, or CRISC preferred • Excellent knowledge of IT compliance, audit, and risk frameworks • Strong communication and stakeholder management skills • Ability to influence development, operations, and support teams to adopt compliance practices • Analytical problem-solving approach to compliance challenges • Detail-oriented documentation, evidence management, and client questionnaire response skills

🏖️ Benefits

• A highly competitive salary • Detailed company training on highest standards • Friendly and supportive culture • Tremendous growth opportunities in a large fast moving international company

Apply Now

Similar Jobs

🕒 March 21

Tether.to

11 - 50

₿ Crypto

💳 Fintech

💸 Finance

Head of Licensing and Regulatory Authorisations managing global authorisation strategy for Tether. Driving regulatory approval processes and leading a distributed team.