
1 - 10 employees
Founded 2018
💼 Consulting
🏥 Healthcare
📣 Marketing
Consulting • Healthcare • Marketing
Change by Degrees is a digital learning platform focused on upskilling and engaging organizations to become leaders in sustainability. Co-founded by Dr. Tara Shine and Madeleine Murray, the platform helps businesses respond effectively to sustainability regulations and metrics through comprehensive training courses that cover social, environmental, governance, and economic topics. Change by Degrees aims to empower employees at all levels, ensuring they have the knowledge and confidence needed to meet climate goals and foster a culture of sustainable practices within their companies.
🔥 14 hours ago
Improve your chances of getting an interview by checking your resume score before you apply.

1 - 10 employees
Founded 2018
💼 Consulting
🏥 Healthcare
📣 Marketing
Consulting • Healthcare • Marketing
Change by Degrees is a digital learning platform focused on upskilling and engaging organizations to become leaders in sustainability. Co-founded by Dr. Tara Shine and Madeleine Murray, the platform helps businesses respond effectively to sustainability regulations and metrics through comprehensive training courses that cover social, environmental, governance, and economic topics. Change by Degrees aims to empower employees at all levels, ensuring they have the knowledge and confidence needed to meet climate goals and foster a culture of sustainable practices within their companies.
• Own the day-to-day operation of Otonomee’s governance, risk and compliance programmes • Maintain a strong, scalable control environment as the business expands its technology, data and AI capabilities • Establish and run a planned internal audit programme across ISO 27001, PCI DSS, SOC 2, and additional frameworks such as HIPAA and HITRUST • Provide independent assurance to the CTO, CEO, and senior leadership on control effectiveness and compliance status • Maintain continuous audit readiness and coordinate external audits and certification cycles end to end • Act as the primary point of contact for auditors • Conduct risk assessments using risk-based methodologies; develop and track KRIs and mitigation plans • Liaise with business process owners and technical teams to drive remediation of control gaps and audit findings • Advise stakeholders and leadership on compliance gaps, risks, business impact, and pragmatic mitigations • Prepare and present compliance reports for leadership, the board, auditors, clients, and regulators • Run third-party and vendor risk reviews and ongoing monitoring • Own security questionnaires and RFP compliance responses and support client-facing assurance through the Trust Centre • Lead information-security awareness initiatives and strengthen the compliance culture • Act as ISMS Coordinator, owning the ISO/IEC 27001 ISMS and its continuous improvement • Operate and administer the Drata GRC platform, including integrations, control mapping, automated evidence collection, alerts, and policy centre • Cross-map controls across ISO 27001, SOC 2, PCI DSS, and additional frameworks • Manage the roadmap for frameworks in pursuit, including HIPAA and HITRUST • Own the SOC 2 programme against the Trust Services Criteria • Maintain the policy and procedure lifecycle, including drafting, version control, review cadence, and employee acknowledgements • Manage audit evidence and compliance documentation • Uphold and enforce information-security policies and ensure incidents and control weaknesses are escalated and remediated to closure • Report to the CTO for security programme delivery and technical oversight, with an independent assurance line to the CEO
• Proven experience (typically 8+ years) in internal audit, GRC, or information-security compliance, including in regulated environments • Hands-on experience implementing and operating an ISO/IEC 27001 ISMS, including gap assessments and remediation roadmaps • Working knowledge of SOC 2 and its Trust Services Criteria, with practical evidence and control-operation experience or a clear trajectory towards it • Practical PCI DSS compliance experience: evidence validation, control documentation, and audit follow-up • Demonstrated internal audit capability, ideally with a recognised internal-auditor qualification • Experience with a GRC or compliance-automation platform (e.g. Drata or equivalent) • Strong command of risk-based methodologies, KRIs, control-effectiveness evaluation, and evidence management • Experience working remotely with distributed, cross-functional teams in a global environment • Data-protection / privacy experience (e.g. GDPR or equivalent) and awareness of financial-crime / AML-CTF contexts desirable • Exposure to HIPAA, HITRUST, NIST CSF/RMF, or other security and healthcare frameworks desirable • Ability to act as the single accountable owner of a cross-framework compliance programme • Ability to exercise objective, independent judgement and provide candid assurance • Ability to communicate compliance status clearly to leadership, auditors, and clients • Ability to translate framework requirements into practical, operational controls • Ability to balance control rigour with the pace and realities of a growing operation • Detail-oriented, evidence-driven, and methodical approach • Ability to quickly familiarise yourself with new compliance frameworks • Proactively upskill and stay current with evolving regulations, controls, and audit expectations
• A competitive salary • Benefits • Equipment provided • Home office allowance • Online Gym and Wellbeing Studio • The opportunity for professional growth • Fun company events and team outings • Autonomy and Responsibility
Apply Now🕒 Yesterday
Regulatory Affairs Contractor supporting global medical-device registrations, lifecycle management, and integration compliance. Abstra provides Latin American tech talent to U.S. companies and beyond.
🇨🇴 Colombia – Remote
💰 $2.3M Seed Round - Abstra on 2022-01
⏰ Full Time
🟡 Mid-level
🟠 Senior
🚔 Compliance
🕒 August 10
Creative Quality & Compliance Specialist reviewing healthcare advertising for MLR compliance at Power Digital, a growth marketing and data intelligence firm. Managing Veeva PromoMats workflows, QA standards, and creative production coordination.
🕒 July 27
Regulatory Specialist navigating payments regulations across LATAM for fintech Localpayment. Responsible for maintaining payment licenses and ensuring compliance in multiple markets.
🗣️🇪🇸 Spanish Required