Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Ataccama

Security and Compliance Manager

Ataccama

. Run Ataccama's security compliance program, including the audit calendar, control framework, security and compliance risks, and executive reporting materials .

Posted 9/29/2026full-timePrague • CzechiaMid-LevelSeniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing security compliance programs, including ISO 27001, SOC 2, and NIST CSF frameworks, while effectively leading teams and communicating complex concepts to diverse stakeholders. Proficient in risk management, compliance assessments, and regulatory requirements, with a focus on building scalable workflows and ensuring customer assurance commitments.

Highest-signal resume keywords
ISO 27001 ComplianceSOC 2 Type II AssessmentNIST CSF ReportingRisk Management ProgramPeople Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information SecurityGRCIT AuditCompliance WorkflowsScriptingAutomationCloud SaaS PlatformsVulnerability ManagementData Privacy RegulationCybersecurity Regulation
Soft Skills
Written CommunicationVerbal CommunicationMentoringSupervisionCollaboration
Tools & Technologies
AWSAzureKubernetesCI/CDAI Tools
Certifications & Qualifications
ISO 27001 Lead AuditorISO 27001 Lead ImplementerCISACRISCCISSPCIPP/E
Industry Keywords
GxPDORAFFIECNERC CIPPCI DSSGDPRNIS2EU AI ActCRA

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityKubernetes

About the role

Key responsibilities & impact
  • Run Ataccama's security compliance program, including the audit calendar, control framework, security and compliance risks, and executive reporting materials
  • Coordinate internal and external SOC 1, SOC 2 Type II, ISO 27001:2022 and customer-driven assessments, including evidence collection, auditor logistics and remediation tracking
  • Operate the corporate risk management program, maintain the risk register, facilitate risk assessments and prepare quarterly NIST CSF 2.0-based reporting
  • Maintain the ISMS policy and standards library and keep it current against regulatory and customer-driven frameworks
  • Review security terms in customer contracts, schedules and addenda with Legal
  • Manage RFx and customer security questionnaire workflows, direct specialists and interns, and review high-stakes submissions
  • Assess and onboard compliance standards and regulations through control mappings, gap analyses and remediation plans
  • Support customer assurance commitments for regulated customers, including GxP validation lifecycle artifacts and Quality and Security Agreements
  • Build and maintain internal GRC workflows for scalable team output
  • Provide input into incident response and vendor risk management, including due diligence, playbooks, cost analysis and customer notifications
  • Manage a small team of compliance specialists and interns through supervision, allocation, quality review, mentoring and hiring
  • Drive security awareness and training initiatives, including secure use of AI tools
  • Liaise with Cloud and App Security, Engineering, Legal, Sales and Customer Success, translating audit, technical and business topics for non-specialists
  • Report to the CISO and collaborate with Cloud and App Security, Engineering, Cloud Operations, Product Management and internal IT

Requirements

What you’ll need
  • 3+ years of experience in information security, GRC, IT audit or compliance
  • Able to grasp both business and technical concepts, and distill what matters
  • Hands-on with standards and frameworks such as ISO 27001, SOC 2 and NIST CSF, and with at least one customer-driven framework (GxP, DORA, FFIEC, NERC CIP or PCI DSS)
  • Capable of reading and interpreting legal and regulatory texts, with working knowledge of data privacy and cybersecurity regulation (GDPR, NIS2/ZoKB, EU AI Act, CRA)
  • Experience scripting, automating or building scalable compliance workflows; responsible use of AI tools and ability to set guardrails
  • Technical fluency discussing cloud SaaS platforms, AWS, Azure, Kubernetes, CI/CD, vulnerabilities, identity and access, and common security threats
  • Strong written and verbal English communication skills; Czech is a plus for ZoKB and local partners
  • Experience supervising or mentoring specialists or interns, including hiring
  • Relevant certifications such as ISO 27001 Lead Auditor or Lead Implementer, CISA, CRISC, CISSP or CIPP/E are a plus
  • People management skills and experience are welcome

Benefits

Comp & perks
  • Long-Term Incentive Program
  • 2 sick days and 25 days of vacation, with the option to request additional Flexible Time-Off days when needed
  • The Global Family Support Program - a paid leave program to help all parents focus on the new addition to their family
  • Flexible working hours & hybrid work setup
  • Benefit Plus - flexible employee benefit platform (incl. Multisport card)
  • Annual package for mental health support
  • "Bring Your Friend" referral program
  • Shared company cards for free entrance to Prague Zoo & Botanical garden
  • Company bikes, longboards, e-scooters
  • Conference tickets to the best industry events of the year
  • Online courses & company access to Udemy to hone your skills
  • Access to paid AI tools
  • Company library, where you can even suggest the best educational books for us to order
  • Kitchens stocked with fresh fruit and juice, teas, and the best coffee
  • Company laptop
  • Company mobile phone + SIM card & package of mobile data