FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates extensive expertise in IT compliance, audit management, and regulatory frameworks, with a strong focus on FDA 21 CFR Part 11 and GxP data integrity requirements. Proficient in leading audits, managing compliance programs, and automating evidence collection to ensure adherence to industry standards.
Highest-signal resume keywords
IT Compliance ManagementFDA 21 CFR Part 11 ExpertiseGxP Data IntegritySOC 1 and SOC 2 AuditsISO/IEC 27001 Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Audit ManagementRisk-Based ValidationValidation PlansRequirements TraceabilityEvidence Collection AutomationControl MappingChange ManagementData HandlingInternal AuditsPolicy Writing
Soft Skills
CommunicationCollaborationProblem-SolvingLeadership
Tools & Technologies
GRC PlatformAWSGCPAzureCI/CD Tools
Certifications & Qualifications
CISAISO/IEC 27001 Lead AuditorISO/IEC 42001 Lead AuditorASQ CQACISSP
Industry Keywords
GxPAI GovernanceFDA GuidanceISO/IEC 42001NIST AI RMFEU AI ActAudit TrailsElectronic SignaturesALCOA+ PrinciplesNonconformities
Tech Stack
Tools & technologiesAWSAzureCloudGoogle Cloud Platform
About the role
Key responsibilities & impact- Own and scale mpathic’s compliance and audit programs
- Plan and run the annual audit and certification cycle for SOC 1, SOC 2, ISO/IEC 27001, ISO/IEC 42001, and Part 11 readiness
- Select auditors, define scope, collect evidence, manage fieldwork and management responses, and deliver final reports or certificates
- Own Part 11 compliance for systems creating, modifying, or storing regulated records
- Maintain system inventories and GxP impact assessments
- Lead risk-based validation and keep validation documentation current through releases and system changes
- Maintain a unified control set mapped across applicable frameworks
- Run risk-based internal audits, ISO-required internal audits, and management reviews; track nonconformities and CAPAs through closure
- Partner with engineering and delivery teams on change management, code review, access reviews, release validation, and data handling
- Automate evidence collection where possible and monitor control health
- Maintain mpathic’s ISO/IEC 42001 AI management system, including AI risk and impact assessments and model lifecycle control documentation
- Own security questionnaires, customer and sponsor quality audits, compliance-related RFP and contract responses, and the trust center
- Own the GRC platform and integrations, including control mappings, automated evidence collection, and policy workflows
- Maintain certification and regulatory policies and SOPs
- Deliver compliance training, including Part 11 and GxP training
- Monitor FDA guidance, AI governance requirements, and applicable data privacy laws and translate changes into recommendations
Requirements
What you’ll need- 7+ years in IT compliance, GRC, audit, or computerized systems validation, including direct ownership of external audits from scoping through final report or certification
- Hands-on experience applying FDA 21 CFR Part 11 and GxP data integrity requirements to software or SaaS systems, including audit trails, electronic signatures, access controls, record retention, and ALCOA+ principles
- Familiarity with FDA Computer Software Assurance (CSA) guidance, GAMP 5, and EU Annex 11 is a strong plus
- Experience writing or leading validation plans, requirements traceability, risk-based test evidence (IQ/OQ/PQ or CSA-style), and validation summary reports
- Experience supporting customer or sponsor audits of validated systems
- Experience leading or supporting SOC 1 and SOC 2 Type II examinations and ISO/IEC 27001 certification or surveillance audits
- Experience with ISO/IEC 42001 or other AI governance frameworks, including NIST AI RMF or the EU AI Act, is a strong plus
- Comfortable reviewing cloud configurations across AWS, GCP, or Azure; IAM policies; CI/CD and change management records; logging; and infrastructure as code
- Able to plan and execute internal audits, sample and evaluate evidence, write clear findings, and drive CAPAs through closure
- Comfortable representing mpathic with external auditors, certification bodies, customers, and sponsor quality teams
- Able to write policies, findings, and customer responses
- Certifications such as CISA, ISO/IEC 27001 Lead Auditor or Lead Implementer, ISO/IEC 42001 Lead Auditor, ASQ CQA, or CISSP are a plus
