Security & Compliance Specialist
Prague, Czechia
Ataccama
Accelerate your organization’s business initiatives with trusted, high-quality, governed data.Our vision is to be the leading AI-powered cloud data management company and to do that, we’re making Ataccama a great place to work and grow. Our people are located across the globe. They succeed by collaborating as a team and thrive in our company culture defined by these core values:
Challenging FunONE TeamCustomer CentricCandid and CaringAim High
“Not all heroes wear capes. Some write policies.”
Do you understand the principles of information security, have previous compliance experience, and are eager to apply your expertise in a dynamic, diverse environment? Are you interested in working at the intersection of business and technology? Join our Information Security team and help us strengthen our Governance, Risk, and Compliance (GRC) capabilities.
This role offers you the opportunity to contribute to a maturing security program, work across departments, and help ensure that our organization continues to meet evolving regulatory and industry standards. You will cooperate with our Engineering, Cloud Operations, Product Management as well as internal IT on making sure our security compliance standards are not just defined and communicated, but practically implemented, automated, proactively monitored and reported.
Your Challenge
- Participate in the design and operation of our security compliance program.
- Support regular risk assessments, control reviews, and audits.
- Maintain documentation of policies, controls, and compliance evidence.
- Monitor compliance with internal policies and external regulations (e.g., GDPR, CCPA, ISO 27001, NIS2).
- Liaise with internal teams and external partners to collect and communicate security & privacy-related information.
- Help drive security awareness and training initiatives.
- Provide input into incident response and vendor risk management processes.
- Assist with RFP (Presale) process by means of filling the customer questionnaires on security/compliance topics.
Is This You?
- Able to grasp both business and technical concepts, and distill what matters.
- Curious, with a keen interest in information security and data protection.
- A strong communicator, comfortable writing documentation and giving presentations.
- Capable of reading and interpreting legal and regulatory texts.
- Proactive, positive, and self-organized — you don’t wait to be told what to do.
- Collaborative, but confident in taking initiative independently
- 2–4 years of experience in information security, IT risk management, audit, or compliance.
- Familiarity with standards and frameworks like ISO 27001, NIST CSF, SOC 2, or similar.
- Working knowledge of data privacy regulations (GDPR, CCPA, etc.).
- Awareness of common security threats (phishing, social engineering, malware, etc.).
- Strong written and verbal English communication skills.
- Relevant certifications (e.g., ISO 27001 Lead Implementer, CIPP, SSCP, or Security+) are a plus.
Why Join Us?
- Work in a forward-thinking and agile security team with a strong mandate and visibility.
- Help shape and scale a maturing GRC function.
- Collaborate with cross-functional teams on interesting and impactful projects.
- Enjoy flexibility, continuous learning, and opportunities for growth.
- Be part of a culture that values initiative, autonomy, and real impact.
Work equipment
- Company laptop
- Company mobile phone + SIM card & package of mobile data
Perks & Benefits
- Long-Term Incentive Program
- "Bring Your Friend" referral program
- Flexible working hours & flexible working setup
- The Global Family Support Program - A paid leave program to help all parents focus on the new addition to their family
- 2 sick days and 25 days of vacation, with the option to request additional Flexible Time-Off days when needed
- Flexipass or Multisport card (after finishing your probation period)
- Annual package for mental health support
- Shared company cards for free entrance to Prague Zoo & Botanical Garden
- Company bikes, longboards, e-scooters
- Online company language courses
- Conference tickets to the best industry events of the year
- Online courses & company access to Udemy to hone your skills
- Company library, where you can even suggest the best educational books for us to order
- Kitchens stocked with fresh fruit and juice, teas, and the best coffee
While we highly value cooperation with all our business partners, we don’t accept unsolicited resumes from any sources other than directly from a candidate. We reserve the right not to pay any fee for sending an unsolicited offer containing the details or resume of a job candidate, even if the relevant candidate is employed by our company.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Audits CCPA CIPP Cloud Compliance GDPR Governance Incident response ISO 27001 Malware NIS2 NIST Privacy RFPs Risk assessment Risk management SOC SOC 2 SSCP
Perks/benefits: Career development Flex hours Flex vacation Health care Snacks / Drinks Startup environment Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.