Compliance Assurance Manager (CAM)
SOV01 - Sofia Business Park B9 (SOV01), Bulgaria
DXC Technology
DXC Technology helps global companies run their mission-critical systems and operations while modernizing IT, optimizing data architectures, and ensuring security and scalability across public, private and hybrid clouds.Job Description:
About DXC Bulgaria
We are DXC - a Fortune 500 global IT services leader. In Bulgaria, we are among the largest employers with over 4,000 employees working on the company's entire IT portfolio. We are flexible - we provide everything you need to comfortably work from home, but we also keep our offices open for collaboration, meetings, and building a strong team spirit. We tailor everyone’s development path to their individual interests through training and additional certifications.
Our experience and desire to grow, our mission, and our values create an environment where ambitious people become successful at home. At home - in Bulgaria.
About the role
The Compliance Assurance Manager (CAM) supports audit and compliance activities including client audits, internal DXC audits, and compliance reviews, provides data in support of audit activities, and generates evidence of Security Training and user attestation. The CAM generates and presents audit and compliance data for regular governance and review meetings. The CAM is responsible for understanding the controls and data artifacts associated with the account and develops and implements the program to collect, record, and report upon the artifacts.
Working hours: 13:00 – 22:00 (1 hour lunch break included)
Daily challenges / not more than 5-6 bullets/
- Audit Management
Act as liaison between external (customer) auditors and DXC teams and coordinate collection of audit evidence and collaboration between teams and external auditors. Ensure audit activities are performed according to contractual obligations. Lead remediation activities as per the vendor recommendations.
- Client Relationship Management
Act as a single point of contact for Audit and compliance for the customer security representative. Maintain good relationship with the customer by meeting their contractual requirements and enhance their current and future security posture.
- Account Responsibilities
Work with account leads and delivery teams to address security audit and compliance issues. Raise the awareness of the account team of the security best practices and standards.
- Risk Management
Communicate with the account Risk Manager any risk identified throughout audits or compliance activities.
Experience and skills required / not more than 5-6 bullets/
- A minimum of 3 years professional experience in Information Security or IT Audit
- Experience in at least one of the industry standards or laws (e.g. ISO27001, PCI-DSS, SOX, HIPAA, ISAE3402 Type II, CCPA, Swiss FADP, ADA and local regulations)
- Practical experience in Project Management
- Fluent in English
- Excellent teamworking skills
- High ethical standards
- Strategic thinking
- Leadership skills
- Certificates considered an advantage: CISA, ISO27001 LA, CISM, CISSP, CompTIA Security+
Company benefits
- Competitive remuneration package
- Additional Medical & Life insurance
- 4 days additional paid leave (total: 24 days)
- The possibility to work entirely remotely.
- Food vouchers
- Training, continuous learning and career development in the largest IT company on the market
- Unlimited access courses from a bunch of external partners for the best learner's experience (e.g., LinkedIn Learning, Udemy)
- Access to a foreign language learning platform
- Stable employment in an international company
- Advancement opportunities within the organization (a variety of interesting projects with the array of technologies and tools)
- Flexibility in work arrangement (hybrid or fully remote work, the home office culture is in our DNA)
- Workplace equipment to organize your home office (e.g., chair, desk, additional monitor, headset etc.)
- DXC Partner courses and certifications (Microsoft, SAP, ServiceNow, AWS, Google, Dell Technologies, IBM, Microfocus, Salesforce, Red Hat, VMware, Workday)
- Employee Referral Program - a financial bonus for the referrer for successful candidate recommendation
- Employee Recognition Program with points assigned by colleagues for the recognized employees (exchangeable for prizes)
- Employee Assistance Program (providing 24/7 support for employees and their families in difficult life situations)
- Opportunity to join our numerous charity and ecology-related events organized by our Employee Ambassadors team
We Deliver eXcellence for our Customers and colleagues every day. Our values form the foundation of everything we do and every decision we make.
If you see yourself working with us, do not delay sending us your CV in English.
At DXC our employees’ safety and well-being remain a key priority for us. Therefore, we continue with stay-at-home recruiting and video interviewing for the foreseeable future.
Please note, only shortlisted candidates will be contacted.
Recruitment fraud is a scheme in which fictitious job opportunities are offered to job seekers typically through online services, such as false websites, or through unsolicited emails claiming to be from the company. These emails may request recipients to provide personal information or to make payments as part of their illegitimate recruiting process. DXC does not make offers of employment via social media networks and DXC never asks for any money or payments from applicants at any point in the recruitment process, nor ask a job seeker to purchase IT or other equipment on our behalf. More information on employment scams is available here.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits AWS CCPA CISA CISM CISSP Compliance CompTIA Governance HIPAA ISO 27001 Red Hat Risk management SAP SOX VMware
Perks/benefits: Career development Flex hours Gear Lunch / meals Medical leave Salary bonus Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.