Remote Jobs RockRemote Jobs Rock

Program Manager-Security Operations & Compliance

๐Ÿ”ฅ 15 hours ago
ISO/IEC 27001SOC 2HIPAAGRC

๐Ÿ“œ Description

  • Maintain and develop Anovia's ISO/IEC 27001 Information Security Management System (ISMS).
  • Support ISO 27001, SOC 2, HIPAA, and other security and compliance initiatives.
  • Coordinate internal and external audit activities, preparing evidence and maintaining action items.
  • Monitor and improve security tooling and processes, including Microsoft 365 security capabilities.
  • Lead technical and operational initiatives from scope definition through implementation.

๐Ÿ› ๏ธ Requirements

  • 4+ years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related field.
  • Experience with GRC processes and tools, including risk and control management, evidence collection, compliance tracking, audit preparation, and remediation or corrective-action management.
  • Working experience with the Microsoft 365 security environment, including familiarity with Microsoft Defender, Intune, Entra ID, and related security and compliance capabilities.
  • Working knowledge of information security principles, risk management, access control, vulnerability management, incident response, and security awareness.
  • Comfortable working directly with auditors, technical teams, business stakeholders, vendors, and leadership.
  • Strong organizational and communication skills, with the ability to manage multiple ongoing activities and follow through on commitments.
  • Bachelor's degree in Information Security, Computer Science, IT, or a related field, or equivalent practical experience.
  • Experience with HIPAA Security and Privacy Rule requirements or other healthcare security and privacy requirements.
  • Experience with GRC platforms such as Secureframe, Vanta, Drata, or OneTrust.
  • Experience with SIEM, EDR/endpoint protection, vulnerability scanners, or related security tooling beyond the Microsoft 365 environment.

โœจ Benefits

  • Comprehensive Health Insurance policy
  • Employee Wellness Program with focus on mental health
  • Robust reward and recognition programs
  • Company incentive programs offered
  • Attractive leave policy: Holiday Leave
  • Maternity Leave
  • Paternity Leave
  • Birthday leave
  • Bereavement Leave and Paid Leave for personal time off
  • Ample growth and learning opportunities
Full job description

Anovia (formerly Innovatia Technical Services) is an industry-leading technology outsourcing support provider with expertise in the telecommunications industry. Operating for over 20 years, we specialize in workflow and knowledge processes, as well as technical support, helpdesk and multilingual support services. With over 200 professional experts across the globe, we service some of the worldsโ€™ most successful Fortune 500 and Fortune 1000 companies.

About the Role

Anovia is looking for a hands-on information security and compliance professional with practical experience working with ISO/IEC 27001, SOC 2, HIPAA, or similar security and compliance programs.

The successful candidate will have experience helping an organization prepare for and work through an audit or certification process, including developing and maintaining policies and controls, supporting evidence collection, coordinating activities and meetings, tracking actions, and working with internal and external auditors.

This is also a build and delivery role. Anovia has a number of technical and operational initiatives that require more structure, planning, coordination, and follow-through. The successful candidate will be comfortable taking an initiative that is not yet well defined, establishing a practical plan, coordinating the people involved, and driving the work through to completion. Examples could include implementing a new security tool, improving security monitoring or vulnerability management, or helping establish a NOC/SOC capability.

Responsibilities

  • Maintain and continue to develop Anovia's ISO/IEC 27001 Information Security Management System (ISMS), including policies, procedures, controls, risks, objectives, evidence, and ongoing improvement activities.
  • Support ISO 27001, SOC 2, HIPAA, and other security and compliance initiatives as they are introduced and developed.
  • Coordinate internal and external audit activities, including preparing evidence, scheduling and facilitating meetings, maintaining action items, and ensuring audit findings and resulting actions are addressed.
  • Maintain the information asset inventory and data classification program, including assigning and tracking ownership.
  • Support identity and access management activities, including provisioning and de-provisioning, access reviews, least-privilege requirements, and privileged access controls.
  • Monitor and improve security tooling and processes, including Microsoft 365 security capabilities, Microsoft Defender, Intune, Entra ID, security monitoring, endpoint protection, and vulnerability management.
  • Coordinate vulnerability identification, remediation tracking, and escalation of significant findings.
  • Coordinate third-party and vendor security assessments, including security questionnaires and contract review support.
  • Develop, maintain, and support adoption of information security policies, standards, and operating procedures.
  • Coordinate security awareness training and phishing simulation programs.
  • Support security incident response activities, including detection, containment, investigation, root-cause analysis, and post-incident reporting.
  • Support business continuity and disaster recovery activities, including maintenance of recovery requirements, testing, and related evidence.
  • Lead or coordinate technical and operational initiatives from initial scope through implementation, establishing plans, identifying dependencies and owners, coordinating stakeholders, tracking risks and issues, and driving work to completion.
  • Serve as a primary point of contact for internal and external auditors and coordinate responses with relevant business and technical stakeholders.

Required Qualifications

  • 4+ years of progressively responsible experience in information security, IT compliance, GRC, security operations, or a related field.
  • Practical experience working with ISO/IEC 27001, SOC 2, or a comparable security and compliance framework. Experience should include meaningful participation in an audit or certification process and familiarity with activities such as policy development, control implementation, evidence collection, audit preparation, management meetings, action tracking, and remediation.
  • Experience with GRC processes and tools, including risk and control management, evidence collection, compliance tracking, audit preparation, and remediation or corrective-action management.
  • Working experience with the Microsoft 365 security environment, including familiarity with Microsoft Defender, Intune, Entra ID, and related security and compliance capabilities.
  • Demonstrated ability to take an ambiguous technical or operational initiative and bring structure to it, including defining scope, developing a practical plan, coordinating stakeholders, managing dependencies and issues, and driving the work through to completion.
  • Working knowledge of information security principles, risk management, access control, vulnerability management, incident response, and security awareness.
  • Comfortable working directly with auditors, technical teams, business stakeholders, vendors, and leadership.
  • Strong organizational and communication skills, with the ability to manage multiple ongoing activities and follow through on commitments.
  • Bachelor's degree in Information Security, Computer Science, IT, or a related field, or equivalent practical experience.

Nice to Have

  • Experience with HIPAA Security and Privacy Rule requirements or other healthcare security and privacy requirements.
  • Experience with GRC platforms such as Secureframe, Vanta, Drata, or OneTrust.
  • Experience with SIEM, EDR/endpoint protection, vulnerability scanners, or related security tooling beyond the Microsoft 365 environment.
  • Experience with NIST CSF or other complementary security frameworks.
  • Experience managing contractors or vendors during technical or security initiatives.
  • Experience helping establish or improve security monitoring, NOC, SOC, or similar operational capabilities.
  • Experience with business continuity and disaster recovery planning.

Certifications

Certifications are useful supporting evidence of knowledge, but are not a substitute for practical experience. Relevant certifications include:

  • ISO/IEC 27001 Lead Implementer or Lead Auditor
  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)

Relevant certifications are preferred but not require

Benefits at Anovia

  • Comprehensive Health Insurance policy
  • Employee Wellness Program with focus on mental health
  • Robust reward and recognition programs
  • Company incentive programs offered
  • Attractive leave policy: Holiday Leave, Maternity Leave, Paternity Leave, Birthday leave, Bereavement Leave and Paid Leave for personal time off
  • Ample growth and learning opportunities
  • Remote work opportunities
  • Focus on work/life balance
  • Immigration Program supporting immigration to Canada for eligible employees

We thank all candidates for their interest, however, only those selected for an interview will be contacted.
Anovia is an equal opportunity employer.

Mindoula Health

Behavioral Health Program Manager, Nevada License

๐Ÿ•’ yesterday
Mindoula Health๐Ÿ‘ฅ 201 - 500 employees๐Ÿข Hospital & Health Care

The Program Manager leads a team of Therapists and Care Extenders to implement programs that empower members in their health and wellness through personalized case management.

Management And ComplianceRelationship ManagementProblem SolvingCommunication
Mindoula Health

Behavioral Health Program Manager

๐Ÿ•’ 5 days ago
Mindoula Health๐Ÿ‘ฅ 201 - 500 employees๐Ÿข Hospital & Health Care

The Behavioral Health Program Manager leads a remote care team to implement programs, empower members in their health journey, and achieve operational and clinical outcomes.

Management And ComplianceRelationship ManagementProblem SolvingCommunication
Wiz

Strategy & Operations Program Manager, Global Technical Enablement

๐Ÿ•’ 5 days ago
Wiz๐Ÿ‘ฅ 1001 - 5000 employees๐Ÿข Computer & Network Security

As the Strategy & Operations Program Manager for Global Technical Enablement, you will build and manage the operating system that supports the organization's strategic initiatives and operational efficiency.

Business OperationsTechnical Program ManagementBudget TrackingVendor Management
STEM Learning

STEM Ambassadors HE & National Programmes Coordinator

๐Ÿ•’ 5 days ago
STEM Learning๐Ÿ‘ฅ 501 - 1000 employees๐Ÿข Education Management

The STEM Ambassadors HE & National Programmes Coordinator will develop partnerships with universities and create outreach initiatives to inspire young people in STEM education.

Public EngagementProject ManagementSTEM EducationCommunication Skills
Socure

Program Manager, Org Effectiveness & Insights

๐Ÿ•’ 6 days ago
Socure๐Ÿ‘ฅ 10,000+ employees๐Ÿข Software Development๐Ÿค B2B

The Program Manager for Organizational Effectiveness & Insights is responsible for managing engagement survey programs, enhancing organizational health, and implementing change management practices.

Program ManagementPeople AnalyticsEngagement SurveysChange Management

Trusted by Remote Workers