Senior Compliance Specialist New
Listed on 2026-08-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Single Store is building a real-time data platform that helps organizations transact, analyze and act on data in a single system. We are committed to operating with strong security, privacy and resilience standards across our products, services and internal operations.
We are seeking an experienced and highly motivated Senior Compliance Specialist to help scale our security, privacy and compliance programs. This role will be responsible for maintaining key certifications, driving cross-functional compliance initiatives, overseeing development and management of our privacy program, supporting compliance with the Digital Operational Resilience Act (DORA), and helping mature our Business Continuity Management System (BCMS).
The ideal candidate is practical, organized and collaborative, with experience translating regulatory and framework requirements into durable operational processes across technical and business teams.
Job ResponsibilitiesSupport governance activities across the security, privacy and compliance program, including maintaining Information Security Management System documentation, evidence, policies, procedures and audit trails.
Help maintain and improve active certifications and attestations such as ISO/IEC 27001, SOC 2 Type II, HIPAA and PCI DSS, while coordinating with stakeholders across the business to ensure ongoing compliance.
Drive readiness efforts for new compliance objectives, certifications and customer-driven assurance requirements.
Participate in enterprise risk management activities, including risk methodology, risk assessments, treatment planning and follow-up with risk owners.
Oversee the development, implementation and ongoing management of Single Store’s privacy program in partnership with Legal, Security, IT and business stakeholders.
Support compliance with applicable privacy and data protection requirements, including operationalizing controls and processes needed to meet regulatory and contractual obligations.
Lead and coordinate DORA-related compliance activities, including control mapping, gap assessments, remediation tracking, evidence collection and cross-functional readiness planning.
Help develop, maintain and mature the company’s Business Continuity Management System (BCMS), including associated governance, documentation, testing coordination and continuous improvement activities.
Support vendor risk and third-party security management activities.
Help define corrective action plans and track remediation of audit findings, non-conformities and control gaps with accountable owners.
Contribute to security and compliance awareness initiatives and internal training efforts.
Partner closely with Legal to support regulatory, contractual and policy compliance obligations across the business.
Communicate compliance priorities, expectations and status clearly to technical, business and executive stakeholders.
Basic Qualifications3+ years of experience in security, privacy or compliance.
2+ years of experience working for an Independent Software Vendor, SaaS provider or other technology company.
Strong understanding of security and compliance frameworks and regulations such as ISO 27001, SOC 2 Type II, HIPAA, PCI DSS, GDPR, CCPA and DORA.
Experience with compliance operations, audits, risk management processes and control-based programs.
Experience coordinating cross-functional work streams and driving follow-through across engineering, IT, legal and business teams.
Working knowledge of cloud technologies and managed service environments.
Strong written and verbal communication skills, with the ability to present clearly to both technical and non-technical audiences.
Preferred QualificationsExperience supporting compliance for managed cloud services or regulated technology environments.
Experience building or operating a privacy program, business continuity program or related governance framework.
Experience with DORA, business continuity, resilience, incident response governance or operational risk programs.
Familiarity with and ability to support compliance initiatives related to the EU AI Act, NIST AI RMF, ISO/IEC 42001 and other emerging AI governance, risk and compliance…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).