> Markdown version of [/jobs/ext/584003-it-compliance-manager](https://www.wearedevelopers.com/jobs/ext/584003-it-compliance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Compliance Manager - **Company:** Cirtec Medical Corporation - **Location:** Brooklyn Park, MN, United States - **Experience:** Expert - **Salary:** $80,000.0 - $95,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Software Vulnerability Management, Information Security Management System, RSA Archer Platform - **Published:** June 20, 2026 - **Apply:** https://www.juju.com/job/00000000g9hf4d ## About the Role Bachelors degree 5+ years in information security, risk, or compliance Experience managing SOC2 and/or ISO27001 programs Experience working with GRC platforms (Drata, Vanta, Secureframe, or similar) Experience coordinating external security audits Strong understanding of security control frameworks Experience managing risk registers and remediation tracking Strong documentation and organizational skills Ability to coordinate across technical and business teams Good to have: ISO27001 Lead Implementer or Lead Auditor CISA, CISM, or CRISC Experience working in regulated industries Experience supporting SOC2 Type II audits Familiarity with vulnerability management and security operations processes, Bachelor Degree ## Description Our dedicated teams prioritize growth, innovation, and collaboration. We actively seek opportunities for improvement to enhance our support for clients. If you embrace a growth mindset and thrive on challenges, you may be a perfect fit for our team!, We are seeking an IT Compliance Manager to lead and manage the organization's information security governance, risk, and compliance programs. This role will own and maintain our ISO27001 Information Security Management System (ISMS) and SOC2 compliance program, ensuring ongoing certification readiness and successful audit cycles. The role will manage our compliance program using Drata, coordinate with internal control owners, and serve as the primary liaison with auditors. This position works closely with IT, engineering, and business teams to ensure security controls are implemented, documented, and maintained across the organization. This role is focused on security governance and compliance program management, not hands-on infrastructure administration., Compliance & Certification Management Own and maintain the organization's ISO27001 ISMS Manage ongoing SOC2 Type II compliance program Maintain control framework within Drata Ensure evidence collection and control validation Coordinate external audit engagements Manage annual surveillance and recertification audits Maintain compliance documentation and audit artifacts Governance, Risk & Policy Management Maintain and update security policies and standards Manage the enterprise risk register and risk treatment plans Conduct periodic risk assessments Track remediation activities and control gaps Ensure alignment between policies, controls, and technical implementations Control Management & Internal Coordination Work with IT and engineering teams to ensure controls are implemented and functioning Assign and track control ownership across departments Monitor compliance posture using Drata dashboards and reports Coordinate evidence collection across control owners Facilitate internal compliance reviews Vendor & Third-Party Risk Manage vendor security review process Maintain vendor risk assessment documentation Support procurement with security due diligence Track vendor compliance obligations Security Program Support Coordinate security awareness training programs Support incident response documentation and post-incident reviews Assist with customer security questionnaires Provide support for regulatory and customer security inquiries ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What is the real price of one successful line of code?](https://www.wearedevelopers.com/videos/1921-what-is-the-real-price-of-one-successful-line-of-code) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager)