
Compliance Manager
- Kuala Lumpur
- Permanent
- Full-time
- Domain Knowledge and Leadership: The Compliance manager will manage and expand the Nintex Compliance Program and be responsible for the entire compliance lifecycle from gap analysis to audit complete. This includes preparing the company for new compliance frameworks. An essential part of the role will also include highly visible demonstration of technical and business leadership of compliance gap analysis, remediation plans, audits, documentation, self-assessment and other audit activities. This role will also be responsible for coordinating and reviewing all evidence gathering for Nintex audits. Furthermore, this role is expected to coach and train a team of compliance analysts to leverage automation and metric development for accelerated compliance delivery to executive stakeholders (legal, finance, IT).
- Global Stakeholder Management: In this role the Compliance Manager will be required to advise geographically separated departments (ex. Engineering, Corp IT, Product, Sales, Human Resources and Legal departments) on how to meet controls and maintain testing the effectiveness of those controls at all levels. In addition, the Compliance Manager will manage, scope and engage third party audits associated with compliance requirements in the Risk Management Program and assist with the Vendor Risk Management reviews for evaluating vendor compliance reports and calculating the risk and impact to Nintex.
- Adhere to Nintex Standards and Practices: The Compliance Manager will be the leading voice in Nintex Governance and Risk Committee (GRC) in the writing, editing, and reviewing of the information security policies and guidelines. They will also support compliance integration activities for company acquisitions.
- Risk Management and Mitigation: In this role, the Compliance Manager will be expected to initiate the security reviews and risk assessment processes for new projects and technologies to ensure compliance. The role will also be responsible for providing timely advice and recommendations to relevant stakeholder groups on potential risks to Nintex and propose risk mitigation strategies for implementation globally or regionally.
- You may be directed to perform other reasonable tasks by the Director of Security and Compliance.
- 7+ years of experience in information security, cybersecurity, transparency reporting, integrity, and/or technology risk including one or more domains (e.g., access management, vulnerability management, change management, business continuity, application security, asset management).
- Expertise in common compliance standards, e.g. ISO27001/270017/270018, SOC 2, NIST CSF and PCI DSS
- Experience with SQL and Sharepoint
- Experience with Azure DevOps and AKS would be beneficial
- Strong knowledge of the global data security regulatory environment
- Global Gratitude and Recharge Days
- Flexible, paid time off policy
- Employee wellness programs and counseling resources
- Meaningful peer recognition and awards
- Paid parental leave
- Invention/patenting assistance
- Community impact, paid volunteer time, and opportunities
- Intercultural learning and celebration
- Multiple tools through which to learn and grow, and an incredible global community