Sigma Software is looking for a Compliance Consultant to strengthen our governance, risk, and compliance practices. In this role, you will work with a wide range of international standards and regulations (such as ISO 27001, SOC 2, GDPR, and others), translating them into clear, practical controls, policies, and processes. You will conduct audits and assessments, advise stakeholders on compliance risks, support certification and customer due diligence activities, and contribute to awareness and training initiatives.
This position is a great fit for a specialist who enjoys working at the intersection of information security, regulations, and business needs, and who is ready to drive tangible improvements in a dynamic IT environment.
Job Description- Lead and oversee compliance projects in accordance with relevant standards and frameworks (e.g., ISO 27001, ISO 27701, ISO 22301, ISO 13485, SOC2, NIST CSF, PCI DSS, GDPR, HIPAA, DORA, OWASP SAMM)
- Develop, implement, and maintain comprehensive compliance policies, procedures, and guidelines aligned with regulatory and framework requirements
- Conduct comprehensive internal audits and assessments to ensure regulatory and framework compliance, documenting findings and non-conformities
- Provide clear, actionable recommendations for corrective and preventive actions and support stakeholders in implementing them
- Collaborate with stakeholders to perform risk assessments and define appropriate controls
- Develop, update, and implement advanced compliance training programs for employees
- Support and enhance the compliance awareness program, promoting a strong compliance and security culture across the organization
- Investigate, resolve, and provide guidance on complex compliance-related requests, incidents, and complaints
- 3+ years of experience in compliance management and implementation, preferably in IT, consulting, or related fields
- Proficiency in some of the following standards and regulations: IISO 27001, ISO 27701, ISO 22301, ISO 13485, SOC2, NIST CSF, PCI DSS, GDPR, HIPAA, DORA
- Proven ability to interpret compliance regulations and framework requirements and translate them into practical policies and controls
- Experience in conducting compliance or security audits and assessments, including planning, execution, reporting, and follow-up
- Experience in drafting and maintaining compliance policies, procedures, and related documentation
- Experience in security consulting for multiple industries
- Solid understanding of information security, risk management, and data protection principles
- Upper-Intermediate English (spoken and written) and proficiency in Ukrainian
- Strong documentation, presentation, and communication skills, with the ability to explain complex topics in a clear and structured way
WILL BE A PLUS - Knowledge of OWASP frameworks
- Hands-on experience with OWASP SAMM implementation in real projects
- Professional certifications such as CISA, CISM, CISSP, or similar
PERSONAL PROFILE
- Strong analytical and problem-solving skills, able to structure and prioritize complex tasks
- Excellent communication and stakeholder management abilities
- Detail-oriented with a strong commitment to accuracy and quality in documentation and processes
- Ability to work independently, take ownership of initiatives, and drive them to completion
- Comfortable working in cross-functional, distributed teams and managing multiple tasks in parallel
- Proactive, responsible, and oriented toward continuous improvement of processes and controls
Skills Required
- 3+ years of experience in compliance management and implementation
- Proficiency with standards and regulations: ISO 27001, ISO 27701, ISO 22301, ISO 13485, SOC2, NIST CSF, PCI DSS, GDPR, HIPAA, DORA
- Ability to interpret compliance regulations and translate them into practical policies and controls
- Experience conducting compliance or security audits and assessments (planning, execution, reporting, follow-up)
- Experience drafting and maintaining compliance policies, procedures, and documentation
- Experience in security consulting across multiple industries
- Solid understanding of information security, risk management, and data protection principles
- Upper-Intermediate English (spoken and written) and proficiency in Ukrainian
- Strong documentation, presentation, and communication skills
- Knowledge of OWASP frameworks (will be a plus)
- Hands-on experience implementing OWASP SAMM in real projects (will be a plus)
- Professional certifications such as CISA, CISM, CISSP, or similar (will be a plus)
Similar Jobs
What We Do
Sigma Software Group, an award-winning and trusted IT partner, has been serving customers for over 21 years, providing comprehensive IT solutions to various businesses, ranging from startups to established software product houses. As one of Europe's substantial IT consultancies, it brings together a dedicated workforce of over 2,100 professionals in 40 offices across 19 countries. With a diverse client base, including more than 300 enterprises, including Fortune 500 stalwarts, Sigma Software Group is a preferred choice for developing solutions that help businesses create cutting-edge products while meeting their unique needs. Sigma Software Group operates as a dynamic ecosystem of tech companies, offering 25 ready-to-implement innovative products and 40+ value-added services. Furthermore, Sigma Software Group is committed to fostering innovation through initiatives such as the Sigma Software Labs business incubator, Sigma Software University, the SID Venture Partners VC Fund, UA Tech Network, Techosystem, the European Business Association, and other collaborative efforts. Since 2015, Sigma Software Group has consistently earned recognition on the IAOP's prestigious World's Top 100 Outsourcing list. The company's accomplishments have also been acknowledged by prominent global media outlets such as Forbes, CNBC, The Times, and Reuters







