Audit and Compliance Lead - ISO -Virtual
Alight SolutionsAbout the role
Our story
At Alight, we believe a company’s success starts with its people. At our core, we Champion People, help our colleagues Grow with Purpose and true to our name we encourage colleagues to “Be Alight.”
Our Values:
Champion People – be empathetic and help create a place where everyone belongs.
Grow with purpose – Be inspired by our higher calling of improving lives.
Be Alight – act with integrity, be real and empower others.
It’s why we’re so driven to connect passion with purpose. Alight helps clients gain a benefits advantage while building a healthy and financially secure workforce by unifying the benefits ecosystem across health, wealth, wellbeing, absence management and navigation.
With a comprehensive total rewards package, continuing education and training, and tremendous potential with a growing global organization, Alight is the perfect place to put your passion to work.
Join our team if you Champion People, want to Grow with Purpose through acting with integrity and if you embody the meaning of Be Alight.
Learn more at careers.alight.com.
Summary
As a member of Alight Global Security’s Security & Compliance team, this position will provide help manage ISO audits and the applicable controls. With a deep understanding of leading audits, this role, will provide guidance to subject matter experts within Alight on what they need to do to meet and demonstrate each control and help speak to and present collected evidence with various auditors. Additionally, this role would lead any necessary gap assessments, compliance readiness, and compliance monitoring activities through internal audits.
Responsibilities
- Ability to manage parts of Alight’s ISO audit program
- Gains a deep understanding in Alight technology, security, and business operations to aid in audits and verifying ISO compliance
- Work with business leaders and other stakeholders to ensure ISO security standards are embedded in business operations and delivery.
- Interpret patterns of ISO non-compliance to determine impact on levels of risk and work with the appropriate resources to drive higher levels of compliance.
- Provides coaching and mentorship to team members and stakeholders on their controls and the application of them
- Provides input into industry best practices for managing compliance in today's landscape
- Help lead the design, documenting and assessment of audit controls
- Develop testing procedures for assessing the design and operating effectiveness, completeness, accuracy/validity, and timeliness of control outputs
- Identify & escalate any new or emerging gaps in policy or control environment & provide expert advice on new requirements
- Develop and maintain findings library to support analysis, trends
- Drive remediation and risk mitigation planning, execution and oversight
- Provide remediation and policy/control guidance to Alight stakeholders
- Escalate and plan for potential ISO program changes
- Leads, delivery of audit milestones to ensure audit timelines stay on target by escalating and identifying roadblocks
- Leads, the identification of business process improvements and partners with technology and business stakeholders to identify pragmatic approaches to compliance readiness and testing
- Collaborates cross-functionally with technology and business stakeholders to drive, track, and resolve all aspects of compliance readiness and audit execution
- Provides control guidance to technology and business stakeholders to lead them in providing the expected and appropriate evidence
- Interfaces with internal and external auditors for audit activities
- Conducts various IT Compliance controls validation
- Collaborates with technology and business stakeholders along with other Compliance team members to facilitate remediation and execution of corrective action plans
- Participates in continuous improvement initiatives
- Develops metrics and dashboards for reporting on assigned compliance programs
- Manage several projects simultaneously with a sense of urgency
- Comfortable dealing with ambiguity
- Ability to work on a diverse team or with a diverse range of coworkers
Qualifications
- 5+ years of experience in IT audit and/or compliance, with a concentration on ISO 27001, 22301, and 27701 a plus
- Must possess a strong background in security audit
- Experience with control assessments an
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s