Compliance Officer/Data Protection Officer
About Wingify: At Wingify, we’re building SaaS (Software as a Service) products - VWO from India used by thousands of brands in more than 90 countries worldwide. We’re proudly outcompeting several international counterparts to clock more than USD 20mn in annual revenue without any external funding in our industry.
Over the last 11 years, VWO by Wingify has helped create industry standards in A/B testing products and has helped brands grow their website conversions by our suite of products across testing, website insights, and engagement. Now VWO is the world's first conversion optimization platform that marketers use to optimize conversion rate and sales on their websites. With 5000+ paying clients, VWO is enabling an experiment and data-driven approach in growing organizations. VWO's latest version combines multiple features in one package: A/B testing, heatmaps, Session Recordings, Funnels, Form Analytics, Push Notifications, Server-Side Testing, idea prioritization.
We at VWO owe our growth to our customers, and building their trust is our top priority. We understand the importance of data in today’s ever-evolving digital landscape and its significance to our customers’ operations and thus, keeping it secure and compliant is paramount to us.
Our compliance offerings go beyond standard certifications. VWO regularly undergoes independent verification of its security, privacy, and compliance control to meet the customers' needs. We strive to achieve certifications, attestations of compliance and undergo regular audits for all relevant standards, regulations, and frameworks around the globe.
Check our compliance and security page to know more details.
https://vwo.com/compliance and https://vwo.com/security
We are looking for a candidate with experience in the Information Security and Compliance domain.
This role will be part of the Corporate Security and Compliance group. It will be responsible for assisting with the information governance and compliance of the company’s information security, privacy, and related activities. The candidate should know about information technology, security, and privacy compliance management framework such as ISO/IEC 27001, ISO/IEC 27701, PCI DSS, SOC, NIST, COBIT, ITIL, GDPR, CCPA, HIPAA, etc. requirements, experience in performing and facing audits, designing action plans for control weaknesses, implementing /auditing Cloud Security Controls, technical skills relevant to the cybersecurity, and cloud security, writing skills for documenting technical policies, procedures, process, and guidelines.
Also, we are looking for a candidate who values attention to detail and delivers quality work within agreed timescales. They must be well presented, with the capacity to work on their initiative and interact closely with personnel from various departments/teams.
To succeed in this role, you should have the following skills and experience
- At least 7-9 years of relevant experience in information security, privacy & data protection, or related functions (e.g., IT audit, IT Risk Management, and IT Compliance)
- Experience with Information Security Management Systems (ISO/IEC 27001) and familiarity with Privacy Information Management Systems (ISO/IEC 27701), NIST, RBI, framework
- Practical experience in Laws and regulations on privacy, data protection, breach notification (GDPR, CCPA, etc.), and familiar with other regulations/acts of US, Europe, and APAC region regulations/act requirements.
- Knowledge of security legislation/industry standards such as SSAE18/SOC2, PCI-DSS, HIPAA, NIST, and CSA CCM/STAR, desirable.
- Develop and manage enterprise-wide Information Security & Privacy policies, standards, and guidelines in accordance with global & organizational regulatory requirements and industry-leading practices.
- Develop and manage Privacy program and Information Security Management System.
- Drive Information Governance connects with Business and Senior Management
- Drive Information Security and Privacy Compliances Awareness of enterprise-wide or Employees.
- Perform due diligence on counterparties and the necessary risk assessments.
- Answer Security and Privacy questionnaires from customers, prospective customers, vendor suppliers, and partners.
- Maintain a structured store of historical Sec questionnaires to facilitate timely, qualified new responses and input into the process of continuous improvement.
- Perform audit projects according to Wingify's audit methodology, focusing on integrated audit approach of security & privacy compliance controls, global processes, and computerized information systems.
- Ability to apply a risk-based approach to planning, executing, and reporting on audit engagements and auditing processes.
- Prepare regular compliance reports to provide consolidated reports to executive management.
- Supervise regional or national regulatory developments and provide suggestions on compliance.
- Help in Internal Business Growth and development.
- Excellent understanding of how different business units integrate into the strategic vision, business trends, and the direction
- Manage external certifications audits like ISO 27001 and ISO 27701 standards.
- As appropriate, identify opportunities for continuous improvement of information security, privacy, business continuity standards. The ability to build and maintain positive relationships with key internal clients, including business teams, legal, operations and application security teams
- Possess the skill to multitask and prioritize
- Experience in dealing with the regulators and auditors would be preferable.
- Learn quickly and apply knowledge to new situations Ability to work autonomously with flexibility and excellent judgment
- Ability to work effectively under pressure to meet deadlines
- Ability to solve problems quickly and automate processes
- Ability to work cooperatively as part of a team
What we look for in people
Critical thinking, openness to unlearn and learn, collaborate seamlessly across borders, enjoy working in a remote and fast-paced environment, curious and passionate about solving customer problems.
We will also be looking for the individual to have the following;
- Highest ethical standards
- Professional, proactive, flexible, diligent, and dependable
- Ability to problem solve and exercise good judgment
- Excellent interpersonal and presentation skills
- Ability to adapt to changing business and regulatory environments
- Ability to work with minimal supervision