Skip to content Skip to footer

Skillset

Information Security & Data Privacy Compliance (ISO 27001, HIPAA, GDPR, CCPA) Experience: 3 – 5 yrs of relevant experience

Overview

NStarX is seeking a detail-oriented and proactive Compliance Officer to own and drive the organization’s information security and data privacy compliance program. The candidate will conduct internal audits, coordinate external audits with certification and regulatory bodies, and implement and maintain ISO 27001, HIPAA, GDPR, and CCPA standards and policies across the organization. This role acts as the primary link between delivery teams, leadership, and external auditors/agencies, and requires hands-on experience with at least one major compliance framework, strong communication skills, and the ability to translate regulatory requirements into practical, adopted policies.

Responsibilities

  • Plan and conduct periodic internal audits across departments to assess compliance with ISO 27001, HIPAA, GDPR, and CCPA requirements, and track findings through to closure.
  • Coordinate with external certification bodies for external/surveillance audits and recertification, serving as the primary point of contact.
  • Implement, maintain, and improve ISO 27001, HIPAA, GDPR, and CCPA policies, procedures, and controls across the organization.
  • Ensure NStarX maintains continuous compliance with its certifications and applicable regulatory and legal requirements, including timely closure of audit actions and renewal of certifications. ▪ Coordinate with delivery, engineering, IT, and HR teams to ensure security and compliance best practices are followed in day-to-day operations and project delivery.
  • Provide compliance insights, risk updates, and status reports, including a monthly compliance report and dashboard to the leadership team.
  • Conduct onboarding compliance training for new joiners and enroll all employees in the annual compliance and security awareness training program, tracking completion.
  • Develop and update training materials, awareness content, and internal guidance documents as needed.
  • Support incident management and breach notification processes, ensuring timely reporting in line with ISO27001, HIPAA, GDPR, and CCPA requirements where applicable.
  • Manage third-party and vendor risk assessments, ensuring vendors and subprocessors meet applicable compliance obligations.
  • Track changes to regulatory requirements and frameworks (e.g., ISO/IEC 27001:2022, HIPAA, GDPR, CCPA updates) and update internal policies and controls accordingly.
  • Maintain a compliance calendar covering audit cycles, policy review dates, training deadlines, and certification renewal timelines, including risk registers and risk treatment plans.

Skills and Experience

  • 3 – 5 years of experience in Governance, risk & compliance (GRC) roles.
  • Hands-on experience implementing or maintaining at least one of ISO 27001, HIPAA, GDPR, or CCPA, exposure to multiple frameworks is preferred.
  • Understanding of ISMS documentation, including the Statement of Applicability, risk assessments/treatment plans, policies, and procedures.
  • Experience conducting or supporting internal and external audits, including evidence collection and remediation of findings/non-conformities.
  • Experience designing and delivering compliance and security awareness training programs. ▪ Ability to work across delivery, engineering, HR, and leadership teams.
  • Ability to interpret regulatory and legal text and translate it into actionable, practical policy. ▪ Excellent written and verbal communication skills, including experience presenting compliance updates to leadership.
  • Detail-oriented and organized, with the ability to manage multiple audit cycles and deadlines concurrently.

To apply for this job email your details to recruiting@nstarxinc.com

Privacy Overview
NStarX Logo

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Necessary

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.