Compliance Specialist, IT/Tech
Cape Town, 7100, South Africa
Listed on 2025-12-19
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
From the day we opened our doors in 1971, MRI Software has built flexible, game-changing real estate software solutions to improve people’s lives. The only way to carry out that mission is to hire the absolute best employees on earth. People like you.
Work hard, play hard. Always. Our relentless commitment to client success, our employee resource groups and our promise to empower our teams to reach their full potential are a few examples of what makes MRI Software special.
And we’re insanely dedicated to creating a work environment that you look forward to every single day. That’s why we invest heavily in our employee engagement, so you enjoy the tech industry’s best perks. Together with the whole Pride, (lion roar for "family") employees, customers, and partners, we’re on a mission to break new ground and lead the real estate industry into a digital-first future.
We understand the need to provide a flexible working environment partnered with team collaboration and socialisation. Therefore, we operate a hybrid working model with 3 days of working from home per week. This role is based in our Cape Town
office.
The Compliance Specialist plays a crucial role in ensuring that MRI's business practices align with relevant regulations, industry best practices, and common security standards. By conducting thorough audits and evaluations of various business functions, the Compliance Specialist helps maintain MRI's commitment to cybersecurity, risk management, data privacy, and continuous improvement. While the primary focus is on technical aspects of security, the role also encompasses non-technical business practices to provide a holistic approach to compliance.
Responsibilities:
Collaborate with business stakeholders to conduct comprehensive audits related to IT general controls, application controls, information security, and business functions.
Address client and internal inquiries regarding compliance, privacy, and security matters, providing expert guidance and solutions.
Maintain and enhance MRI's risk register by creating, updating, and assessing entries to ensure accurate documentation of potential risks and mitigation strategies.
Ensure timely completion of corrective actions by diligently following up with internal and external parties.
Manage the lifecycle of policies and security documentation, including drafting, updating, archiving, and circulating to relevant stakeholders.
Prepare detailed minutes, collect and analyze data, and maintain action lists to support meetings, audits, and incident response efforts.
Align MRI's overall security strategy with internal teams, industry best practices, and global legislation, including but not limited to SOC 1, SOC 2, ISO 27001, NIST, and other standards.
Develop and oversee mitigation plans related to information security risks, audits, and policy findings, collaborating with relevant teams to ensure effective implementation.
Conduct vendor security risk assessments and provide risk-based recommendations to help evaluate and improve the company's risk posture.
Contribute to the development and delivery of engaging and informative enterprise-wide security awareness initiatives to foster a culture of security.
Forge strong, collaborative partnerships with security, infrastructure, legal, audit, and IT teams to ensure a cohesive approach to compliance and risk management.
Stay abreast of emerging trends, threats, and best practices in cybersecurity and compliance, proactively identifying opportunities for improvement and implementing necessary changes.
Qualifications:
Professional experience and familiarity with specifically ISO 27001, while ISO 9001, SOC 1, SOC 2, and other auditing standards are also plusses.
Professional experience and familiarity with one or more: NIST, CIS, SANS, ISO, CES, FedRAMP, and other cybersecurity frameworks.
Working knowledge of major international, national, and state level security and privacy regulations, practices, and standards.
Solid technical background with an applied understanding of common types of security risks and mitigation strategies.
Experience with vendor risk management and performing security risk reviews.
Ability to…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: