Quality/Compliance/Operations Manager
Sydney, New South Wales, Australia
- Passed SOC 2 Type 2 and ISO 27001:2022 certification within 6 and 10 months of company inception, respectively. Auditor’s comment: Easiest and smoothest audit in his experience so far.- Established an Information Security Management System (ISMS) from the ground up, in conjunction with team leads, creating the most suitable process with minimal checkbox exercises. The standards were implemented sensibly, instead of blindly following the letter of the law, with automated processes established where possible.- Monitored threats and risks, working with the engineering team to mitigate risks. Received Wiz Zero Critical Club achievement upon full implementation of Wiz monitoring.- Performed periodic access reviews, management reviews, risk assessments, and other recurring activities as required for certifications.- Distilled user requirements, performed market research, evaluated relevant third-party vendors, and selected best cost/benefit choices for information security activities: compliance platform (Vanta), cloud monitoring and prevention (Wiz), external audits and pen testing (Prescient Security), MDM (Mosyle), etc.- Trained the company on certification requirements: SOC 2, ISO 27001, HIPAA.- Established and tested Disaster Recovery/Incident Response plan, as appropriate for the company.- Subject Matter Expert (SME) for customer inquiries for privacy, regulations, and compliance questions.- Took on the role of systems administrator and managed system access in accordance to principle of least privilege (PoLP), including Google Cloud Platform (GCP) Identity and Access Management (IAM), Github, Jira/Confluence, etc.- Took over HR and recruitment roles, and successfully recruited 2 candidates for 2 roles, managing the recruitment process and performing initial screening interviews.- Gained familiarity with Software Development Life Cycle (SLDC) process and basic platform engineering, including Terraform modules.