Skip to content

Open nowPosted 8 days agoWe saw it 52 min after it went up

Security and Compliance Manager

Ataccama12 open roles

Where
Prague, Czechia
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity and Compliance ManagerAtaccama · Prague, Czechia
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Ataccama's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Ataccama postings stay open a median of 3 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.0%14 days
  5. 34.0%30 days
This job: posted 8 days ago

Ataccama median: 3 days open

The posting

Ataccama is the agentic data trust company. Organizations worldwide rely on Ataccama ONE, the agentic data trust platform, to ensure data is accurate, accessible, and trusted for every decision and system. Powered by the ONE AI Agent, Ataccama ONE brings autonomy to data quality and governance, continuously monitoring, improving, and explaining the reliability of data across complex enterprise and multi-agent environments. At the core of the platform is Ataccama’s market-leading data quality, with modules built around it to unify data quality monitoring, catalog, lineage, observability, and reference data management, ensuring data is consistent and explainable. This quality-first foundation makes data the engine of trust, powering AI, analytics, and operations with confidence.

Recognized as a Leader in the 2026 Gartner Magic Quadrant for Augmented Data Quality and positioned furthest in Completeness of Vision, Ataccama continues to set the standard for enterprise-grade data trust.

Our people are located across the globe. They succeed by collaborating as a team and thrive in our company culture defined by these core values:

Challenging Fun

ONE Team

Customer Centric

Candid and Caring

Aim High

Have you run SOC 2 and ISO 27001 or similar audits end to end, kept a corporate risk register alive, and negotiated security terms with enterprise customers in regulated industries, preferably in a tech company? Do you reach for establishing functional workflow when a compliance process comes back for the third time? Join our Information Security team and take over the day-to-day running of our security compliance team and Governance, Risk, and Compliance (GRC) program.

Reporting to the CISO, this role offers you the opportunity to participate in building and maintaining Ataccama ISMS, work across departments, represent the security program externally to our auditors and customers, and help ensure that our organization continues to meet evolving regulatory and industry standards. You will cooperate with our Cloud and App Security, Engineering, Cloud Operations, Product Management as well as internal IT on making sure our security compliance standards are not just defined and communicated, but practically implemented, automated, proactively monitored and reported.

Your Challenge

  • Run our security compliance program day to day: own the audit calendar, keep the control framework current, manage the security and compliance risks and prepare the materials that feed executive-level reporting and governance forums.
  • Coordinate internal and external audits (SOC 1, SOC 2 Type II, ISO 27001:2022 and customer-driven assessments), including evidence collection, auditor logistics, and tracking of findings through to remediation with control owners.
  • Operate the corporate risk management program: maintain the risk register, facilitate periodic risk assessments with control owners, prepare quarterly risk reporting (NIST CSF 2.0 based), and surface cross-departmental risks for treatment decisions.
  • Maintain the ISMS policy and standards library: author and revise core policies, coordinate scheduled reviews with control owners, and keep them current against regulatory obligations (GDPR, NIS2/ZoKB, EU AI Act, CRA) and customer-driven frameworks (GxP, DORA, FFIEC, NERC CIP, PCI DSS).
  • Review security terms in customer contracts, security schedules and addenda with enterprise and regulated-industry customers, together with Legal.
  • Manage the RFx and customer security questionnaire process: operate the workflow against established quality standards, direct the specialists and interns answering questionnaires, and act as senior reviewer for high-stakes prospect and customer submissions.
  • Assess and onboard new compliance standards and regulations: control mappings, gap analyses and remediation plans in coordination with Engineering, Cloud Operations and IT. Support customer assurance commitments for regulated customers, including GxP validation lifecycle artifacts and Quality and Security Agreements.
  • Build and maintain internal GRC so the team scales its output without adding headcount.
  • Provide input into incident response and vendor risk management: vendor due diligence, incident playbooks and cost analysis, and customer notifications.
  • Manage a small team of compliance specialists and interns, including work supervision, task allocation, quality review, mentoring and hiring.
  • Help drive security awareness and training initiatives, including secure use of AI tools across the company.
  • Liaise with stakeholders across Cloud and App Security, Engineering, Legal, Sales and Customer Success on compliance-impacting topics, translating between the audit, technical and business worlds for non-specialist audiences.

Is This You?

  • 3+ years of experience in information security, GRC, IT audit or compliance
  • Able to grasp both business and technical concepts, and distill what matters.
  • Hands-on with standards and frameworks such as ISO 27001, SOC 2 and NIST CSF, and with at least one customer-driven framework (GxP, DORA, FFIEC, NERC CIP or PCI DSS).
  • Capable of reading and interpreting legal and regulatory texts, with working knowledge of data privacy and cybersecurity regulation (GDPR, NIS2/ZoKB, EU AI Act, CRA).
  • A builder: when a compliance task comes back for the third time, you script it, automate it or build a scalable workflow, and you use AI tools responsibly and can set guardrails for others.
  • Technically fluent enough to talk to engineers about how a cloud SaaS platform is built and operated (AWS and Azure, Kubernetes, CI/CD, vulnerabilities, identity and access) and about common security threats.
  • A strong communicator, comfortable writing policies and documentation, giving presentations, and briefing executives, auditors and customers.
  • Proactive, positive, and self-organized: you don't wait to be told what to do, and you are comfortable owning a whole agenda in a small team with few formalities.
  • Experience supervising or mentoring specialists or interns, including hiring.
  • Strong written and verbal English communication skills; Czech is a plus for ZoKB and local partners.
  • Relevant certifications (e.g., ISO 27001 Lead Auditor or Lead Implementer, CISA, CRISC, CISSP, CIPP/E) are a plus.
  • People management skills and experience are welcome.

Perks & Benefits

• Long-Term Incentive Program

• 2 sick days and 25 days of vacation, with the option to request additional Flexible Time-Off days when needed

• The Global Family Support Program - a paid leave program to help all parents focus on the new addition to their family

• Flexible working hours & hybrid work setup

• Benefit Plus - flexible employee benefit platform (incl. Multisport card)

• Annual package for mental health support

• "Bring Your Friend" referral program

• Shared company cards for free entrance to Prague Zoo & Botanical garden

• Company bikes, longboards, e-scooters

• Conference tickets to the best industry events of the year

• Online courses & company access to Udemy to hone your skills

• Access to paid AI tools

• Company library, where you can even suggest the best educational books for us to order

• Kitchens stocked with fresh fruit and juice, teas, and the best coffee

Work Equipment

• Company laptop

• Company mobile phone + SIM card & package of mobile data

At Ataccama, our core values are Candid & Caring, so we are upfront about our process and details that are important to you. We sometimes use AI tools to help us with things like reviewing applications, taking notes from screening conversations, scheduling interviews, or supporting assessments. These tools make the process smoother and fairer — but don’t worry, they never make the final decision. Every hiring decision is made by our Talent Acquisition Partners and Hiring Managers, with AI only acting as a helpful assistant. We believe technology should support the process, not replace the human touch.

We currently use AI-assisted tools - Metaview for interview notes and Lever Talent Fit to help highlight key experience. If you have any questions or concerns, feel free to reach out to us at [email protected], making reference to AI Act Inquiry in the subject line.

While we highly value cooperation with all our business partners, we don’t accept unsolicited resumes from any sources other than directly from a candidate. We reserve the right not to pay any fee for sending an unsolicited offer containing the details or resume of a job candidate, even if the relevant candidate is employed by our company.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Ataccama's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Ataccama's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Ataccama's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.