Remote
Internal Audit & Compliance Manager ( Remote in Colombia )
About this role
We are seeking an experienced Internal Audit & Compliance Manager to own the day-to-day operation of Otonomee’s governance, risk and compliance programmes. This role will be central to maintaining a strong, scalable control environment as the business continues to grow and expand its technology, data and AI capabilities. The successful candidate will manage our established ISO/IEC 27001 ISMS, maintain continuous audit readiness across PCI DSS and SOC 2, and support additional frameworks on our roadmap.
The role will establish a risk-based internal audit programme, coordinate internal and external audits, operate the GRC platform, and ensure that controls, policies, risks, findings and supporting evidence are actively managed. Working across technology, operations and corporate functions, the role will translate compliance requirements into practical controls and provide clear, objective assurance to senior leadership.
It will also support client assurance through security questionnaires, RFP responses, vendor reviews and compliance reporting. Success will be measured through sustained certification and attestation outcomes, effective control operation, timely remediation of findings and improved visibility of organisational risk. This is a high-impact opportunity for an experienced compliance professional who combines independent judgement with a pragmatic understanding of a fast-growing international business .
Reporting Line The role reports to the CTO for security programme delivery and technical oversight, with an independent assurance line to the CEO. What you will do Establish and run a planned internal audit programme across ISO 27001, PCI DSS, SOC 2, and additional frameworks in scope (e.g. HIPAA, HITRUST), including control testing, findings, and remediation tracking to closure. Provide independent assurance to the CTO, CEO, and senior leadership on control effectiveness and compliance status.
Maintain continuous audit readiness and coordinate external audits and certification cycles end to end, acting as the primary point of contact for auditors. Conduct risk assessments using risk-based methodologies; develop and track key risk indicators (KRIs) and mitigation plans. Liaise with business process owners and technical teams to drive and track remediation of control gaps and audit findings. Advise stakeholders and leadership on compliance gaps, risks, and their business impact, recommending pragmatic mitigations.