This is a remote position.
SyncEzy is a growing Integration Company in the B2B SAAS space, with a strong focus on the Construction, Trades, and Service Industries. We are fiercely independent & bootstrapped, NOT VC Funded. This is A TRUE Remote /work-from-home position. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly, easy-going culture.
We are looking for a hands-on Information Security & Compliance Analyst (GRC)to take ownership of the day-to-day activities required to maintain our security and compliance posture. The role will support and coordinate compliance activities across SOC 2, ISO 27001 and Cyber Essentials, and will work closely with Engineering, DevOps, IT and management to keep controls operating effectively and evidence audit-ready throughout the year.
This is an execution-focused role.The successful candidate should be comfortable moving between policy work, evidence collection, endpoint/software compliance, risk tracking, access reviews and audit coordination. The Senior Engineering Manager will remain the management and escalation point, while the analyst becomes the primary owner of routine compliance operations and follow-up.
Primary Objectives
·Maintain year-round readiness for SOC 2, ISO 27001 and Cyber Essentials rather than treating compliance as a once-a-year audit exercise.
·Own routine compliance administration, evidence collection, control monitoring and follow-up so engineering leadership can remain focused on product delivery and technical management.
·Translate compliance requirements into practical actions for Engineering, DevOps and IT teams without creating unnecessary operational overhead.
·Identify gaps early, track remediation to closure and maintain clear documentation showing that controls are designed and operating effectively.
Requirements
Required Qualifications & Skills
·2–4 years of relevant experience in GRC, information security compliance, security assurance, IT audit or a closely related role.
·Practical exposure to at least one major security/compliance framework such as SOC 2 or ISO 27001; familiarity with Cyber Essentials is strongly preferred.
·Experience collecting, reviewing and organizing audit evidence and working with technical control owners.
·Strong documentation and policy-writing skills with attention to consistency and audibility.
·Working understanding of cloud environments, identity and access management, endpoint security, vulnerability management, logging, backups and change management.
·Ability to read technical evidence and ask the right questions without needing to be a software engineer or DevOps engineer.
·Strong ownership, follow-up and organizational skills; comfortable tracking multiple recurring compliance activities simultaneously.
·Clear written and verbal communication skills and the ability to work with both technical and non-technical stakeholders.
Preferred / Good-to-Have·Experience with compliance automation or GRC platforms such as Vanta, Drata, Sprinto or equivalent tools.
·Experience working in a SaaS, software-development or cloud-first organization.
·Familiarity with MDM / endpoint-management tooling and software inventory reviews.
·Exposure to AWS, Azure or other public-cloud security controls.
·Experience supporting customer security questionnaires or vendor-risk assessments.
·Relevant certifications such as ISO 27001 Internal Auditor / Lead Implementer, Security+, CISA, CRISC or similar are useful but not mandatory.
Benefits
Benefits - A TRUE Remote / Work from Home position. We are a Global Remote company, and have been remote working long before it was made popular by COVID. We have staff dispersed across 4 countries and 15 cities. We pride ourselves on running a flat organization, with a friendly and going culture.
Competitive Salary + All the belowSalary range:7-9 lacs Allowance for Internet / Phone costs Company Hardware provided after completing probation. Continuous development and education allowances. Flexible Remote work from anywhere (As long as you have good internet and communication) Excellent growth opportunities, growth into leadership for the right candidate Generous policies around leave / social and training allowances End of year Bonuses based on company + Individual performance. Zero Commute, Work while you work, play while you play. Perfect Work / Life balance. Remote job opportunities and other benefits to be discussed during the interviewFlexible, family friendly & fun work environment
SyncEzy is a B2B SaaS integration company specializing in the Construction, Trades, and Service Industries, including Electrical, Plumbing, HVAC, and Security sectors. The company integrates leading SaaS platforms such as Procore, Simpro, Autodesk, Dropbox, SharePoint, and HiBob to streamline workflows for construction and trade service businesses. As a bootstrapped, independent Australian company, SyncEzy prioritizes stability and long-term success over rapid growth. The company has operated as a fully remote organization for over 10 years with a global team distributed across 5 countries.