Overview
Ataccama is the agentic data trust company. Organizations worldwide rely on Ataccama ONE, the agentic data trust platform, to ensure data is accurate, accessible, and trusted for e
Full job description
Ataccama is the agentic data trust company. Organizations worldwide rely on Ataccama ONE, the agentic data trust platform, to ensure data is accurate, accessible, and trusted for every decision and system. Powered by the ONE AI Agent, Ataccama ONE brings autonomy to data quality and governance, continuously monitoring, improving, and explaining the reliability of data across complex enterprise and multi-agent environments. At the core of the platform is Ataccama’s market-leading data quality, with modules built around it to unify data quality monitoring, catalog, lineage, observability, and reference data management, ensuring data is consistent and explainable. This quality-first foundation makes data the engine of trust, powering AI, analytics, and operations with confidence.
Recognized as a Leader in the 2026 Gartner Magic Quadrant for Augmented Data Quality and positioned furthest in Completeness of Vision, Ataccama continues to set the standard for enterprise-grade data trust.
Our people are located across the globe. They succeed by collaborating as a team and thrive in our company culture defined by these core values:
Challenging Fun ONE Team Customer Centric Candid and Caring Aim High
Run our security compliance program day to day: own the audit calendar, keep the control framework current, manage the security and compliance risks and prepare the materials that feed executive-level reporting and governance forums. Coordinate internal and external audits (SOC 1, SOC 2 Type II, ISO 27001:2022 and customer-driven assessments), including evidence collection, auditor logistics, and tracking of findings through to remediation with control owners. Operate the corporate risk management program: maintain the risk register, facilitate periodic risk assessments with control owners, prepare quarterly risk reporting (NIST CSF 2.0 based), and surface cross-departmental risks for treatment decisions. Maintain the ISMS policy and standards library: author and revise core policies, coordinate scheduled reviews with control owners, and keep them current against regulatory obligations (GDPR, NIS2/ZoKB, EU AI Act, CRA) and customer-driven frameworks (GxP, DORA, FFIEC, NERC CIP, PCI DSS). Review security terms in customer contracts, security schedules and addenda with enterprise and regulated-industry customers, together with Legal. Manage the RFx and customer security questionnaire process: operate the workflow against established quality standards, direct the specialists and interns answering questionnaires, and act as senior reviewer for high-stakes prospect and customer submissions. Assess and onboard new compliance standards and regulations: control mappings, gap analyses and remediation plans in coordination with Engineering, Cloud Operations and IT. Support customer assurance commitments for regulated customers, including GxP validation lifecycle artifacts and Quality and Security Agreements. Build and maintain internal GRC so the team scales its output without adding headcount. Provide input into incident response and vendor risk management: vendor due diligence, incident playbooks and cost analysis, and customer notifications. Manage a small team of compliance specialists and interns, including work supervision, task allocation, quality review, mentoring and hiring. Help drive security awareness and training initiatives, including secure use of AI tools across the company. Liaise with stakeholders across Cloud and App Security, Engineering, Legal, Sales and Customer Success on compliance-impacting topics, translating between the audit, technical and business worlds for non-specialist audiences.
3+ years of experience in information security, GRC, IT audit or compliance Able to grasp both business and technical concepts, and distill what matters. Hands-on with standards and frameworks such as ISO 27001, SOC 2 and NIST CSF, and with at least one customer-driven framework (GxP, DORA, FFIEC, NERC CIP or PCI DSS). Capable of reading and interpreting legal and regulatory texts, with working knowledge of data privacy and cybersecurity regulation (GDPR, NIS2/ZoKB, EU AI Act, CRA). A builder: when a compliance task comes back for the third time, you script it, automate it or build a scalable workflow, and you use AI tools responsibly and can set guardrails for others. Technically fluent enough to talk to engineers about how a cloud SaaS platform is built and operated (AWS and Azure, Kubernetes, CI/CD, vulnerabilities, identity and access) and about common security threats. A strong communicator, comfortable writing policies and documentation, giving presentations, and briefing executives, auditors and customers. Proactive, positive, and self-organized: you don't wait to be told what to do, and you are comfortable owning a whole agenda in a small team with few formalities. Experience supervising or mentoring specialists or interns, including hiring. Strong written and verbal English communication skills; Czech is a plus for ZoKB and local partners. Relevant certifications (e.g., ISO 27001 Lead Auditor or Lead Implementer, CISA, CRISC, CISSP, CIPP/E) are a plus. People management skills and experience are welcome.
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
Verification notes
laptop-ats-crawler v3
JobOpportunity is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from Ataccama (lever) →