IT and Compliance Manager

Sendmarc - South Africa - original posting ->
Status
Open
Remote policy
Remote
Employment type
Not stated
Salary
Not stated
Categories
IT-Compliance-Manager, IT-Operations, Information-Security-Management, Compliance-Management, Operations, Security-And-Compliance-Manager, Information-Security-Compliance-Manager, Risk-And-Compliance-Manager, Compliance-Manager, Operations-and-Compliance-Manager
Tech
remote-countrylegal
Source
himalayas
First observed
2026-09-06 14:01 UTC
Last seen
2026-09-06 14:01 UTC
Source claims posted
2026-09-06 13:56 UTC
Consecutive misses
0 of 10

What the posting says

This role is fully remote but the successful candidate is required to be located in South Africa.

ROLE SPECIFICATION

IT and Compliance Manager

Operations · Reports to: Kieran Frost (Chief Operating Officer)

About Sendmarc

We are a cyber security company that is on a mission to make the internet a safer place. We do this by delivering tooling and services related to an international standard, DMARC. Our technology enables organisations to protect their staff, customers, suppliers, and the whole world from email spoofing and impersonation attacks on their domains.

We’re a fully remote company with the majority of our builders working out of South Africa and sales teams in the Netherlands, the US, Latin America, Australia and the UK.

Missionof the role

Own Sendmarc’s internal IT operations and the operating side of our information security compliance programme: the systems, devices, and access that keep the business running day to day, and the SOC 2 and ISO 27001 evidence, controls and policies that keep us credible with the customers and partners who ask hard questions about security.

Why This Role Exists

Sendmarc sells trust for a living. We’re a cyber security company, and our own security posture is part of our product story.Our ISO 27001 certification, our SOC 2 Type II report,and our Trust Centre exist to let prospects self-serve security questions, reduce friction in deals, and show that we practice what we preach. Compliance isn’t a background operational task here; it’s a strategic asset.

Outcomes

The four core outcomes this role is accountable for:

IT Operations & Support:Own internal IT for Sendmarc’s global, fully remote team: helpdesk and device support, identity and access management (onboarding/offboarding provisioning across our core systems), and administration of tools like 1Password,Microsoft 365, and Entra.

Compliance & Audit Management Own the operating programme for our ISO 27001 certification and SOC 2 Type II report via Vanta: evidence collection, control monitoring, clearing flagged items, and coordinating directly with auditors. Keep our Trust Centre (trust.sendmarc.com) accurate, current, and something Sales can point to with confidence.

Security Risk & Remediation Tracking Maintain the risk register, triage and track remediation of security findings (penetration test and vulnerability scan results) through to closure, and own our information security policy set.

Vendor & Access Governance:Administer access reviews and sharing permissions across core systems, and support third-party/vendor risk reviews alongside Finance, and own the security awareness training and phishing simulation programme with our Chief People Officer

Competencies

TECHNICAL

Hands-on IT administration experience: device management, identity and access management, helpdesk/ticketing

Comfortable administering SaaS platform security settings

Working understanding of SOC 2 and ISO 27001 frameworks and their evidence requirements

Familiarity with compliance automation platforms (Vanta, Drata, Secureframe, or similar)

Basic grounding in infrastructure/network security concepts: enough to triage a vulnerability finding and know who needs to see it

COMPLIANCE & RISK

Has sat on the “prep” side of a SOC 2 and/or ISO 27001 audit before

Comfortable owning a risk register and tracking remediation items to actual closure

Able to translate audit and regulatory requirements into practical, low-friction internal process

Experience drafting or maintaining information security policy documentation

Familiar with the ISO 27001 clause 9 cycle (internal audit and management review)

WAYS OF WORKING

Proactive communicator: flags issues and drives them to resolution

Comfortable being the point of contact

Treats IT support as a service function, not a bottleneck for the rest of the business

Takes ownership: this is the “buck stops here” seat for IT and compliance, not a coordination-only role

EXPERIENCE

3–5+ years in IT management, information security, or compliance-focused roles

Hands-on SOC 2 Type II and/or ISO 27001 audit experience

Experience supporting a distributed, multi-country remote workforce is a strong plus

Cyber security industry background is a nice-to-have, not required

Primary Tools: Vanta, Microsoft 365 andSharePoint, Entra, 1Password, Slack

Who We're Looking For

You’re the person who actually wants to own IT and compliance, not tolerate it. You see a strong security posture as a competitive edge, not a checkbox, and you get real satisfaction from a clean risk register, a Vanta dashboard with nothing flagged, and a laptop fleet that’s patched before anyone notices it needed to be.

Originally posted on Himalayas

Quality

Completeness: 65%

Not enough history yet to judge honesty signals.

Timeline

  1. *
    #603509 2026-09-06 14:01 UTC
    Published