Compliance Manager
HeadwayFull Time
Senior (5 to 8 years), Expert & Leadership (9+ years)
Candidates must have 5 to 8 years of information security program management experience, with a preference for specialization in ISMAP. Native or business-level Japanese language proficiency is required. Demonstrated experience with the ISMAP certification process and requirements is essential, along with a strong understanding of compliance certifications and frameworks such as SOC 2, CSA STAR, ISO/IEC 27001:2022, ISO/IEC 27017:2015, PCI DSS, TISAX, IRAP, and NIST 800-53. The ability to build rapport and maintain relationships across various internal functions is necessary, as is a fundamental technical understanding of operating systems, networks, application development, databases, virtualization, and cloud infrastructure. A Bachelor's or Master's degree in a related field, or equivalent experience, is also required.
The Sr. Governance, Risk, and Compliance Specialist will lead CrowdStrike's ISMAP certification efforts and support broader global compliance initiatives. This role involves leading ISMAP certification processes, including documentation preparation, control implementation, and audit coordination. Responsibilities include maintaining multiple compliance frameworks such as SOC 2, ISO/IEC 27001:2022, ISO/IEC 27017:2015 CSA STAR, C5, PCI DSS, TISAX, and other relevant certifications. The specialist will facilitate internal and external audits, conduct third-party controls evaluations and risk assessments, collaborate with internal teams on remediation efforts, and respond to customer inquiries regarding compliance and security controls. Developing and maintaining compliance documentation in both English and Japanese is also a key responsibility, along with performing other duties within the scope of governance, risk, and compliance.
Cloud-native endpoint security solutions provider
CrowdStrike specializes in cybersecurity, focusing on protecting businesses from cyber threats through cloud-native endpoint security solutions. Their main product, the Falcon platform, includes services like Falcon Pro, which replaces traditional antivirus with next-generation antivirus that integrates threat intelligence, Falcon Insight for endpoint detection and response, and Falcon Device Control to manage connected devices. Unlike many competitors, CrowdStrike's services are subscription-based, allowing clients to choose different levels of protection based on their needs. The company serves a diverse clientele, including many Fortune 100 companies, and is recognized as a leader in the cybersecurity field, known for its effectiveness in threat detection and response.