Compliance Analyst (Part-Time)

PositionCompliance Analyst
Employment TypePart-Time
Experience2–3 Years
LocationRemote / Work From Home
Reporting ToCompliance Manager / Director – GRC
Working HoursFlexible (20–25 hours per week, based on project requirements)

About Frigg Business Solutions:

Frigg Business Solutions is a global Cybersecurity, Governance, Risk & Compliance (GRC), Data Privacy, and Business Continuity consulting firm helping organizations achieve international compliance standards and strengthen their security posture. We partner with startups, SMEs, healthcare organizations, SaaS companies, and enterprises across North America, Europe, the Middle East, and Asia.

We are looking for a motivated and detail-oriented Compliance Analyst who is passionate about information security, privacy, and regulatory compliance.

Job Summary:

The Compliance Analyst will support consulting engagements involving ISO 27001 implementation, SOC 2 readiness, compliance assessments, documentation, audit support, and implementation activities.

This role is ideal for candidates with 1–2 years of experience who have participated in at least one ISO/IEC 27001:2022 implementation project and have basic exposure to SOC 2 Type II.

Key Responsibilities:

ISO 27001 Implementation

  • Support ISO/IEC 27001:2022 implementation projects
  • Assist in gap assessments
  • Help implement Annex A controls
  • Support risk assessment activities
  • Assist in Statement of Applicability (SoA) preparation
  • Support certification readiness

Documentation:

Assist in preparing and maintaining Information Security Policies, Procedures, Risk Register, Asset Register, Risk Treatment Plan, Control Documentation, Compliance Reports, Develop, review, and maintain Information Security manual, Statement of Applicability (SoA), Privacy Documentation, and AI Governance Documentation.

Audit Support: Support internal and external audits by:

  • Collecting evidence
  • Reviewing control implementation
  • Coordinating with client stakeholders
  • Preparing audit documentation
  • Tracking corrective actions
  • Maintaining compliance documentation 

SOC 2 Support: Assist in:

  • SOC 2 readiness assessments
  • Evidence collection
  • Control mapping
  • Documentation reviews
  • Audit preparation

Client Engagement:

  • Participate in client meetings
  • Assist during workshops
  • Conduct documentation reviews
  • Track project deliverables and timelines
  • Support implementation projects

Continuous Compliance: Assist clients in establishing continuous compliance programs through:

  • Compliance monitoring
  • Control reviews
  • Policy reviews
  • Internal audit support
  • Awareness initiatives

Required Skills & Experience:

  • 2–3 years of experience in Information Security Compliance, GRC, Risk Management, or Privacy.

Technical Knowledge: Working knowledge of at least 3 out of this list:

  • ISO/IEC 27001:2022
  • ISO/IEC 27701 (PIMS)
  • SOC 2 Type II
  • GDPR
  • ISO/IEC 42001
  • Risk Assessment methodologies
  • Security Controls
  • Information Security Governance
  • Privacy Principles

Documentation Skills: 

Experience creating and reviewing Policies, Procedures, Control Documentation, Compliance Reports, Audit Evidence, Risk Registers, Compliance Matrices

Soft Skills:

Idea candidate should posses Excellent English written and verbal communication, Strong analytical thinking, High attention to detail, Ability to manage multiple client engagements, Self-driven with excellent time management, and Comfortable working remotely, 

Preferred Qualifications:

At least two certifications are mandatory:

  • ISO/IEC 27001 Lead Implementer
  • ISO/IEC 27001 Lead Auditor
  • ISO/IEC 27701 Lead Implementer
  • ISO/IEC 42001 Lead Implementer
  • ISO/IEC 42001 Lead Auditor
  • Certified Information Privacy Professional (CIPP)
  • Certified Information Privacy Manager (CIPM)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Any recognized GRC or cybersecurity certification

Good to Have:

Exposure to any of the following would be an advantage:

HIPAA/HITECHISO 9001SOC 2 Type IIDigital Personal Data Protection Act (DPDPA)
PIPEDAISO 22301UAE PDPLNIST Cybersecurity Framework (CSF)
NIST SP 800-53ISO 27000PCI DSSAI Governance and Responsible AI frameworks

What We Offer:

  • Flexible work schedule
  • 100% Remote Work
  • Exposure to international clients
  • Opportunity to work across multiple compliance frameworks
  • Continuous learning and certification support
  • Collaborative and growth-oriented work environment

Ideal Candidate:

We are seeking a proactive professional who enjoys solving compliance challenges, working with global clients, and helping organizations build secure, privacy-focused, and audit-ready environments. If you have a passion for cybersecurity, governance, risk management, and international compliance standards, we’d love to hear from you.

Apply for this position

Allowed Type(s): .pdf, .doc, .docx