IT and Compliance Manager
This role is fully remote but the successful candidate is required to be located in South Africa.
ROLE SPECIFICATION
IT and Compliance Manager
Operations · Reports to: Kieran Frost (Chief Operating Officer)
About Sendmarc
We are a cyber security company that is on a mission to make the internet a safer place. We do this by delivering tooling and services related to an international standard, DMARC. Our technology enables organisations to protect their staff, customers, suppliers, and the whole world from email spoofing and impersonation attacks on their domains.
We’re a fully remote company with the majority of our builders working out of South Africa and sales teams in the Netherlands, the US, Latin America, Australia and the UK.
Mission of the role
Own Sendmarc’s internal IT operations and the operating side of our information security compliance programme: the systems, devices, and access that keep the business running day to day, and the SOC 2 and ISO 27001 evidence, controls and policies that keep us credible with the customers and partners who ask hard questions about security.
Why This Role Exists
Sendmarc sells trust for a living. We’re a cyber security company, and our own security posture is part of our product story. Our ISO 27001 certification, our SOC 2 Type II report,and our Trust Centre exist to let prospects self-serve security questions, reduce friction in deals, and show that we practice what we preach. Compliance isn’t a background operational task here; it’s a strategic asset.
Outcomes
The four core outcomes this role is accountable for:
- IT Operations & Support: Own internal IT for Sendmarc’s global, fully remote team: helpdesk and device support, identity and access management (onboarding/offboarding provisioning across our core systems), and administration of tools like 1Password,Microsoft 365, and Entra.
- Compliance & Audit Management Own the operating programme for our ISO 27001 certification and SOC 2 Type II report via Vanta: evidence collection, control monitoring, clearing flagged items, and coordinating directly with auditors. Keep our Trust Centre (trust.sendmarc.com) accurate, current, and something Sales can point to with confidence.
- Security Risk & Remediation Tracking Maintain the risk register, triage and track remediation of security findings (penetration test and vulnerability scan results) through to closure, and own our information security policy set.
- Vendor & Access Governance: Administer access reviews and sharing permissions across core systems, and support third-party/vendor risk reviews alongside Finance, and own the security awareness training and phishing simulation programme with our Chief People Officer
Competencies
TECHNICAL
- Hands-on IT administration experience: device management, identity and access management, helpdesk/ticketing
- Comfortable administering SaaS platform security settings
- Working understanding of SOC 2 and ISO 27001 frameworks and their evidence requirements
- Familiarity with compliance automation platforms (Vanta, Drata, Secureframe, or similar)
- Basic grounding in infrastructure/network security concepts: enough to triage a vulnerability finding and know who needs to see it
COMPLIANCE & RISK
- Has sat on the “prep” side of a SOC 2 and/or ISO 27001 audit before
- Comfortable owning a risk register and tracking remediation items to actual closure
- Able to translate audit and regulatory requirements into practical, low-friction internal process
- Experience drafting or maintaining information security policy documentation
- Familiar with the ISO 27001 clause 9 cycle (internal audit and management review)
WAYS OF WORKING
- Proactive communicator: flags issues and drives them to resolution
- Comfortable being the point of contact
- Treats IT support as a service function, not a bottleneck for the rest of the business
- Takes ownership: this is the “buck stops here” seat for IT and compliance, not a coordination-only role
EXPERIENCE
- 3–5+ years in IT management, information security, or compliance-focused roles
- Hands-on SOC 2 Type II and/or ISO 27001 audit experience
- Experience supporting a distributed, multi-country remote workforce is a strong plus
- Cyber security industry background is a nice-to-have, not required
Primary Tools: Vanta, Microsoft 365 and SharePoint, Entra, 1Password, Slack
Who We're Looking For
You’re the person who actually wants to own IT and compliance, not tolerate it. You see a strong security posture as a competitive edge, not a checkbox, and you get real satisfaction from a clean risk register, a Vanta dashboard with nothing flagged, and a laptop fleet that’s patched before anyone notices it needed to be.