MacPaw is a software company that develops and distributes software for macOS and iOS. Today, we have 20 million active users across all our products.
At MacPaw, we believe humans and technology can reach their greatest potential together.
MacPaw is proud to be Ukrainian. The support and development of Ukraine are significant parts of the company’s culture. MacPaw gathers open-minded people who support each other and aspire to change the world around us.
We are looking for an Information Security Compliance Analyst to strengthen our security and compliance practices across all products. In this role, you’ll oversee compliance processes, support audits, manage vendor reviews, and collaborate with cross-functional teams to improve workflows and reduce risks.
This position requires a solid background in IT compliance and risk management, combined with strong communication skills and a proactive mindset.
If it sounds like a match for you – we’d love to hear from you!
Monitor and support ISO 27001:2022 surveillance audits using our GRC automation platform.
Monitor and support SOC2 Type II audits with GRC automation platform.
Perform IT vendor security compliance reviews (mostly automated).
Collaborate with cross-functional teams to coordinate compliance efforts across all products.
Perform initial cyber risk assessment and reporting.
Contribute to building scalable compliance and risk management processes.
Raise awareness and consult employees on security and compliance topics.
3+ years of experience in IT compliance, risk management, or information security.
Strong knowledge of IT governance frameworks and compliance standards: ISO/IEC 27001 or SOC2.
Familiar with cloud providers (Google Cloud, AWS), device management, and network security.
Experience in documenting and improving security/compliance processes.
Strong analytical and problem-solving skills.
Excellent communication skills — able to explain complex concepts clearly and work with different stakeholders.
Leadership and interpersonal skills to drive cross-team initiatives.
Upper-Intermediate English level for interaction with auditors and external partners.
Professional certifications such as CISA, CRISC, SSCP, CCSP, or CISSP.
Experience in SaaS, fintech, or other compliance-heavy industries.
Knowledge of secure development practices or OSINT research.
Bachelor’s or Master’s degree in Information Technology, Cybersecurity, Law, or Business Administration.
Steps may differ depending on the position, but this is our usual hiring process.
This could be your
next workplace
An unexpected error occurred, please try again later.