Summary
Overview
Work history
Education
Skills
Languages
Visa status
Timeline
Generic

Jovana Bozanovic

Hove,United Kingdom

Summary

Results-driven Senior Manager with knack for transforming teams and processes to achieve organisational goals. Leveraged leadership skills to boost team productivity and streamline operations, delivering impactful changes across departments. Known for fostering collaborative environments and driving strategic growth initiatives.

Overview

9
9
years of post-secondary education
12
12
years of professional experience

Work history

Head of SOC 1 & SOC 2 compliance

Strada
London
2026.01 - Current
  • Lead a global, cross-functional team across US Europe and EMEA, driving the strategic oversight of SOC 1 and SOC 2 compliance programmes and fostering a high-performance, collaborative culture.
  • Provide leadership, coaching, and professional development to team members, building organisational capability and strengthening compliance expertise across the function.
  • Own the end-to-end SOC 1 and SOC 2 compliance framework, ensuring alignment with regulatory requirements, industry best practices, and organisational objectives.
  • Establish and implement compliance policies, standards, and governance processes to maintain and continuously enhance the organisation's control environment.
  • Direct internal monitoring, review, and escalation activities for SOC compliance, ensuring effective risk identification and timely remediation of control deficiencies.
  • Lead the global SOC 1, SOC 2 , ISO 27001, ISO 27701 and ISO 23301 audit lifecycle, managing relationships with external auditors and ensuring successful audit outcomes through robust planning, documentation, and stakeholder engagement.
  • Oversee the preparation and review of audit reports and supporting evidence, driving improvements in audit quality, efficiency, and consistency across the organisation.
  • Develop and execute risk management strategies by identifying compliance risks, implementing mitigation plans, and monitoring key compliance metrics and emerging trends.
  • Partner with senior leaders across Technology, Legal, Operations, and other business functions to align compliance initiatives with broader business and strategic priorities.
  • Act as the primary executive liaison for external auditors and regulatory stakeholders, effectively communicating compliance status, audit findings, and remediation initiatives.
  • Champion continuous improvement initiatives by optimising audit methodologies, enhancing control frameworks, and embedding best practices across compliance operations.
  • Monitor regulatory and industry developments to proactively adapt compliance programmes and strengthen the organisation's overall governance and risk posture.
  • Drive strategic initiatives that improve operational efficiency, enhance compliance maturity, and support the organisation's commitment to maintaining industry-leading assurance standards.

Senior Manager, Risk Management

Apptio, an IBM company
London , United Kingdom
2023.02 - 2026.01
  • Directed SOC1, SOC2, ISO, TISAX, and NIST compliance initiatives, leveraging a Governance, Risk, and Compliance (GRC) Management System to drive process alignment and performance.
  • Streamlined audit processes by consolidating ISO/SOC/TISAX audit cycles, significantly reducing client audit workload and increasing operational efficiency.
  • Managed the tracking and resolution of audit findings, ensuring timely action and closure while providing regular progress reports to leadership.
  • Automated control evidence collection, minimizing audit fatigue and improving efficiency in compliance tracking and reporting.
  • Led reviews to assess service delivery and ensure compliance with contractual requirements, regulatory controls, and organizational policies, mitigating the risk of non-compliance.
  • Developed and implemented an authority process in alignment with business partners and technology teams to ensure cohesive compliance management.
  • Translated regulatory and legal guidance into actionable IT operations, ensuring seamless compliance with evolving regulatory requirements.
  • Maintained alignment of baseline IT policies and procedures with organizational risk, quality, and compliance standards, ensuring consistency across operations.
  • Spearheaded the integration of repeatable compliance monitoring controls to ensure ongoing adherence to regulatory, investor, and process requirements, delivering clear, actionable reports on compliance performance.
  • Designed and executed remediation strategies and attestation approaches to drive IT improvements and maintain compliance standards.
  • Led various client audits, offering subject matter expertise on compliance, risk management, and information security controls throughout the audit process.
  • Monitored shifting risk levels due to compliance challenges, reporting findings and recommendations to Enterprise Risk Management Leadership for informed decision-making.
  • Built and maintained an efficient third-party risk management program to assess and mitigate risks associated with external vendors and partners.
  • Managed team dynamics by implementing conflict resolution strategies.
  • Led performance reviews, identified areas for improvement.

Third Party Risk Manager

Jaggaer
Belgrade, Serbia
2021.08 - 2023.01
  • Led planning and execution of SOC 2, ISO 27001, and ISO 9001 audits, including scope development, risk assessments, fieldwork (interviews, surveys, control analysis, testing), and reporting of findings and recommendations.
  • Communicated audit objectives, risks, and controls effectively to all levels of management.
  • Tracked results of prior audits (SOC 2, ISO), facilitating corrective actions as necessary.
  • Built and mapped control frameworks in GRC tools to strengthen risk management processes.
  • Collaborated with cross-functional teams (Supply Chain, Procurement, Legal, IT, etc.) to design and implement a Third-Party Risk Management (TPRM) program for risk identification, assessment, and mitigation.
  • Drove the creation of global TPRM standards, KPIs, and frameworks to continuously evaluate and improve controls, tools, and processes.
  • Designed and implemented global policies and procedures aligned with TPRM requirements, ensuring the framework remained fit for purpose.
  • Developed and aligned global TPRM strategy and roadmap with broader business objectives.
  • Established a global reporting framework for TPRM to deliver accurate and actionable insights.
  • Continuously improved the global operating model to enhance effectiveness, efficiency, and compliance.
  • Developed and managed a global TPRM training and communication plan, overseeing execution across divisions.
  • Built and led a team of third-party risk analysts to strengthen the TPRM function.
  • Developed and implemented a Policy Management framework to ensure policy alignment and compliance.

Third Party Risk Analyst

JAGGAER
Belgrade, Serbia
2020.10 - 2021.08
  • Conducted third-party risk assessments for new and existing vendor engagements, ensuring compliance with established standards and updating policies and procedures as needed.
  • Collaborated with vendors and SME's to collect due diligence documentation for new and existing vendor engagements in alignment with JAGGAER policies.
  • Evaluated the adequacy of due diligence documentation, engaging subject matter experts when necessary to ensure compliance.
  • Provided guidance to vendor managers on applying JAGGAER standards and recommended risk mitigation or remediation strategies for vendor engagements.
  • Worked with vendor managers to develop corrective action plans addressing vendor information security, performance, financial, and business process issues.
  • Acted as a resource for process improvements, identifying opportunities to reduce errors and mitigate risks.
  • Provided ongoing monitoring, analysis, and reporting on third-party risk areas.
  • Led the planning and execution of SOC 2, ISO 27001, and ISO 9001 audits, including scope development, risk assessment, fieldwork, and reporting of audit findings and recommendations.
  • Implemented Governance, Risk & Compliance (GRC) and Denied Party Screening tools to enhance risk management processes.

Quality & Risk Management Assistant

KPMG doo
Belgrade, Serbia
2018.10 - 2020.10
  • Developed and implemented local risk management policies in line with global standards.
  • Provided expert support to service teams on RM policies, procedures, and regulatory requirements.
  • Reviewed internal policies to ensure compliance with management directives and risk mitigation goals.
  • Assisted in planning, executing, and reporting for ISO 27001 certification.
  • Coordinated and implemented third-party evaluation tools.
  • Collaborated with business owners to ensure compliance with entity and process-level controls.
  • Analyzed data related to information systems functions for risk assessment.
  • Supervised KYC procedures, conflict of interest checks, and vendor/client screening.
  • Managed mandatory RM training and compliance testing efforts.
  • Conducted Root Cause Analysis and monitored control objectives and compliance.
  • Identified process improvements and supported the optimization of key processes.
  • Reviewed test findings, facilitated remediation, and escalated critical issues to senior management.
  • Supported implementation of ethics, independence, and RM policies across internal projects.

Risk Management Assistant, Senior Partnerʼs PA

KPMG doo
Belgrade, Serbia
2016.10 - 2018.10
  • Performed regular review and assessment of Risk Management policies, personal risk assessments, risk handling plans, and monitoring results, recommending corrective actions as needed.
  • Lead Anti-Money Laundering (AML) compliance efforts, staying current on regulations, typologies, and industry trends.
  • Deliver Risk Management training, including courses, presentations, and self-study programs for staff.
  • Coordinate projects, tenders, and engagements; prepare reports and presentations with statistical insights.
  • Ensure nonprofit legal and regulatory compliance, including handling registrations and required documentation.
  • Provide executive support to the Senior Partner, managing schedules, expenses, events, and client communication.
  • Optimize administrative systems and processes to improve office efficiency; implement policies as needed.

Audit Delivery Center Senior Assistant / Junior audit

KPMG doo
Belgrade, Serbia
2014.09 - 2016.10
  • Developed audit procedures and contributed to audit planning and execution.
  • Tested balance sheet items and profit & loss accounts for accuracy.
  • Managed financial statements and supporting notes for.
  • Gathered and presented key data to support audit team analysis.
  • Prepared audit documentation for further review and testing.
  • Reported on the performance of junior team members.
  • Assisted in preparing group reports for international clients and Long Form checks.
  • Prepared documentation for internal control compliance.
  • Led, communicated, and mentored junior team members.

Education

Agroeconomy - Master’s Degree in Agricultural Economics

Faculty of Agriculture University of Belgrade
Belgrade, Serbia
2004.09 - 2013.03

Skills

  • MS Office (MS Word, Excel, PowerPoint)
  • CRM/ EMS
  • CEAC
  • IDEA
  • GRC tools proficiency (ZenGRC, Whistic, Anecdotes, MSAC)
  • Cybersecurity tools (Up Guard)

Languages

Serbian
Native
English
Fluent
Spanish
Elementary

Visa status

Visa sponsorship required until February 2028

Type : Skilled Worker 

Timeline

Head of SOC 1 & SOC 2 compliance

Strada
2026.01 - Current

Senior Manager, Risk Management

Apptio, an IBM company
2023.02 - 2026.01

Third Party Risk Manager

Jaggaer
2021.08 - 2023.01

Third Party Risk Analyst

JAGGAER
2020.10 - 2021.08

Quality & Risk Management Assistant

KPMG doo
2018.10 - 2020.10

Risk Management Assistant, Senior Partnerʼs PA

KPMG doo
2016.10 - 2018.10

Audit Delivery Center Senior Assistant / Junior audit

KPMG doo
2014.09 - 2016.10

Agroeconomy - Master’s Degree in Agricultural Economics

Faculty of Agriculture University of Belgrade
2004.09 - 2013.03
Jovana Bozanovic