Назад
Company hidden
11 дней назад

Information Security & Compliance Manager (GRC)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Austria
Релокация
Austria
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security & Compliance Manager (GRC): Owning and maturing fiskaly’s ISMS, ISO 27001 re-certification, ISO 9001 QMS, and GDPR framework across a cloud-native SaaS environment with an accent on audit leadership, risk management, and security-by-design. Focus on closing nonconformities, building scalable compliance processes, automating evidence collection, and translating technical and regulatory risks into actionable roadmaps for leadership.

Location: Vienna, Austria — hybrid with regular on-site presence and full on-site presence during audits. Based in Vienna or willing to relocate.

Company

hirify.global is a B2B software company providing digital receipt and legally compliant transaction technology across seven European markets.

What you will do

  • Own the Information Security Management System end-to-end, including scope, policies, controls, risk registers, management reviews, and continuous improvement.
  • Lead the ISO 27001 re-certification planned for early 2027 by assessing gaps, closing nonconformities, running internal audits, preparing evidence, and working with the certification body.
  • Build practical ISMS processes for business continuity, change management, incident and vulnerability management, and supplier risk management.
  • Run the company-wide risk management program and translate business and technical risks into prioritized engineering and leadership actions.
  • Partner with Engineering and Product on security-by-design across the SDLC, CI/CD, infrastructure-as-code, and automated evidence monitoring.
  • Maintain the ISO 9001 QMS and GDPR framework, support customer due diligence, and translate NIS2 and AI Act requirements into practical roadmaps.

Requirements

  • 5+ years of experience in Information Security, Compliance, Risk Management, or GRC, including experience building or maturing an ISMS.
  • End-to-end ownership of at least one ISO 27001 certification, surveillance, or re-certification audit.
  • Deep knowledge of ISO 27001:2022 and its controls, with working knowledge of ISO 9001 and GDPR and the ability to navigate NIS2.
  • Hands-on understanding of SaaS and cloud environments, including GCP and/or Azure, CI/CD, infrastructure-as-code, and modern change management.
  • Strong risk management foundations and the ability to communicate risk to C-level stakeholders in business terms.
  • English at C1 level and regular on-site presence in Vienna are required; willingness to relocate to Austria is expected if not already based there.

Nice to have

  • German language skills.
  • ISO 27001 Lead Implementer or Lead Auditor, CISM, CISSP, or CISA certification.
  • Experience with GRC platforms such as Vanta or Drata.

Culture & Benefits

  • Full-time permanent employment with a competitive salary and benefits package.
  • Hybrid setup with a modern Vienna office and a high degree of autonomy.
  • Collaborative international environment focused on trust, growth, and transparency.
  • Time and budget for continuous learning and professional certifications.

Hiring process

  • Resume screening and initial contact.
  • Cultural Fit discussion.
  • Skill and Team Fit discussions with the future team lead and colleagues, followed by an offer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →