11 дней назад
Information Security & Compliance Manager (GRC)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security & Compliance Manager (GRC): Owning and maturing fiskaly’s ISMS, ISO 27001 re-certification, ISO 9001 QMS, and GDPR framework across a cloud-native SaaS environment with an accent on audit leadership, risk management, and security-by-design. Focus on closing nonconformities, building scalable compliance processes, automating evidence collection, and translating technical and regulatory risks into actionable roadmaps for leadership.
Location: Vienna, Austria — hybrid with regular on-site presence and full on-site presence during audits. Based in Vienna or willing to relocate.
Company
is a B2B software company providing digital receipt and legally compliant transaction technology across seven European markets.
What you will do
- Own the Information Security Management System end-to-end, including scope, policies, controls, risk registers, management reviews, and continuous improvement.
- Lead the ISO 27001 re-certification planned for early 2027 by assessing gaps, closing nonconformities, running internal audits, preparing evidence, and working with the certification body.
- Build practical ISMS processes for business continuity, change management, incident and vulnerability management, and supplier risk management.
- Run the company-wide risk management program and translate business and technical risks into prioritized engineering and leadership actions.
- Partner with Engineering and Product on security-by-design across the SDLC, CI/CD, infrastructure-as-code, and automated evidence monitoring.
- Maintain the ISO 9001 QMS and GDPR framework, support customer due diligence, and translate NIS2 and AI Act requirements into practical roadmaps.
Requirements
- 5+ years of experience in Information Security, Compliance, Risk Management, or GRC, including experience building or maturing an ISMS.
- End-to-end ownership of at least one ISO 27001 certification, surveillance, or re-certification audit.
- Deep knowledge of ISO 27001:2022 and its controls, with working knowledge of ISO 9001 and GDPR and the ability to navigate NIS2.
- Hands-on understanding of SaaS and cloud environments, including GCP and/or Azure, CI/CD, infrastructure-as-code, and modern change management.
- Strong risk management foundations and the ability to communicate risk to C-level stakeholders in business terms.
- English at C1 level and regular on-site presence in Vienna are required; willingness to relocate to Austria is expected if not already based there.
Nice to have
- German language skills.
- ISO 27001 Lead Implementer or Lead Auditor, CISM, CISSP, or CISA certification.
- Experience with GRC platforms such as Vanta or Drata.
Culture & Benefits
- Full-time permanent employment with a competitive salary and benefits package.
- Hybrid setup with a modern Vienna office and a high degree of autonomy.
- Collaborative international environment focused on trust, growth, and transparency.
- Time and budget for continuous learning and professional certifications.
Hiring process
- Resume screening and initial contact.
- Cultural Fit discussion.
- Skill and Team Fit discussions with the future team lead and colleagues, followed by an offer.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
GRC Specialist (Cybersecurity Compliance)
9 дней назад
Security GRC Specialist (Fintech)
12 дней назад
GRC Specialist (Cybersecurity)
8 дней назад
Vice President & Chief Information Security Officer (Cybersecurity)
228 700 - 285 900$
7 дней назад