Назад
Company hidden
6 дней назад

Security & Compliance Officer

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Sweden
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security & Compliance Officer (ISO 27001/GDPR): Owning Bambuser's information security management system, privacy and compliance frameworks, and operational risk registers with an accent on audit readiness, policy governance, and enterprise security reviews. Focus on translating regulations into scalable controls, coordinating penetration testing and training, and automating recurring security and compliance workflows.

Location: Hybrid in Stockholm, Sweden; candidates already based in Stockholm and eligible to work in Sweden without visa sponsorship are prioritized.

Company

hirify.global is a fast-moving scale-up providing B2B SaaS technology.

What you will do

  • Own and continuously improve the ISO 27001 information security management system and prepare the organization for surveillance audits and recertification.
  • Plan and run internal and external audits, including scoping, evidence collection, stakeholder coordination, and remediation of findings.
  • Maintain the ISMS policy library, improve adoption, and develop practical control documentation and playbooks.
  • Lead customer security reviews, information security sections of RFPs, Trust Center updates, and the rollout of an RFP AI tool.
  • Assess information security, data handling, access, and integration risks for new tools and vendors, including AI tools.
  • Oversee GDPR and international privacy compliance, regulatory monitoring, penetration testing, security training, and the corporate risk register.

Requirements

  • 5+ years of experience in information security compliance, IT audit, or risk management, ideally in B2B SaaS or a fast-growing technology company.
  • Experience implementing or maintaining ISO/IEC 27001 certifications.
  • Strong practical knowledge of GDPR in multi-tenant SaaS environments.
  • Familiarity with AI regulation, including the EU AI Act, and its implications for technology businesses.
  • Ability to translate regulatory requirements and technical security risks into practical workflows and business language.
  • Comfort with workflow automation, reminders, scheduling tools, and AI-assisted drafting.

Nice to have

  • Experience running or supporting penetration testing programs.
  • Experience working in or with publicly listed companies and knowledge of internal control requirements.

Culture & Benefits

  • Fast-moving scale-up environment with an emphasis on pragmatic, solutions-oriented security practices.
  • Preference for automating recurring tasks such as evidence collection, training reminders, and audit scheduling.
  • Opportunity to establish documented, scalable security workflows across the organization.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →